PR.PS-01.240

Does your organization have a process to monitor software for deviations from approved baselines?

Explanation

Software baseline monitoring ensures that deployed applications maintain their approved configurations and security settings over time. Without regular monitoring, unauthorized changes or drift from secure configurations can introduce vulnerabilities or compliance issues. Evidence could include documentation of a baseline monitoring system (such as configuration management tools), periodic compliance reports showing deviations from baselines, change detection logs, or screenshots of monitoring dashboards that track software configurations against established baselines.

Implementation Example

Monitor implemented software for deviations from approved baselines

ID: PR.PS-01.240

Context

Function
PR: PROTECT
Category
PR.PS: Platform Security
Sub-Category
Configuration management practices are established and applied

ResponseHub is the product I wish I had when I was a CTO

Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.

As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!

I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

Signature
Neil Cameron
Founder, ResponseHub
Neil Cameron