A Security Baseline is a specialization of Baseline that establishes an approved reference for security controls, configuration values, constraints, and expected security characteristics.
The general concept of Baseline provides the controlled reference against which a subject can be compared, evaluated, changed, or restored.
A Security Baseline applies that concept to the security characteristics of a subject such as:
A Security Baseline may identify:
A Security Baseline differs from a security policy:
A Security Baseline also differs from an observed security state:
Comparing the observed security state with the Security Baseline may identify a Compliance Finding.
baseline that establishes an approved reference for the security controls, configuration values, constraints, and expected security characteristics of a subject
Dido Solutions, Inc. and Jackrabbit Consulting, Inc.
A Security Baseline may derive from:
A Security Baseline should have an identifiable revision so an evaluator can determine which reference applies to a particular assessment, deployment, or operational state.
Approval of a Security Baseline does not establish that every subject conforms to it. Conformance requires comparison of the subject with the applicable Security Baseline.
The term does not require a particular security framework, assessment method, configuration format, repository, tool, or implementation technology.
A Security Baseline for a Red Hat Enterprise Linux Machine Image specifies permitted services, authentication settings, cryptographic settings, logging requirements, file permissions, network controls, and required security patches. An evaluator compares the resulting Machine Image with that Security Baseline to determine whether the image satisfies the applicable security requirements.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.