Instiq
Chapter 5 · Security Policies and Procedures·v1.0.0·Updated 7/20/2026·~16 min

What's changed: Initial version

5.1Security management concepts

Key points

Covers asset management to know what you protect, configuration management to keep an approved state, MDM to govern mobile devices, patch management to close known flaws, and vulnerability management to continuously assess and prioritize weaknesses—framed as the operational judgment of "which management process addresses this risk."

Security operations is not only dramatic incident response; the unglamorous management processes underneath it are the foundation. "We do not know what is connected," "an unapproved configuration change slipped in," "a patch has gone unapplied for months"—such management gaps hand attackers their first foothold. This section organizes the five management concepts—asset, configuration, mobile device, patch, and vulnerability—by which risk each one is meant to eliminate, so you can choose the right process for the situation.

5.1.1Asset and configuration management

  • Asset management is the process of identifying, classifying, tracking, and inventorying assets such as hardware, software, and data. Because you cannot protect, patch, or monitor what you do not know you have, it is the starting point for all management. Shadow IT and end-of-life devices missing from the inventory tend to become entry points, unmonitored and unpatched.
  • Configuration management defines an approved known-good state (baseline) and governs changes, preventing unauthorized changes and configuration drift while making deviations detectable. During an incident, the difference from the "normal configuration" is itself a clue to compromise, so it also serves as a forensic reference line.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.