The Configuration Management Episode
Transcript
Introduction to the Guest and Topic:
Host Allie Krings introduces Shannon Lane, a Lead Practitioner at Kirkpatrick Price. The conversation focuses on configuration management—what it is, why it matters, and how it supports stronger security and compliance. Shannon shares his background, explaining that his journey into cybersecurity began after a long IT career and a challenge to earn his CISSP certification, which ultimately led him into auditing and consulting.
What Is Configuration Management?:
Configuration management is the process of understanding, building, and maintaining an organization’s systems in a secure and consistent way. It requires knowing exactly what assets exist, how they are configured, and how they support business operations.
At its core, configuration management focuses on the people, processes, and technology involved in maintaining an environment so it can securely and reliably drive the business forward.
What Does Configuration Management Look Like Up Close?:
For Individuals (IT Teams): It involves understanding how systems are built, what is installed on them, and ensuring configurations are consistent across environments. IT teams must document what they do, why they do it, and how systems are maintained over time.
For Companies: Organizations must define how their systems are designed, implemented, and maintained. This includes documenting configurations, managing infrastructure, and ensuring systems align with business needs while remaining secure.
What Are the Biggest Gaps in Compliance?:
One of the biggest gaps is a lack of planning and documentation. Misconfigurations often occur early in a system’s lifecycle and go unnoticed because they were never properly recorded or reviewed.
Another major gap is resourcing—organizations frequently fail to give technical teams enough time, tools, or personnel to properly build and maintain secure systems. Without adequate support, even well-designed standards cannot be effectively implemented.
Why Do Misconfigurations Happen?:
Misconfigurations typically happen when systems are built quickly to meet business needs without considering long-term maintenance or security. Over time, these issues persist because no one revisits or documents the original setup.
Because they are not continuously reviewed, these misconfigurations can remain in place for years until they are discovered—often after becoming a serious security risk.
How Are Misconfigurations Identified?:
Auditors identify misconfigurations by following business processes and tracing where sensitive data exists. They then examine each system and configuration along that path to ensure it is properly secured.
This process typically involves reviewing different layers—such as networks, devices, cloud environments, and storage systems—to ensure each component is configured correctly within the overall environment.
How Should Organizations Build Secure Systems?:
Start with the Business Process: Organizations must first understand what they are trying to accomplish and how data flows through their systems.
Map Data Flow: Identify where data is stored, processed, and transmitted to understand all potential risk points.
Conduct Risk Assessments: Evaluate risks at every stage of the data flow and identify necessary security controls.
Secure Each Step: Apply controls to each part of the system to ensure data is protected at every point.
Why Are Audits So Important?:
Audits provide an external perspective that helps organizations uncover risks they may have overlooked. Rather than relying solely on internal teams, audits bring in additional expertise and knowledge from across industries.
They help validate whether risks have been properly identified and mitigated, and whether systems are configured securely based on known threats and best practices.
How Should Companies Create and Maintain Standards?:
Provide Resources First: Organizations must ensure their technical teams have enough time and support before expecting standards to be created or maintained.
Document Everything: Standards should clearly define how systems are built and managed, including the reasoning behind decisions.
Train Teams: IT staff must understand the importance of documentation and consistency, even if it goes against their natural preference to focus on technical execution.
How Do You Test Configuration Management Effectiveness?:
Testing is done by comparing actual configurations against documented standards. If processes are properly defined and followed, it becomes straightforward to verify whether systems were built and maintained as intended.
This structured approach allows organizations to quickly identify gaps and confirm whether controls are working effectively.
What About Change Management?:
Change management is a critical part of configuration management. Every change to a system must be reviewed, documented, and aligned with existing standards.
It ensures that updates do not introduce new risks and that documentation remains accurate as systems evolve.
How Does Technology Evolution Impact Configuration Management?:
While technology evolves rapidly—especially with the rise of cloud computing—the core principles of configuration management remain the same.
Organizations must still understand their systems, manage risk, and ensure secure configurations. The tools and environments may change, but the underlying security mindset and processes remain consistent.
How Can Companies Ensure Compliance?:
Compliance begins with clearly defining and documenting how systems should be configured. Organizations must ensure that these standards are consistently implemented and maintained over time.
They should also perform regular audits, update documentation as systems change, and invest in training and resources for their teams. Ultimately, strong configuration management enables organizations to proactively identify risks and maintain secure, compliant environments as they grow.
Notes
In this episode, host Allie Krings sits down with Shannon Lane, Lead Practitioner at KirkpatrickPrice, to break down configuration management — the broad, often overlooked practice of knowing exactly what’s in your environment and how it’s built. Shannon explains why long-term breaches usually trace back to a misconfiguration that nobody documented or caught early on, what it really takes to build a solid configuration standard, and why resourcing, not technical skill, is the most common finding she sees on audits. She also shares a standout example of a client who got configuration management right by treating infrastructure like code, and explains why change management and configuration management are more connected than most people realize. It’s a deep dive into the unglamorous work that quietly keeps everything else secure.
At KirkpatrickPrice, we’re on a mission to help 10,000 organizations raise the bar for cybersecurity and compliance. Join Our Cybersecurity Mission. If you’re going to invest in an audit, it should deliver real value. That’s why we partner with you from audit readiness to final report, ensuring you get the assurance you deserve.
Ready to strengthen your security and compliance posture? Connect with an expert today and learn how we can help you meet your toughest goals.
Send a Question
Do you have a question for our podcast? Send it to us here.
