it-service@brocent.com
Configuration Management
Security baseline conformance, configuration drift, change control and hardening coverage across endpoints, servers and network devices for the August 2026 reporting period.
Endpoints conform to baseline; network devices and change records are the gap
Baseline conformance across the 35 managed computers reached 96.2% of assessed controls, up from 92.8% in July. Disk encryption, host firewall and screen-lock policy are now at full coverage, and local administrator rights have been removed from every user account except two approved break-glass identities.
The material gaps sit outside the endpoint fleet. No formal baseline exists for the twelve network devices, so their configuration is maintained by convention rather than by policy; two switches still permit unencrypted management protocols. Separately, four configuration changes were applied during the period without a change record, all by client staff with retained administrative access on the file server.
Configuration position at period end
Conformance is measured against the assessed control set only. A device counts as "in policy" when every mandatory control passes; a single failed control removes it from that count regardless of severity.
Four items require action
Evidence. Four switches, two firewalls and six access points have no documented target configuration. Two access switches still accept Telnet and HTTP management; three devices share a single local administrator credential.
Impact. Without a baseline there is no definition of drift, so a malicious or accidental change to the perimeter cannot be detected. This is also the most commonly cited gap in operational due-diligence reviews of small trading firms.
Recommendation. Adopt the vendor hardening guide as the baseline, disable Telnet and HTTP in favour of SSH and HTTPS, and move device administration to individual accounts backed by the identity provider.
Evidence. A share permission change, two scheduled-task additions and a firewall rule edit were detected by drift monitoring with no corresponding ticket. All four were performed with a client-held administrator account on the file server.
Impact. Undocumented changes break the audit trail, make incident root-cause analysis unreliable, and mean the configuration record cannot be relied on for recovery.
Recommendation. Retire the shared client administrator account in favour of named, time-limited elevation, and route all server changes through the standard change record even when performed by client staff.
Evidence. Two research-team Macs are excluded from the removable-media policy by an exception granted in March 2026 for a data-transfer workflow that has since been replaced by a cloud share.
Impact. Unrestricted USB write access on devices holding research material is an uncontrolled egress path and a stale exception that no longer has a business justification.
Recommendation. Withdraw the exception and re-apply the policy in read-only mode; confirm the cloud share meets the original workflow need.
Evidence. A screen-lock timeout change on one Shenzhen desktop took nine days to repair because the device was offline for the annual research shutdown.
Recommendation. Exclude devices offline for more than five consecutive days from the drift clock and report them separately as unreachable.
The two unencrypted devices raised in July are now encrypted with keys escrowed to the tenant, and the last two standing local administrator rights were removed on 2026-08-21 and replaced with just-in-time elevation. Both items are closed and retained for the audit trail.
Four of five service levels met
| Committed service level | Target | Actual | Status | Note |
|---|---|---|---|---|
| Baseline applied at enrolment | 100% | 100% | MET | 2 of 2 new devices |
| Baseline conformance | ≥ 95% | 96.2% | MET | Assessed control set |
| Drift remediation | ≤ 5 days | 9 days (1 device) | MISSED | Device offline during shutdown |
| Change record for every change | 100% | 100% (BCS) | MET | 4 client-side changes unrecorded — this SLA covers changes performed by BCS Support Center; the four unrecorded changes were made with client-held credentials and are reported as a finding rather than a service-level breach. |
| Monthly report issued | By 5th working day | 3rd working day | MET | Issued 2026-09-03 |
Three-period movement
| Metric | Jun 2026 | Jul 2026 | Aug 2026 | Direction of travel |
|---|---|---|---|---|
| Baseline conformance | 89.4% | 92.8% | 96.2% | Third consecutive improvement; above the 95% commitment. |
| Devices fully in policy | 27/35 | 30/35 | 33/35 | Two remaining failures are the USB exception Macs. |
| Drift events | 31 | 26 | 17 | Falling as policy replaces manual configuration. |
| Unapproved changes | 2 | 3 | 4 | Rising — client-held admin access is the single cause. |
| Mean drift repair | 4.1 d | 3.5 d | 2.4 d | Improving; automated remediation now covers 9 controls. |
| Network devices with baseline | 0/12 | 0/12 | 0/12 | No movement — the structural gap in this discipline. |
Bars are scaled to the largest area (5). Twelve of the 17 events were auto-remediated within 24 hours; the remaining five required a technician.
Baseline conformance by control
The assessed control set for the 35 managed computers. Controls marked mandatory determine whether a device counts as fully in policy.
| Control | Mandatory | Conforming | Status | Note |
|---|---|---|---|---|
| Full-disk encryption with key escrow | Yes | 35/35 | PASS | Completed this period; keys held in the tenant. |
| Host firewall enabled | Yes | 35/35 | PASS | Inbound default deny on all profiles. |
| No standing local administrator | Yes | 35/35 | PASS | Just-in-time elevation; 2 break-glass accounts vaulted. |
| Screen lock ≤ 10 minutes | Yes | 35/35 | PASS | One drift event repaired late; now compliant. |
| Removable media controlled | Yes | 33/35 | GAP | Two Macs on a stale exception — see finding. |
| Endpoint protection active | Yes | 35/35 | PASS | Tamper protection on; real-time scanning enforced. |
| Secure boot and TPM enabled | Yes | 30/30 | PASS | Windows devices only; not applicable to Macs. |
| Legacy protocols disabled | No | 34/35 | GAP | One device retains SMBv1 for a legacy printer. |
| Local account password policy | No | 35/35 | PASS | Randomised and rotated by the management agent. |
| Audit logging to SIEM | No | 32/35 | GAP | Three Macs pending agent upgrade; see SOC report. |
Network and server configuration status
| Device | Class | Firmware | Baseline | Mgmt protocol | Admin access | Action |
|---|---|---|---|---|---|---|
| ACM-FW-01 | Firewall | Current | NONE | HTTPS + SSH | Shared local | Adopt vendor guide |
| ACM-FW-02 | Firewall | Current | NONE | HTTPS + SSH | Shared local | Adopt vendor guide |
| ACM-SW-C1 | Core switch | Current | NONE | SSH | Shared local | Adopt vendor guide |
| ACM-SW-C2 | Core switch | Current | NONE | SSH | Shared local | Adopt vendor guide |
| ACM-SW-A1 | Access switch | 1 behind | NONE | Telnet + HTTP | Shared local | Disable Telnet; upgrade |
| ACM-SW-A2 | Access switch | Unsupported | NONE | Telnet + HTTP | Shared local | Replace — pending disposal |
| ACM-AP-01–06 | WIFI AP | Current | NONE | Controller | Controller SSO | Baseline via controller |
| ACM-SRV-01 | File server | Current | APPLIED | RDP restricted | Client + BCS | Retire client shared admin |
| ACM-SRV-02 | App server | Current | APPLIED | RDP restricted | BCS only | None |
Change activity
| Change type | Count | With record | Note |
|---|---|---|---|
| Standard (pre-approved) | 14 | 14 | Policy assignments, baseline updates, agent upgrades. |
| Normal (approved) | 5 | 5 | Firewall rule additions and a share restructure, all ticketed. |
| Emergency | 1 | 1 | Browser policy rollback after a rendering fault; retro-approved. |
| Unrecorded | 4 | 0 | Client-side changes detected by drift monitoring — see finding. |
Open items carried between periods
| Ref | Risk | Severity | Owner | Due | Status | Next action |
|---|---|---|---|---|---|---|
| CONF-R01 | No baseline for network devices — drift cannot be defined or detected | HIGH | BCS Support Center | 2026-10-31 | In progress | Adopt vendor hardening guides; disable Telnet and HTTP first. |
| CONF-R02 | Client-held shared administrator on the file server — source of all unrecorded changes | HIGH | Client IT + BCS | 2026-09-30 | Open | Replace with named just-in-time elevation and close the shared account. |
| CONF-R03 | Stale USB exception — two devices outside removable-media control | MEDIUM | BCS Support Center | 2026-09-30 | Open | Withdraw the exception; re-apply policy read-only. |
| CONF-R04 | Unsupported access switch in production — no firmware fixes available | MEDIUM | Client COO | 2026-11-30 | Open | Approve replacement; BCS to quote with the refresh proposal. |
| CONF-R05 | SMBv1 retained for a legacy printer — deprecated protocol on one device | LOW | BCS Support Center | 2026-12-31 | Open | Replace the printer driver path or the printer at refresh. |
Next period commitments
| BCS Support Center will | Client is asked to |
|---|---|
| Publish a network device baseline and disable Telnet and HTTP management. | Approve the retirement of the shared file-server administrator account. |
| Withdraw the USB exception and confirm the cloud share meets the workflow. | Confirm the research team no longer requires removable-media write access. |
| Move network device administration onto named identity-backed accounts. | Approve replacement of the unsupported access switch. |
| Report drift separately for devices offline more than five days. | Route client-side server changes through the change record. |
How this report was produced
| Source | Extracted | Records | Used for |
|---|---|---|---|
| Endpoint policy platform | 2026-09-01 02:20 HKT | 35 devices | Policy assignment, conformance per control, drift events. |
| CIS benchmark scan | 2026-08-30 22:00 HKT | 10 controls | Independent conformance verification of the assessed set. |
| Network device configuration pull | 2026-08-31 21:00 HKT | 12 devices | Firmware, management protocols, administrative access. |
| Change and ticket record | 2026-08-31 | 20 changes | Change classification and record completeness. |
| Server configuration audit | 2026-08-31 | 2 servers | Baseline application and administrative access review. |
Method and definitions
Baseline. is CIS Level 1 for the relevant platform plus the client overlay agreed in the service description. Only the ten controls listed in section 06 are assessed; conformance percentages refer to that set and are not a claim of full CIS compliance.
Drift. is any deviation of an assessed control from its baseline value, whether caused by a user, an application or an administrator. A drift event is counted once per device per control, and the drift clock starts at detection, not at the change itself.
Unapproved change. is a configuration change detected without a matching change record. It is reported even when the change is benign, because the absence of a record is itself the control failure.
Exclusions. Cloud tenant configuration is reported in the Microsoft 365 Security report; account and permission settings in the Account Management and Access Review reports. Application-level configuration inside client-managed software is out of scope.
This copy is an anonymised sample prepared for illustration. The client name, hostnames, device identifiers and vendor names have been replaced with fictitious or generic values; counts, ratios, dates and findings reflect a representative managed estate. No real client data appears in this document.
BCS Support Center · it-service@brocent.com
See what your own Configuration Management report would say
A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.