Under active development Content is continuously updated and improved

3.2.8Security Configuration Baselines

>Control Description

FRFIs should implement approved, risk-based security configuration baselines for technology assets and security defence tools, including those provided by third parties. Where possible, security configuration baselines for different defence layers should disable settings and access by default. FRFIs should define and implement processes to manage configuration deviations.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.