Skip to content
ControlVerdict
CM.L2-3.4.2addresses
CM.L2-3.4.2Security Configuration Enforcement
Establish and enforce security configuration settings for information technology products employed in organizational systems.
  • [a]

    security configuration settings for information technology products employed in the system are established and included in the baseline configuration; and
  • [b]

    security configuration settings for information technology products employed in the system are enforced.

View full control

CIS-aligned Windows baseline assigned by compliance; drift becomes a ticket

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Security Configuration Enforcement objectives for the Windows CUI fleet. Lab Windows IoT and macOS engineer devices use a reduced checklist under documented exceptions but are still governed by the same establish-and-enforce baseline process.

Baseline content. Hardened password/PIN policy (complementing IdP MFA), BitLocker required, Secure Boot, disabled SMBv1, restricted PowerShell language mode for standard users, Windows Defender real-time + cloud protection on, local admin rights removed for standard users, screen lock ≤ 15 minutes, USB write blocked on CUI devices.

Assignment. Baseline is an Intune configuration profile + compliance policy. Noncompliant devices lose CUI Conditional Access until remediated (except a documented grace period for rebuilds).

Drift. Compliance dashboard reviewed weekly; devices noncompliant >7 days auto-open a ticket to the endpoint team. Local changes that fight the baseline (e.g., re-enabling local admin) are overwritten on next Intune sync.

Maintenance. Baseline versioned (vYYYY.MM). Changes go through CAB with security review. After each major OS upgrade, re-diff against CIS and update the profile within 30 days.

Accepted gap. Lab instruments on Windows IoT cannot take the full baseline. They are VLAN-isolated, no CUI at rest, and use a reduced hardening checklist signed by the enclave owner.

What the evidence looks like

  • Intune profile export (settings list)
  • Compliance policy and Conditional Access grant dependency
  • Baseline version history / CAB ticket for last change
  • Weekly compliance snapshot with open drift tickets
  • Lab exception checklist

Environment

Windows 11 fleet for CUI users; macOS engineers on a separate, smaller baseline.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.