Security Baseline
What is Security Baseline?
A set of minimum security standards and configurations that all systems within an organisation must meet. Security baselines provide a consistent foundation for security across the environment and are often based on CIS Benchmarks or vendor hardening guides.
Terms that appear alongside security baseline
Each of these is named in at least one of the same controls as security baseline. The number is how many controls name both.
- baseline 15 shared controls
- information security 10 shared controls
- encryption 9 shared controls
- access control 7 shared controls
- integrity 5 shared controls
- security testing 5 shared controls
- audit 4 shared controls
- cybersecurity 4 shared controls
Frameworks that govern security baseline
What the standards actually require on security baseline
Requirements naming security baseline across 6 standards, quoted from the control text.
Define and keep current the minimum security requirements each class of application must satisfy before it is built or released.
CCM-AIS-02 · Application Security Baseline Requirements →Personnel security + insider threat for aviation cybersecurity covers: (a) FAA Order 1370.123A insider threat program for FAA employees + contractors;
FAA-CSA-Personnel · Personnel Security Training and Insider Threat →FISMA coordination with CIRCIA + Zero Trust + Executive Orders + OMB Memoranda. CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022): Final Rule effective 2026;
FISMA-CIRCIA-ZTA-EO14028 · CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda →ITU-T Recommendation X.805 (10/2003) Security architecture for systems providing end-to-end communications is a foundational network security architecture standard published by the International Telecommunication Union Telecommunication Standardization Sector...
X805-Scope-Architecture-3Layers-3Planes-8Dimensions-5Threats-72Cells-X.800-Series-Heritage · ITU-T X.805 Scope + Security Architecture Overview + 3 Security Layers x 3 Security Planes (9 Modules) x 8 Security Dimensions = 72 Security Perspectives + 5 Threat Categories + X.800-Series Heritage + End-to-End Network Communications →Per IC 24-15-4-5 and IC 24-15-4-10 plus the separate Indiana Personal Information Disclosure Statute IC 24-4.9 (Indiana data breach notification law) controllers and processors must implement security + breach response + and records discipline.
INCDPA-Security-ReasonablePractices-Breach-Notification-Records-Encryption-Pseudonymisation · Indiana CDPA Security + Reasonable Practices + Breach Notification + Indiana Breach Notification Law (IC 24-4.9) + Records + Encryption + Pseudonymisation + De-Identification →Per Iowa Code 715D.5-1 and Iowa Personal Information Security Breach Notification Law (Iowa Code 715C separate statute) controllers and processors must implement security + breach response + records discipline.
ICDPA-Security-ReasonablePractices-Breach-Notification-Iowa-Code-715C-Records-Encryption-Pseudonymisation · Iowa CDPA Security + Reasonable Practices + Iowa Personal Information Security Breach Notification Law (Iowa Code 715C) + Records + Encryption + Pseudonymisation →Questions people ask about security baseline
What is Security Baseline?
Why is Security Baseline important for compliance?
Which compliance frameworks address Security Baseline?
Where can I learn more about Security Baseline?
See how Security Baseline applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.