Skip to main content
Category: Security Policies & Standards

Baseline Configuration

Also known as: Configuration Baseline, Baseline (configuration management)
Simply put

A baseline configuration is a documented, approved snapshot of how a system should be set up at a specific point in time. It acts as a known-good reference point that teams can compare against later to detect unauthorized changes, maintain consistency, and support security. Any future changes are measured against this agreed-upon starting state.

Formal definition

A baseline configuration is a formally reviewed and approved set of specifications for a system or a configuration item within a system, established at a given point in time and serving as the reference against which subsequent changes are evaluated and controlled. In configuration management practice, it captures the agreed attributes of a system or component and provides the basis for change control, drift detection, and configuration verification. Baselines are typically maintained through a defined change management process, and in tooling such as endpoint or compliance management platforms they may be composed of predefined configuration items and, optionally, nested baselines used to assess systems against required settings. A virtual CISO engagement may advise on the governance, review, and approval processes surrounding baseline configurations, but the hands-on creation, deployment, and enforcement of technical baselines typically remain operational tasks outside the standard scope of vCISO advisory work unless explicitly contracted.

Why it matters

A baseline configuration matters because it provides an authoritative, known-good reference point against which all subsequent system changes can be measured. Without a documented and approved baseline, organizations lose the ability to distinguish authorized changes from unauthorized ones, making configuration drift difficult to detect and control. This reference point underpins change control, drift detection, and configuration verification, which are core disciplines in maintaining both operational consistency and security posture.

From a governance perspective, baseline configurations translate abstract security intentions into concrete, verifiable specifications. When a system is set up in a standardized way from the outset, teams can maintain consistency across similar systems and more readily identify deviations that may indicate misconfiguration, unapproved modifications, or potential compromise. The formally reviewed and agreed-upon nature of a baseline is what gives it authority: it is not simply how a system happens to be configured, but how it has been approved to be configured at a given point in time.

For security leadership, the value of a baseline depends heavily on the discipline surrounding it. A baseline that is documented but never enforced, reviewed, or updated through a defined change management process loses much of its usefulness. The effectiveness of baseline configuration practices therefore reflects an organization's broader configuration management maturity and its willingness to sustain the governance processes that keep baselines current and meaningful.

Who it's relevant to

Security and IT Operations Teams
Operations teams are typically responsible for the hands-on creation, deployment, and enforcement of baseline configurations. They use baselines as the standardized setup that defines how systems should run and as the reference point for detecting configuration drift and unauthorized changes across similar systems.
Virtual and Fractional CISOs
A vCISO or fractional CISO commonly advises on the governance, review, and approval processes that surround baseline configurations, helping ensure a defined change management process exists. However, the technical implementation and enforcement of baselines generally remain outside the standard advisory scope unless explicitly contracted, so the distinction between advising on governance and executing operational work should be made clear in the engagement.
Compliance and Governance Stakeholders
Those responsible for configuration management and change control rely on baselines as the formally approved state of a system at a point in time. A well-maintained baseline supports configuration verification and provides an audit-ready reference, though its usefulness depends on organizational maturity and sustained adherence to the change management process.
Executive and Risk Owners
Organizational officers and risk owners retain accountability for security decisions, including how configuration baselines are established and maintained. While advisors and operations teams support the process, the responsibility for sustaining the governance discipline behind baselines ultimately rests with the client organization.

Inside Baseline Configuration

Approved Configuration Settings
A documented, agreed-upon set of parameters for systems, applications, and network devices, such as operating system hardening options, service enablement, and access control settings, that represents the accepted secure state for a given asset type.
Version and Change Documentation
Records that identify the specific version of a baseline and the history of authorized changes, allowing an organization to track how the accepted configuration has evolved over time and to distinguish approved deviations from unauthorized drift.
Scope and Asset Coverage
A definition of which systems, environments, or asset classes a given baseline applies to, since baselines often differ by platform, sensitivity, or business function rather than being a single universal standard.
Reference to Frameworks or Benchmarks
A baseline may draw on external guidance such as NIST CSF outcomes, ISO 27001 control objectives, or published hardening benchmarks. These sources inform the settings but a documented baseline does not by itself constitute certification or a guarantee of compliance.
Deviation and Exception Handling
A defined process for recording, approving, and reviewing configurations that intentionally differ from the baseline, so that exceptions are governed rather than treated as silent, undocumented drift.

Common questions

Answers to the questions practitioners most commonly ask about Baseline Configuration.

Isn't a baseline configuration just the default settings that come with a system or product?
No, and this is a common misconception. Vendor defaults are a starting point, not a baseline. A baseline configuration is a documented, approved set of settings that an organization deliberately establishes as the standard secure state for a given system type. It typically reflects hardening decisions, disabled unnecessary services, and organization-specific security requirements that go well beyond out-of-the-box defaults. Treating defaults as a baseline often leaves systems more permissive than intended.
If we set a baseline configuration once, are we done and protected from misconfiguration?
Not really. A baseline is not a one-time task. It is a reference point that must be maintained, versioned, and reviewed as systems, threats, and business needs change. Configuration drift, where live systems gradually diverge from the approved baseline, is common and requires ongoing monitoring to detect. Establishing a baseline supports better configuration management, but it does not by itself guarantee that systems remain compliant or secure over time.
Who should own and approve the baseline configuration in our organization?
Ownership typically sits with the teams responsible for the affected systems, such as IT operations or platform engineering, while security leadership provides governance and approval criteria. In many engagements, a virtual CISO helps define the standards, review processes, and approval workflow rather than authoring every technical setting. Accountability for maintaining the baseline generally remains with the client organization; the vCISO advises and directs but does not usually assume operational ownership unless the contract specifies it.
How do baseline configurations relate to frameworks like NIST CSF or ISO 27001?
Several frameworks and standards treat configuration management and secure baselines as an expected practice, and maintaining documented baselines can support readiness efforts toward standards such as ISO 27001, SOC 2, or alignment with NIST CSF. However, having a baseline does not by itself assert or guarantee certification or compliance. It is one supporting control among many, and how it is evaluated may vary by auditor, framework, and scope.
How often should we review or update our baseline configurations?
Review cadence varies by organization, system criticality, and rate of change. Many organizations review baselines on a defined periodic schedule and also update them in response to significant events, such as major software upgrades, newly identified vulnerabilities, or changes in regulatory or contractual requirements. The appropriate frequency often depends on organizational maturity and the resources available to maintain and validate changes.
How do we detect when systems drift away from the approved baseline?
Detecting drift typically involves comparing the current state of systems against the documented baseline, often using configuration management tooling or automated scanning. It is worth noting that operating and administering such tools is generally an operational task; a virtual CISO usually advises on the process, standards, and remediation priorities rather than performing hands-on monitoring or tool administration unless that work is explicitly contracted. The effectiveness of drift detection depends heavily on the baseline being well documented and on access to the relevant systems and stakeholders.

Common misconceptions

A baseline configuration is set once and remains valid indefinitely.
Baselines typically require periodic review and update as software versions, threats, and business requirements change. A stale baseline can drift out of alignment with current risk and often needs revalidation as part of an ongoing governance process.
Establishing a baseline configuration is a hands-on task a virtual CISO performs directly on systems.
A virtual CISO generally advises on and directs the definition, governance, and review of baselines as a strategy and governance function. Hands-on implementation, tool administration, and enforcement typically fall to internal operational staff or contracted providers unless the engagement explicitly includes such work.
Having an approved baseline guarantees compliance or prevents breaches.
A baseline supports readiness and reduces configuration-related risk, but it does not by itself assert certification against a framework or guarantee security outcomes. Its value depends on consistent enforcement, monitoring, organizational maturity, and stakeholder cooperation.

Best practices

Document baselines explicitly for each relevant asset class and record the version, scope, and change history rather than relying on undocumented conventions.
Establish a formal deviation and exception process so intentional differences from the baseline are approved and reviewed rather than treated as unmanaged drift.
Review and update baselines on a defined cadence and after significant changes to software, threats, or business requirements, since a stale baseline may no longer reflect current risk.
Where a virtual CISO is engaged, keep their role focused on advising, directing, and governing the baseline while assigning hands-on implementation and enforcement to internal or contracted operational teams under a clearly defined scope.
Use external frameworks or hardening benchmarks as reference inputs to inform settings, while communicating clearly that a baseline supports readiness and does not by itself constitute certification or compliance.
Clarify that accountability for accepting and maintaining the baseline remains with the client organization and its officers, with the advisor's role limited to guidance unless a contract specifies otherwise.