PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CM-2 — Baseline Configuration

Framework: NIST SP 800-53 Rev.5 CM-2 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Verify a documented baseline configuration exists for each system/component type, capturing OS versions and patch levels, installed software/packages, key configuration settings, network topology, and logical placement within the architecture, and that it is dated and version-labeled.
Examine Confirm the current baseline is maintained under configuration control in a version-controlled repository or CM tool, with a retained change history that references the authorizing change request.
Interview Ask the configuration manager how often baselines are reviewed, updated, and re-approved, and confirm the cadence matches the organization-defined frequency (e.g., at least annually and upon significant change or system upgrade).
Test Select a sample of production hosts and compare their live running configuration against the documented baseline to confirm they match, with any drift documented and approved.
Examine Review change records for recent installs/upgrades to confirm the baseline is updated as an integral part of component changes rather than after the fact.
Test Retrieve a prior baseline version from the repository to confirm previous configurations are retained to support rollback/reconstitution (CM-2(3)).