What is configuration drift?
Configuration drift is the accumulation of unauthorized or undocumented configuration changes between formal baselines: small modifications that erode compliance posture between audit cycles. Common causes: troubleshooting changes that don't get reverted, firefighting under operational pressure, and legitimate administrative actions that bypass change-management. Continuous monitoring with drift detection catches these in minutes, not at the next quarterly audit.
The longer answer.
Drift is rarely one bad change. It is usually many small ones: a firewall rule opened during an incident, an audit policy disabled to reduce log volume, a service re-enabled by a software update. Each looks harmless, but together they move a system away from the hardened baseline it was approved against.
Detecting drift means comparing every scan with the previous baseline rather than only reporting current status. CISGuard classifies each change as an improvement or a regression and alerts on regressions within minutes, so the fix happens while the change is still fresh.
More questions on Fundamentals?
Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.