Secure Configuration Baseline
A secure configuration baseline is a documented, agreed-upon set of security settings applied to a system or device to give it a basic, hardened level of protection against attack. It acts as a known starting point that has been reviewed and approved, so an organization can consistently configure its IT assets and detect when settings drift away from the approved state. These baselines often supplement, rather than replace, an organization's own requirements and risk decisions.
A secure configuration baseline is a formally reviewed and approved set of configuration specifications for a system or configuration item, captured at a given point in time, that hardens the asset by defining recommended security settings and their implications. In practice, baselines are often expressed as adoptable policy configuration recommendations (for example, CISA's Microsoft 365 baselines or Microsoft's Windows security baselines) that organizations tailor to their unique requirements and risk tolerance. Baselines support hardening, configuration consistency, and change/drift detection, but their effectiveness depends on scoping, enforcement, and ongoing management; establishing a baseline does not by itself guarantee compliance with any framework or certification, and accountability for accepting residual risk and any deviations remains with the owning organization.
Why it matters
A secure configuration baseline addresses one of the most common and preventable sources of security exposure: systems and devices deployed with default, inconsistent, or unhardened settings. Without an agreed-upon starting point, each asset can be configured differently, creating gaps that attackers can exploit and that are difficult for a security team to see or measure. A documented, formally reviewed baseline gives an organization a known, approved state against which it can consistently configure assets and detect when settings drift away from that state.
Baselines also provide a governance anchor. Published, adoptable recommendations such as CISA's Microsoft 365 secure configuration baselines and Microsoft's Windows security baselines give organizations a credible reference point rather than requiring them to define every setting from scratch. As CISA describes them, these baselines are meant to complement an organization's own unique requirements and risk decisions, not override them. From a security leadership perspective, this makes a baseline a useful tool for translating abstract hardening goals into concrete, reviewable specifications that stakeholders can approve.
It is important not to overstate what a baseline delivers. Establishing a baseline does not by itself guarantee compliance with any framework or certification, nor does it prevent breaches on its own. Its value depends on how well it is scoped, enforced, and maintained over time, and accountability for accepting residual risk and for approving any deviations remains with the owning organization and its officers.
Who it's relevant to
Inside Secure Configuration Baseline
Common questions
Answers to the questions practitioners most commonly ask about Secure Configuration Baseline.