A secure baseline is a documented, approved configuration that every system of a given type must meet: which services run, which settings are enforced, which software is installed and how logging works. Baselines turn hardening from a one-off effort into a repeatable standard. The lifecycle has three steps the exam names: establish the baseline (often from CIS Benchmarks or vendor guides, adjusted for business needs), deploy it (through group policy, configuration management tools, images or infrastructure as code), and maintain it (scan for drift, update the baseline when new threats or versions appear, and re-apply it). Mobile devices need baselines too, and managing them depends heavily on who owns the device.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.