SCF - CFG-02.1 - Reviews & Updates
Mechanisms exist to review and update baseline configurations:
- At least annually;
- When required due to so; or
- As part of system component installations and upgrades.
Mapped framework controls
ISO 27002
- A.8.9
NIST 800-53
SOC 2
Control questions
Does the organization review and update baseline configurations:
- At least annually;
- When required due to so; or
- As part of system component installations and upgrades?