Minimum Baseline Security Standard Development
A set of guidelines and requirements for the minimum secure configuration information systems must meet, tailored to your organization and industry.

What this achieves.
Minimum configuration levels
Establishes the minimum security configuration every system must meet to safeguard sensitive information.
Deployment guidelines
Delivers guidelines and requirements for deploying effective security controls across systems.
Regulatory compliance
Helps fulfill legal and regulatory obligations regarding information protection.
How the standard is built.
Built from system security benchmarks, vendor-recommended practices, security hardening guidelines from research institutes, established security standards, and our own field expertise.
Deliverables.
Where this connects.
Common questions.
Is the standard generic, or specific to us?
Specific. The baseline is tailored to your organization and industry, and the deliverable is a minimum-level security configuration standard written per system rather than one blanket document.
What is the standard built from?
System security benchmarks, vendor-recommended practices, security hardening guidelines from research institutes, established security standards, and our own field expertise.
Does this help with regulatory obligations?
Yes. One of the stated objectives is helping fulfil legal and regulatory obligations regarding information protection, by fixing a defensible minimum every system has to meet.
How does this relate to a configuration review?
This engagement defines the standard systems should meet. A Low-Level Secure Configuration Review measures existing systems against that kind of standard and reports the gaps.