B BROCENT
Brocent — Your Asia IT Team
BCS Support Center · Hong Kong
it-service@brocent.com
Monthly client report · 03 of 09

Configuration Management

Security baseline conformance, configuration drift, change control and hardening coverage across endpoints, servers and network devices for the August 2026 reporting period.

Client
Acme Capital Limited
Reporting period
2026-08-01 → 08-31
Issued
2026-09-03
Reference
CONF-2026-08
Scope
35 computers · 2 servers · 12 network
Baseline
CIS Level 1 + client overlay
Prepared by
BCS Support Center
Classification
Confidential
01 · Executive summary

Endpoints conform to baseline; network devices and change records are the gap

Baseline conformance across the 35 managed computers reached 96.2% of assessed controls, up from 92.8% in July. Disk encryption, host firewall and screen-lock policy are now at full coverage, and local administrator rights have been removed from every user account except two approved break-glass identities.

The material gaps sit outside the endpoint fleet. No formal baseline exists for the twelve network devices, so their configuration is maintained by convention rather than by policy; two switches still permit unencrypted management protocols. Separately, four configuration changes were applied during the period without a change record, all by client staff with retained administrative access on the file server.

Service verdict
Met, with action
Four of five configuration service levels were met; drift remediation exceeded the 5-day target on one endpoint. Two structural items — network baseline and change discipline — are tracked as CONF-R01 and CONF-R02.
02 · Key indicators

Configuration position at period end

Baseline conformance
96.2%
▲ +3.4 pts
Devices in policy
33/35
▲ +3 vs Jul
Drift events
17
▲ −9 vs Jul
Unapproved changes
4
▼ +1 vs Jul
Disk encryption
100%
▲ +5.7 pts
Local admin removed
35/35
▲ +2 vs Jul
Network baseline
0/12
— unchanged
Mean drift repair
2.4 d
▲ −1.1 d

Conformance is measured against the assessed control set only. A device counts as "in policy" when every mandatory control passes; a single failed control removes it from that count regardless of severity.

03 · Key findings

Four items require action

No security baseline exists for the twelve network devices · carried forward (3 periods)
HIGH

Evidence. Four switches, two firewalls and six access points have no documented target configuration. Two access switches still accept Telnet and HTTP management; three devices share a single local administrator credential.

Impact. Without a baseline there is no definition of drift, so a malicious or accidental change to the perimeter cannot be detected. This is also the most commonly cited gap in operational due-diligence reviews of small trading firms.

Recommendation. Adopt the vendor hardening guide as the baseline, disable Telnet and HTTP in favour of SSH and HTTPS, and move device administration to individual accounts backed by the identity provider.

Owner BCS Support Center Target 2026-10-31 Ref CONF-2026-06-01
Four changes were applied without a change record
HIGH

Evidence. A share permission change, two scheduled-task additions and a firewall rule edit were detected by drift monitoring with no corresponding ticket. All four were performed with a client-held administrator account on the file server.

Impact. Undocumented changes break the audit trail, make incident root-cause analysis unreliable, and mean the configuration record cannot be relied on for recovery.

Recommendation. Retire the shared client administrator account in favour of named, time-limited elevation, and route all server changes through the standard change record even when performed by client staff.

Owner Client IT + BCS Support Center Target 2026-09-30 Ref CONF-2026-08-02
Two endpoints fail the USB storage control
MEDIUM

Evidence. Two research-team Macs are excluded from the removable-media policy by an exception granted in March 2026 for a data-transfer workflow that has since been replaced by a cloud share.

Impact. Unrestricted USB write access on devices holding research material is an uncontrolled egress path and a stale exception that no longer has a business justification.

Recommendation. Withdraw the exception and re-apply the policy in read-only mode; confirm the cloud share meets the original workflow need.

Owner BCS Support Center Target 2026-09-30 Ref CONF-2026-08-03
One drift repair exceeded the five-day target
LOW

Evidence. A screen-lock timeout change on one Shenzhen desktop took nine days to repair because the device was offline for the annual research shutdown.

Recommendation. Exclude devices offline for more than five consecutive days from the drift clock and report them separately as unreachable.

Owner BCS Support Center Target 2026-10-31 Ref CONF-2026-08-04
Closed this period · disk encryption and local administrator removal completed
RESOLVED

The two unencrypted devices raised in July are now encrypted with keys escrowed to the tenant, and the last two standing local administrator rights were removed on 2026-08-21 and replaced with just-in-time elevation. Both items are closed and retained for the audit trail.

04 · Service level attainment

Four of five service levels met

Committed service levelTargetActualStatusNote
Baseline applied at enrolment 100% 100% MET 2 of 2 new devices
Baseline conformance ≥ 95% 96.2% MET Assessed control set
Drift remediation ≤ 5 days 9 days (1 device) MISSED Device offline during shutdown
Change record for every change 100% 100% (BCS) MET 4 client-side changes unrecorded — this SLA covers changes performed by BCS Support Center; the four unrecorded changes were made with client-held credentials and are reported as a finding rather than a service-level breach.
Monthly report issued By 5th working day 3rd working day MET Issued 2026-09-03
05 · Trend

Three-period movement

MetricJun 2026Jul 2026Aug 2026Direction of travel
Baseline conformance 89.4% 92.8% 96.2% Third consecutive improvement; above the 95% commitment.
Devices fully in policy 27/35 30/35 33/35 Two remaining failures are the USB exception Macs.
Drift events 31 26 17 Falling as policy replaces manual configuration.
Unapproved changes 2 3 4 Rising — client-held admin access is the single cause.
Mean drift repair 4.1 d 3.5 d 2.4 d Improving; automated remediation now covers 9 controls.
Network devices with baseline 0/12 0/12 0/12 No movement — the structural gap in this discipline.
Drift events by control area · 17 in period
Local firewall rules
5
Scheduled tasks
4
Share permissions
3
Screen lock timeout
2
Browser policy
2
Service start type
1

Bars are scaled to the largest area (5). Twelve of the 17 events were auto-remediated within 24 hours; the remaining five required a technician.

06 · Detail data

Baseline conformance by control

The assessed control set for the 35 managed computers. Controls marked mandatory determine whether a device counts as fully in policy.

ControlMandatoryConformingStatusNote
Full-disk encryption with key escrowYes35/35PASSCompleted this period; keys held in the tenant.
Host firewall enabledYes35/35PASSInbound default deny on all profiles.
No standing local administratorYes35/35PASSJust-in-time elevation; 2 break-glass accounts vaulted.
Screen lock ≤ 10 minutesYes35/35PASSOne drift event repaired late; now compliant.
Removable media controlledYes33/35GAPTwo Macs on a stale exception — see finding.
Endpoint protection activeYes35/35PASSTamper protection on; real-time scanning enforced.
Secure boot and TPM enabledYes30/30PASSWindows devices only; not applicable to Macs.
Legacy protocols disabledNo34/35GAPOne device retains SMBv1 for a legacy printer.
Local account password policyNo35/35PASSRandomised and rotated by the management agent.
Audit logging to SIEMNo32/35GAPThree Macs pending agent upgrade; see SOC report.

Network and server configuration status

DeviceClassFirmwareBaselineMgmt protocolAdmin accessAction
ACM-FW-01FirewallCurrentNONEHTTPS + SSHShared localAdopt vendor guide
ACM-FW-02FirewallCurrentNONEHTTPS + SSHShared localAdopt vendor guide
ACM-SW-C1Core switchCurrentNONESSHShared localAdopt vendor guide
ACM-SW-C2Core switchCurrentNONESSHShared localAdopt vendor guide
ACM-SW-A1Access switch1 behindNONETelnet + HTTPShared localDisable Telnet; upgrade
ACM-SW-A2Access switchUnsupportedNONETelnet + HTTPShared localReplace — pending disposal
ACM-AP-01–06WIFI APCurrentNONEControllerController SSOBaseline via controller
ACM-SRV-01File serverCurrentAPPLIEDRDP restrictedClient + BCSRetire client shared admin
ACM-SRV-02App serverCurrentAPPLIEDRDP restrictedBCS onlyNone

Change activity

Change typeCountWith recordNote
Standard (pre-approved)1414Policy assignments, baseline updates, agent upgrades.
Normal (approved)55Firewall rule additions and a share restructure, all ticketed.
Emergency11Browser policy rollback after a rendering fault; retro-approved.
Unrecorded40Client-side changes detected by drift monitoring — see finding.
07 · Risk register

Open items carried between periods

RefRiskSeverityOwnerDueStatusNext action
CONF-R01 No baseline for network devices — drift cannot be defined or detected HIGH BCS Support Center 2026-10-31 In progress Adopt vendor hardening guides; disable Telnet and HTTP first.
CONF-R02 Client-held shared administrator on the file server — source of all unrecorded changes HIGH Client IT + BCS 2026-09-30 Open Replace with named just-in-time elevation and close the shared account.
CONF-R03 Stale USB exception — two devices outside removable-media control MEDIUM BCS Support Center 2026-09-30 Open Withdraw the exception; re-apply policy read-only.
CONF-R04 Unsupported access switch in production — no firmware fixes available MEDIUM Client COO 2026-11-30 Open Approve replacement; BCS to quote with the refresh proposal.
CONF-R05 SMBv1 retained for a legacy printer — deprecated protocol on one device LOW BCS Support Center 2026-12-31 Open Replace the printer driver path or the printer at refresh.

Next period commitments

BCS Support Center willClient is asked to
Publish a network device baseline and disable Telnet and HTTP management. Approve the retirement of the shared file-server administrator account.
Withdraw the USB exception and confirm the cloud share meets the workflow. Confirm the research team no longer requires removable-media write access.
Move network device administration onto named identity-backed accounts. Approve replacement of the unsupported access switch.
Report drift separately for devices offline more than five days. Route client-side server changes through the change record.
Appendix · Method and definitions

How this report was produced

SourceExtractedRecordsUsed for
Endpoint policy platform 2026-09-01 02:20 HKT 35 devices Policy assignment, conformance per control, drift events.
CIS benchmark scan 2026-08-30 22:00 HKT 10 controls Independent conformance verification of the assessed set.
Network device configuration pull 2026-08-31 21:00 HKT 12 devices Firmware, management protocols, administrative access.
Change and ticket record 2026-08-31 20 changes Change classification and record completeness.
Server configuration audit 2026-08-31 2 servers Baseline application and administrative access review.

Method and definitions

Baseline. is CIS Level 1 for the relevant platform plus the client overlay agreed in the service description. Only the ten controls listed in section 06 are assessed; conformance percentages refer to that set and are not a claim of full CIS compliance.

Drift. is any deviation of an assessed control from its baseline value, whether caused by a user, an application or an administrator. A drift event is counted once per device per control, and the drift clock starts at detection, not at the change itself.

Unapproved change. is a configuration change detected without a matching change record. It is reported even when the change is benign, because the absence of a record is itself the control failure.

Exclusions. Cloud tenant configuration is reported in the Microsoft 365 Security report; account and permission settings in the Account Management and Access Review reports. Application-level configuration inside client-managed software is out of scope.

Anonymisation notice

This copy is an anonymised sample prepared for illustration. The client name, hostnames, device identifiers and vendor names have been replaced with fictitious or generic values; counts, ratios, dates and findings reflect a representative managed estate. No real client data appears in this document.

Questions on this report
BCS Support Center · it-service@brocent.com
Brocent — Your Asia IT Team
Next step

See what your own Configuration Management report would say

A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.

Book a free IT health check Contact BCS Support Center