Technology · Security · Component
Security control baseline
The recognised set of security controls the organisation has adopted, tailored to its threats, with the honest status of each.
The deliverable
What it is
A baseline avoids inventing security from first principles. ISO/IEC 27001 Annex A, the CIS Controls and national schemes such as Cyber Essentials each offer a set of controls tested across many organisations; the work is choosing one, tailoring it, and knowing where the organisation stands against it.
The baseline is technical and operational. Independent testing of whether controls operate belongs to Compliance under monitoring, which can use this baseline as its reference instead of keeping a second list.
One level in
What it is made of
Each element is a constituent part of the component. Follow one to see the attributes it carries.
Chosen framework
Which reference set of controls was adopted, which version, and the reasoning for choosing it.
3 attributes: Framework · Version · Chosen because
LearnControl status
For each control: implemented, partial, planned or deliberately not applied, with a justification for each gap.
4 attributes: Control · Implementation · Owner · Justification
LearnImprovement backlog
The controls not yet in place, ordered by the threat scenarios they would reduce and the effort they need.
3 attributes: Control · Priority · Target date
Learn
Adopt a baseline; do not write one. The value of a recognised set is that others have already argued over it.
The other components in security
Threat model
What is worth protecting, who might want it, and the plausible routes by which harm could arrive.
LearnIdentity and access arrangements
How people and systems prove who they are, what privileged accounts exist, and how access follows people as they join, move and leave.
LearnBackup and recovery plan
What is backed up, how quickly each critical system must return, and dated evidence that restoring actually works.
Learn