Secure baselines provide standardized checklists for hardening IT equipment, drawing from sources such as product developers, vendors, government bodies like NIST, and security organizations. Organizations typically adopt, adapt, or combine these baselines to fit their specific environments.
Secure Baselines
With each piece of equipment, we could be taking different steps to go through this hardening process. But how do we know which steps we need to do on different pieces of equipment? We can use secure baselines to do that, to understand what it is that we need to do to harden pieces of equipment.
Think of secure baselines as the checklist of what we need to do to harden a piece of equipment.
Some sources where these secure baselines come from would be, if the product is being developed, whoever is developing that product would create these secure baselines. Also, product vendors: whoever is selling these products will also create secure baselines that we can follow. Or there are a lot of government and other organizations, nonprofit organizations, that will create baselines that you can follow — NIST is an example of that. And then there are also security vendors that are out there that will create secure baselines that we can utilize.
What I have found is that you go and do some research and then you create your own baselines that you are going to follow. So you either choose to follow one of these others, or kind of merge them together to create your own self-created baselines.
Essentially what we need to do is establish what those baselines are going to be, and deploy those baselines. But then there's also a maintenance that occurs with this, that you want to make sure that those baselines continue to be updated as things change.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →