← PCI DSS 4.0.1 · Req 2 — Secure configurations

2.2 — Secure configuration of system components

high config-management

Requirement

System components are configured and managed securely: configuration standards address known vulnerabilities and are consistent with industry hardening standards, vendor default accounts are removed or have their passwords changed, and only necessary services are enabled.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
configuration standardconfiguration standardshardeningharden…cis benchmarksecure configurationbaseline
Required element 2 — any one of
vendor defaultdefault accountsdefault passwordsunnecessary servicesnecessary servicesapplieddocumentedenforcedindustry
Supporting terms — specificity signals
2.2.12.2.22.2.4infrastructure as codegolden imagedrift
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

default passwords are in use default password is still

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
ISO 27001 A.8.9 Configuration management config-management
SOC 2 CC7.1 Detection of configuration changes and vulnerabilities config-management
SOC 2 CC5.2 Technology general controls config-management