📖 What is Baseline?

A Baseline is a minimum set of security controls and configurations that must be applied to a system to ensure a consistent level of protection. It provides a known good state that can be used to detect unauthorized changes over time.

🥋 Sensei Says:

"Think of a baseline as the security floor. Anything below the baseline is considered non-compliant and must be remediated."

📚 Certification: Certified in Cybersecurity (CC)

🔑 What are the Key Concepts of Baseline?

  • Baselines are central to configuration management, ensuring all systems start from a standardized, approved security posture to significantly reduce the overall attack surface.
  • By comparing current system states against the established baseline, administrators can quickly identify unauthorized changes, potential compromises, or what is known as configuration drift.
  • Baselines serve as the technical benchmark for audits, allowing organizations to prove that their systems meet minimum regulatory requirements or internal security standards.
  • When a system falls below the baseline, it is flagged as non-compliant, triggering a remediation process to return the system to its known good state.
  • Standardized baselines prevent the creation of 'snowflake' systems, which are unique, undocumented configurations that are significantly harder to secure, patch, and manage at scale.

🎯 How does Baseline appear on the CC Exam?

You may be asked to identify the best method for detecting unauthorized changes to a server's configuration. The correct answer will involve comparing the current system state against a documented security baseline to find discrepancies.

A scenario might describe a company deploying hundreds of new workstations. Expect questions about how to ensure every machine meets the same minimum security standards by applying a pre-approved baseline image.

Expect questions where you must distinguish between a high-level security policy and a technical baseline, specifically when asked which document provides the actual minimum configuration settings for a system.

❓ Frequently Asked Questions

What is the difference between a security policy and a security baseline?

A policy is a high-level directive stating what must be achieved, such as 'all systems must be hardened.' A baseline is the specific technical implementation, such as 'disable Telnet and set password length to 14 characters.'


How does a baseline help in incident response?

During an investigation, a baseline provides a 'known good' reference point. By comparing the compromised system to the baseline, responders can isolate exactly which files or settings the attacker modified to gain access.

Related Terms from Certified in Cybersecurity

📝 Related Study Guides

Study Guide 8 min read

ISC2 CC Certification Guide: Your Free Entry into Cyber

The ISC2 Certified in Cybersecurity (CC) is a free, entry-level certification designed for beginners. It covers five core domains—Security Principles, BCP/DR, Access Control, Network Security, and Security Operations—via a 100-question exam. It's the ideal starting point for career changers to build a foundation without financial barriers.

Exam Tips 8 min read

ISC2 CC Exam Domains: What You Need to Know to Pass

The ISC2 CC exam consists of five domains: Security Principles, Business Continuity (BC), Disaster Recovery (DR), and Incident Response (IR), Access Controls, Network Security, and Security Operations. To pass, you must master the CIA Triad and security governance, while prioritizing high-weight domains through targeted practice and domain-specific analytics.

Deep Dive 10 min read

Mastering the CIA Triad for ISC2 CC: A Deep Dive

The CIA triad is the foundational model of information security, consisting of Confidentiality (preventing unauthorized access), Integrity (ensuring data accuracy and consistency), and Availability (guaranteeing reliable access to resources). Balancing these three pillars allows security professionals to manage risk effectively and protect organizational assets against diverse cyber threats.

🧠

Test Your Knowledge

Think you understand Baseline? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium