Technology · Security · Component

Security control baseline

The recognised set of security controls the organisation has adopted, tailored to its threats, with the honest status of each.

The deliverable

What it is

A baseline avoids inventing security from first principles. ISO/IEC 27001 Annex A, the CIS Controls and national schemes such as Cyber Essentials each offer a set of controls tested across many organisations; the work is choosing one, tailoring it, and knowing where the organisation stands against it.

The baseline is technical and operational. Independent testing of whether controls operate belongs to Compliance under monitoring, which can use this baseline as its reference instead of keeping a second list.

One level in

What it is made of

Each element is a constituent part of the component. Follow one to see the attributes it carries.

  1. Chosen framework

    Which reference set of controls was adopted, which version, and the reasoning for choosing it.

    3 attributes: Framework · Version · Chosen because

    Learn
  2. Control status

    For each control: implemented, partial, planned or deliberately not applied, with a justification for each gap.

    4 attributes: Control · Implementation · Owner · Justification

    Learn
  3. Improvement backlog

    The controls not yet in place, ordered by the threat scenarios they would reduce and the effort they need.

    3 attributes: Control · Priority · Target date

    Learn

Adopt a baseline; do not write one. The value of a recognised set is that others have already argued over it.