Skip to content

Configuration Management

Authorized By: Chief Information Security Officer (CISO)

Our Cybersecurity Configuration Management Policy establishes a standardized approach to managing and controlling the configuration of Safire’s information systems, networks, and devices. The policy aims to ensure system integrity, availability, and security by implementing effective configuration management practices, minimizing the risk of unauthorized access, data breaches, and system disruptions, and maintaining compliance with industry standards and regulatory requirements.

The Configuration Management Policy applies to all Safire employees, contractors, and stakeholders and encompasses the management and control of configuration settings and changes within our IT infrastructure. This policy covers all hardware, software, network devices, and systems that require consistent and secure configurations to maintain their integrity, availability, and compliance with company standards. It establishes guidelines for configuration baselines, change management processes, and version control to ensure that configurations are documented, approved, and monitored.

The policy also defines procedures for configuration drift detection, configuration audits, and configuration backups. Compliance with this policy is mandatory for all individuals within Safire and any deviations or exceptions require approval from the designated authority responsible for configuration management and cybersecurity governance.

New components that make up Safire’s hardware, software, services, and networks must have their required security settings defined and correctly configured (Hardened) prior to their implementation within our ICT environment.

  • Configurations will be based on industry-standard hardening guides (e.g., CIS Benchmarks, NIST, vendor-specific security guides).
  • Review Cadence: Configuration standards must be reviewed at least annually or upon significant changes to the threat landscape or technology stack (e.g., major OS version releases).
  • Protection: Details of configuration standards will be protected as sensitive information.
  • Endpoint devices (desktops, laptops, mobile phones, tablets)
  • Network devices (routers, switches, firewalls)
  • Servers (OS, databases, web servers)
  • Cloud infrastructure (virtual servers, networks, storage)

Operating System and Application Management

Section titled “Operating System and Application Management”

Safire shall maintain a library of approved configuration benchmarks that enforce “Least Functionality,” including:

  • Disabling unnecessary services, features, and ports.
  • Disabling unnecessary scripting languages/features.
  • Enabling advanced logging (e.g., PowerShell transcription).
  • Enforcing protections such as DEP, ASLR, and UAC (or platform equivalents).
  • Disabling autorun/auto-play.
  • Enforcing automatic screen locks after defined inactivity.
  • Requiring secure boot (e.g., UEFI Secure Boot) where supported.
  • Enforcement: Where feasible, automated software methods (e.g., RMM tools, MDM, Infrastructure as Code) will be used to apply and maintain baselines on all in-scope systems, regardless of location.
  • Approvals: All configuration changes to production systems must follow the approved Change Management process, including documented testing, backout plans, security impact assessments, and approvals from the System Owner.
  • Emergency Changes: Emergency changes must be documented and reviewed retrospectively within one business day.

The IT team shall continuously or periodically monitor for “Configuration Drift” (deviations from the approved baseline).

  • Deviations must be investigated and corrected; remediation shall be prioritized based on risk/severity.
  • Where feasible, automated audit and remediation tools shall be employed.

To ensure configurations remain secure, Safire will adhere to the following minimum cadence:

  • Vulnerability scans: Quarterly or more frequently as needed.
  • Configuration scans: Quarterly or more frequently as needed.
  • Manual configuration review: Annually or more frequently as needed.
  • Penetration testing: Annually or more frequently as needed.
  • Secure Code review: Annually (for in-scope proprietary software).
  • Backups: Device and system configuration files must be backed up regularly to ensure restorability. Backups must be encrypted and protected from unauthorized access.
  • Least Privilege: Administrators of configuration tools must operate under the principle of least privilege. Duties should be separated so implementers cannot unilaterally approve their own changes where feasible.
  • Cloud Posture: Cloud security baselines (identity, network, storage, logging) must be applied and monitored (e.g., via CSPM tools).

The policy owner will verify compliance to this policy through methods including automated configuration audits, variance reports from RMM/MDM tools, and internal/external audits. Oversight is provided by CISO, IT, and Compliance functions. Enforcement of this policy is coordinated through Human Resources and Executive Management.

Any exceptions must be approved by the Policy Owner in advance.

Non-compliance with this policy may result in disciplinary action in line with our corporation’s human resources procedures. Consequences may range from mandatory refresher training and written warnings to temporary suspension of remote access privileges and, in severe cases, termination of employment or contractual obligations. Individuals could be subject to legal consequences under applicable laws if violations involve illegal activities. These sanctions emphasize the critical importance of cybersecurity, the individual’s role in protecting our digital assets, and the potential risks associated with policy violations. Enforcement will be consistent and impartial, with the severity of the action corresponding directly to the seriousness of the breach.

Section titled “Related Standards, Policies, Plans, and Procedures”
  • Change Management Procedure
  • Vulnerability Management Policy
  • Access Control Policy

Revision History

2026-08-20 — Darren Rush
Merge pull request #2 from safire-dev/dev (16cb681)
Edit this Page