HomeControl Library › 3.4.2
3.4 Configuration Management5 pts

3.4.2 — Enforce secure configuration settings

Establish and enforce security configuration settings for information technology products employed in organizational systems.

Your systems are hardened to a defined secure baseline — and it's enforced.

What it actually means

Having a baseline (3.4.1) isn't enough — you have to enforce hardened security settings on the products you use. In practice that's applying a recognized hardening standard (CIS Benchmarks / DISA STIGs) through group policy, Intune, or your config-management tooling, and keeping machines in that state.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library