risk
Poor configuration management and insecure baseline drift
Without documented, enforced baseline configurations and change control, systems drift into insecure states, contain unauthorized changes, or expose unnecessary network services, expanding attack surface.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Secure Configuration & Change Management
- Vulnerability & Patch Management
- taxonomy
- iso-27005-vulnerability
- nist-800-30-threat-event
- inherent_rating
- high
Details
- risk_id
- config-poor-baseline-drift
- category
- cyber_security
- likelihood
- high
- impact
- medium
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-vulnerability
- nist-800-30-threat-event
Source
No record-specific source URL is provided.
Connections
- UC-CONFIG-02 — Authorize, test, and approve changes before production mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Gating changes through authorization and impact analysis prevents unauthorized changes that cause drift, though baseline monitoring is the operative control.
- UC-CONFIG-01 — Harden systems to approved secure configuration baselines mitigates Poor configuration management and insecure baseline drift
- strength
- primary
- rationale
- Establishing enforced baselines and monitoring/remediating deviations is the direct defense against insecure configuration drift.
- UC-VULN-06 — Verify software, firmware, and information integrity mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Integrity monitoring detects unauthorized changes and deviations from the trusted baseline.
- UC-ACCESS-16 — Authorize, test, and approve changes and development mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Requiring authorized, documented changes reduces the unauthorized changes that drive drift, though baseline monitoring is the operative control.
- UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Scans surface deviations from secure baselines (missing patches, insecure settings), flagging drift for remediation.
- UC-CONFIG-09 — Document configuration management policy, plan, and procedures mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- A documented CM plan defining how configuration items are identified and managed is the foundation enabling baseline control, but not the operative drift defense.
- UC-CONFIG-03 — Separate environments and protect production data in testing mitigates Poor configuration management and insecure baseline drift
- strength
- related
- rationale
- Restricting who can alter production and separating environments reduces ad-hoc unauthorized production changes that cause drift.
- UC-VULN-09 — Employ non-persistence and information-resilience techniques mitigates Poor configuration management and insecure baseline drift
- strength
- primary
- rationale
- Non-persistent provisioning and periodic refresh from known-good trusted sources revert configuration drift and unauthorized changes.