What is file integrity monitoring (FIM) and how does it relate to configuration monitoring?
File integrity monitoring (FIM) detects and alerts on changes to critical files: the hashes, permissions, ownership, and content of system binaries, configuration files, and logs. Security configuration management (SCM) is different: it validates that system settings match a hardening baseline such as a CIS Benchmark. The two are complementary layers. FIM tells you that a file changed; SCM tells you whether the resulting configuration is still compliant with the baseline.
The longer answer.
FIM answers "did something change?" by comparing current file state against a known-good snapshot. It is strong at catching tampering with binaries and unexpected edits to configuration files, but it has no opinion about whether the original state was secure in the first place.
Configuration monitoring answers "is this setting correct?" by evaluating each control in a baseline against the live system. In practice mature programs run both: FIM for change detection on critical files, and continuous CIS Benchmark scanning with drift detection so every deviation from the approved baseline is caught and documented.
More questions on Fundamentals?
Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.