Configuration Drift
Configuration drift is when a system's actual settings gradually move away from the intended, approved baseline over time. This usually happens unintentionally through small, undocumented, or manual changes that accumulate. As a result, the system no longer matches its desired state, which can create security and reliability gaps.
Configuration drift refers to the progressive divergence of a network, application, device, or other IT system's actual configuration from its defined baseline or desired state. It typically arises from incremental, manual, or untracked changes made over time rather than through controlled, documented processes. In a security context, drift includes deviation of security settings from their intended state, which can undermine posture and compliance assurance until the configuration is detected, reconciled, and returned to baseline.
Why it matters
Configuration drift matters because security posture is only as reliable as the baseline that defines it. When systems gradually diverge from their approved configurations through incremental, manual, or untracked changes, the protections an organization believes are in place may no longer reflect reality. A firewall rule loosened for a troubleshooting session, an encryption setting left disabled after testing, or a permission expanded for convenience can persist undocumented and quietly widen the attack surface. Because drift accumulates slowly, it often goes unnoticed until an audit, an incident, or a compliance review exposes the gap.
Drift also undermines compliance assurance. Frameworks and control regimes such as NIST CSF, ISO 27001, SOC 2, HIPAA, and PCI DSS generally assume that documented configurations are actually enforced and maintained over time. When actual settings deviate from the intended state, an organization may believe it is meeting a control while the evidence on the system tells a different story. It is important to be precise here: detecting and reconciling drift supports compliance readiness, but it does not by itself guarantee certification or continuous compliance, which depend on broader governance, evidence, and audit processes.
From a leadership perspective, configuration drift is a governance and risk issue as much as a technical one. It typically arises where change management is weak, ownership is unclear, or manual changes are made without documentation. Left unmanaged, drift erodes both security and reliability, making systems harder to predict, troubleshoot, and defend. Treating drift as a symptom of process gaps, rather than a purely technical nuisance, is what distinguishes mature security programs from reactive ones.
Who it's relevant to
Inside Configuration Drift
Common questions
Answers to the questions practitioners most commonly ask about Configuration Drift.