PlumbTrackLive demoGRC Risk System

← internal audit

Audit — CM-6 — Configuration Settings

Framework: NIST SP 800-53 Rev.5 CM-6 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 6 checked
Examine Verify documented, mandatory configuration settings (hardening standards) exist for each component type and are derived from an approved source such as CIS Benchmarks, DISA STIGs, or vendor security guidance (CIS Control 4).
Test Run a configuration-compliance scan (e.g., SCAP/CIS-CAT) against a sample of hosts and confirm the assessed settings match the approved secure baseline.
Examine Review the register of approved deviations/exceptions from baseline settings and confirm each has a documented business justification, risk acceptance, and authorizing approval.
Interview Ask administrators how configuration settings are enforced and drift is detected (e.g., Group Policy, MDM, Ansible/Puppet/Chef, or CSPM for cloud).
Test On a sample endpoint, attempt an unauthorized change to a controlled setting (or review enforcement/remediation logs) to confirm the change is prevented, reverted, or alerted.
Examine Confirm the proportion of in-scope components actually under automated configuration-setting management, with no ungoverned or manually configured systems slipping outside the process.