Baseline

An approved, documented secure configuration that systems are compared against.

CIS Benchmarks and DISA STIGs are common baseline sources that prescribe hardened configurations per platform. Once a baseline is approved, configuration-management tooling enforces it and reports deviations; unexplained drift from baseline is a leading indicator of misconfiguration or compromise and a frequent SIEM detection rule.

Related terms

Back to General Security Concepts