CM.L2-3.4.2Security Configuration Enforcement
Establish and enforce security configuration settings for information technology products employed in organizational systems.
[a]
security configuration settings for information technology products employed in the system are established and included in the baseline configuration; and[b]
security configuration settings for information technology products employed in the system are enforced.
CIS-aligned Windows baseline assigned by compliance; drift becomes a ticket
Implementation
AO coverage. Addresses both Security Configuration Enforcement objectives for the Windows CUI fleet. Lab Windows IoT and macOS engineer devices use a reduced checklist under documented exceptions but are still governed by the same establish-and-enforce baseline process.
Baseline content. Hardened password/PIN policy (complementing IdP MFA), BitLocker required, Secure Boot, disabled SMBv1, restricted PowerShell language mode for standard users, Windows Defender real-time + cloud protection on, local admin rights removed for standard users, screen lock ≤ 15 minutes, USB write blocked on CUI devices.
Assignment. Baseline is an Intune configuration profile + compliance policy. Noncompliant devices lose CUI Conditional Access until remediated (except a documented grace period for rebuilds).
Drift. Compliance dashboard reviewed weekly; devices noncompliant >7 days auto-open a ticket to the endpoint team. Local changes that fight the baseline (e.g., re-enabling local admin) are overwritten on next Intune sync.
Maintenance. Baseline versioned (vYYYY.MM). Changes go through CAB with security review. After each major OS upgrade, re-diff against CIS and update the profile within 30 days.
Accepted gap. Lab instruments on Windows IoT cannot take the full baseline. They are VLAN-isolated, no CUI at rest, and use a reduced hardening checklist signed by the enclave owner.
What the evidence looks like
- Intune profile export (settings list)
- Compliance policy and Conditional Access grant dependency
- Baseline version history / CAB ticket for last change
- Weekly compliance snapshot with open drift tickets
- Lab exception checklist
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.