Configuration Management
Configuration management is the practice of keeping computer systems, software, and networks in a known, consistent, and correct state, including their required security settings. It involves establishing controlled processes and procedures so that changes to those systems are tracked and managed rather than made in an uncontrolled way. The goal is to help ensure that hardware, software, services, and networks continue to function correctly throughout their lifecycle.
Configuration management (CM) is a management and systems engineering process for establishing and maintaining consistency of a product's or system's performance, functional, and physical attributes throughout its lifecycle. In an information security context, it generally focuses on ensuring that hardware, software, services, and networks function correctly with their required security settings and are maintained in a defined, desired state. CM typically incorporates established methodology, systems, and procedures to control the elements of the change process. Note that this entry addresses the general concept; specific control requirements, baselines, and family designations (for example, the Configuration Management control family under NIST control catalogs) vary by applicable framework and revision and should be confirmed against the current authoritative text.
Why it matters
Configuration management is foundational to maintaining a secure and reliable operating environment because systems rarely stay in their intended state on their own. Software updates, ad hoc administrative changes, misconfigured services, and undocumented modifications can gradually push a system away from its approved baseline, introducing vulnerabilities and inconsistencies. By keeping hardware, software, services, and networks in a known, consistent state with their required security settings, configuration management reduces the risk that uncontrolled or unauthorized changes will degrade functionality or weaken defenses over time.
For defense and public sector organizations, configuration management also supports accountability and traceability. Because changes are tracked and managed through established methodology, systems, and procedures rather than made in an uncontrolled way, teams can understand what the approved state should be, detect deviations, and respond to them. This discipline underpins broader security operations activities and is generally treated as a distinct control area within recognized security frameworks, though the specific control requirements, baselines, and family designations vary by framework and revision.
It is worth emphasizing that configuration management is not the same as security more broadly, and maintaining a documented baseline is not by itself proof of a secure system. A configuration can be consistently maintained yet still contain weak or inappropriate settings if the baseline itself is flawed. Configuration management is most effective when paired with ongoing assessment and continuous monitoring, and readers should confirm the precise obligations that apply to their systems against the current authoritative text for their applicable framework.
Who it's relevant to
Inside CM
Common questions
Answers to the questions practitioners most commonly ask about CM.