Security baseline

A defined minimum set of security controls or configuration settings for a class of systems or data, usually adopted from a published source such as the NIST SP 800-53B baselines.

A security baseline, or simply a baseline, is the minimum set of security controls or configuration settings that applies to every system or data set in a given class. NIST SP 800-53B publishes low, moderate and high control baselines, plus a privacy baseline, and a federal system is matched to one according to its impact level under FIPS 199. At the level of individual settings, the CIS Benchmarks and the DISA Security Technical Implementation Guides (STIGs) do the same job. In configuration management the word also means the approved configuration that later changes are measured against.

A baseline is a starting point, not a finished control set. Scoping removes baseline controls that do not apply to the environment, and tailoring adjusts the controls that remain, including adding compensating controls where one cannot be implemented as written. Hardening applies a configuration baseline to a system, and change management keeps it current so that drift can be detected. Choosing which published baseline to start from is part of standards selection.

Exam relevance: questions in this area tend to turn on sequence. Candidates are expected to see that a baseline is selected first and then scoped and tailored, and to recognise that a baseline sets a floor of protection for a class of system rather than the ideal level for any single one.