Skip to main content
All answers

What is configuration drift?

Configuration drift is the accumulation of unauthorized or undocumented configuration changes between formal baselines: small modifications that erode compliance posture between audit cycles. Common causes: troubleshooting changes that don't get reverted, firefighting under operational pressure, and legitimate administrative actions that bypass change-management. Continuous monitoring with drift detection catches these in minutes, not at the next quarterly audit.

The longer answer.

Drift is rarely the result of malice; it is the natural entropy of a live environment. A setting is loosened to unblock an incident at 2 a.m. and never tightened again, a default reverts after a patch, a temporary firewall exception outlives the reason it was created. Each change is individually reasonable, but collectively they move a system away from the hardened state it was signed off in, without anyone deciding to weaken security.

What makes drift dangerous is the detection lag. If systems are only checked at audit time, a control can sit broken for a whole cycle before anyone notices, and by then the audit finding is the first signal. Detecting configuration changes against a known baseline shortly after they happen converts that slow, invisible decay into a prompt alert an operator can act on while the context is still fresh.

More questions on Fundamentals?

Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.