Guides
- NIST SP 800-128 – Guide for Security-Focused Configuration Management of Information Systems
- SANS Institute – Secure Configuration Management Demystified
Example Tools
Sample Policy & Procedures
- Department of Education – Information Technology Configuration Management Plan Guide
- Environmental Protection Agency – Information Procedure CIO-2150.3-P-05.1 – Information Security – Interim Configuration Management Procedures