Security requirements

Keep your security configuration working as requirements change

Adopting a security configuration creates a continuing responsibility to maintain it. Devicie develops and tests configurations informed by supported CIS Benchmarks, corrects drift in managed policies and gives your team a process for deliberate changes.

Standard and process

Put CIS recommendations into ongoing practice

CIS Benchmarks provide technology-specific secure-configuration recommendations. CIS publishes distinct guidance for Microsoft Intune and related Microsoft technologies, so the exact benchmark and version matter.

Your team needs to decide which recommendations apply, evaluate their effect on the business and maintain the configuration it adopts.

That work continues after deployment. A policy can be changed during troubleshooting, and a new benchmark release can introduce recommendations that need evaluation.

Supported recommendations

Turn supported recommendations into managed configuration

Devicie's specialists evaluate changes to security benchmarks and Intune capabilities, then develop, test and refine Devicie configurations.

Your team can draw on that work when planning its configuration. Devicie also supports adopting existing configuration, with the supported policy scope agreed for your environment.

The starting point should reflect the devices you manage, your business requirements and the configuration you intend to maintain.

Drift and deliberate change

Keep agreed managed settings in place

When a managed policy drifts from its agreed state, Devicie restores it and sends a readable notification explaining the change and correction.

For an intentional change, a pause, edit and resume workflow provides a defined process. Your team retains responsibility for who can make changes and what the revised configuration should achieve.

Maintaining the agreed policy and updating the agreed standard are separate activities. Drift correction restores the current agreement; your team decides how to adopt configuration improvements.

Health Check Pillar mix-1
Health Check reporting — CIS 3.0 compliance, OS patching, applications distribution, device warranty and endpoint protection across the fleet. Illustrative dashboard.

Coverage

Make configuration and assessment coverage clear

Before evaluating results, establish three things.

QuestionWhat to establish
Which standard are we using?The full benchmark name, version, applicable profile and device scope.
What is being configured?The supported recommendations implemented through the managed policies, including any modifications or exceptions.
What is being assessed?The recommendations checked by the assessment, how each result is determined and what is outside its coverage.

Using the results

Configuration support and reporting coverage can differ. Use the actual scope of each when deciding what a result means.

A deployed policy is also distinct from the effective state on a device. Your review should account for device receipt and any additional checks needed to establish that state.

Give security and IT a common decision

Start with a recommendation your teams want to implement. Confirm its applicable benchmark and profile, review the supported configuration and test its effect on business workflows.

Then agree the managed policy state and deliberate-change process. Inspect a correction notification when a supported managed setting is changed.

Security can assess the intended requirement while IT reviews deployment and compatibility. Both teams understand the remaining exceptions and the checks needed on devices.

Where to begin

Start with the current configuration

The Intune Health Assessment provides a review of your environment within an agreed scope, with findings your team can use to prioritize next steps.

Use the findings to discuss which settings should be addressed, which need a business decision and how the resulting configuration will be maintained.

Questions we get asked

Does supported configuration mean every benchmark recommendation is implemented?

No. Review the exact supported recommendations and any exceptions for your selected benchmark and device scope.

Does a configuration change automatically update our assessment coverage?

Configuration and assessment are separate capabilities. Confirm the benchmark version and recommendation coverage for each.

Can we keep configuration we already use?

Devicie supports adopting existing configuration. Review supported policy types and the adoption process for your environment.

What happens when a benchmark changes?

Devicie's specialists evaluate benchmark changes when developing its configurations. Your team should review the available updates and decide how they fit its requirements.

Review the standard, the implementation and the ongoing work

Bring the benchmark you use and the configuration your team maintains. Walk through the supported scope, drift correction and intentional-change process.