Skip to content
IT Atlas

Secure

Control baselines

Controls stated as outcomes rather than product purchases. Each baseline gives the objective, the implementation steps that satisfy it, the evidence that demonstrates it during an audit or a board review, and the framework clauses it maps to.

10 baselines
A reference architecture schematic: users, remote workforce and branch office feed edge connectivity, DNS, perimeter security, the access layer and the core network, which reaches compute, applications, data, the data centre, cloud platforms and backup, with monitoring and security operations spanning the estate.
Controls are layered deliberately: identity, endpoint, network and recovery each assume the others will sometimes fail.

How to use these baselines

  • Assess against the objective, not the step list. A different implementation that achieves the stated outcome is equally valid.
  • Evidence is part of the control. If nobody can produce the artefact named, the control is not operating, however well it is intended.
  • Framework references are mappings, not certifications. Meeting a baseline does not by itself satisfy an audit scope.
  • Order matters: inventory, identity and recovery first. Detection without those three produces alerts nobody can act on.

Filter by area

FoundationCIS Controls 1 & 2NIST CSF ID.AMISO 27001 A.5.9

Authoritative asset and identity inventory

Maintain a single, reconciled view of devices, servers, cloud resources, identities and internet facing services.

Implementation

  • Reconcile at least three sources: directory, device management and network or cloud discovery.
  • Record an owner and a business service for every asset, not just a hostname.
  • Treat anything discovered but unmanaged as an exception with a due date.
  • Include internet facing services and public DNS records in the same inventory.

Evidence

Dated inventory export with unmanaged asset count and exception list.

Reduces

IdentityCIS Control 6NIST CSF PR.AAISO 27001 A.5.15 A.5.18NIST SP 800-207

Identity access baseline

Every interactive sign in is multi factor, legacy authentication is impossible, and privilege is temporary.

Implementation

  • Require phishing resistant multi factor for administrators and remote access.
  • Block legacy authentication protocols outright at the identity provider.
  • Remove standing privileged role assignment; require activation with approval and expiry.
  • Separate cloud only administrative accounts from everyday user accounts.
  • Maintain break glass accounts, excluded from conditional access, stored offline and monitored.

Evidence

Policy export, count of privileged standing assignments, legacy auth sign in report.

Reduces

EndpointsCIS Controls 4 & 10NIST CSF PR.PSISO 27001 A.8.1

Managed endpoint baseline

Every device that accesses corporate data is enrolled, configured to a baseline, encrypted, patched and monitored.

Implementation

  • Enrolment as a condition of access, enforced by conditional access rather than policy text.
  • Apply a published security baseline and record every deviation with a reason.
  • Full disk encryption with escrowed recovery keys.
  • Remove standing local administrator rights; unique rotated local admin passwords.
  • Endpoint detection with tamper protection and centrally enforced policy.

Evidence

Compliance report by policy, encryption coverage, agent health percentage.

Reduces

NetworkCIS Controls 12 & 13NIST CSF PR.IRISO 27001 A.8.20 A.8.22

Network segmentation and egress control

Traffic is permitted by explicit intent, east west movement is constrained, and outbound access from servers is limited.

Implementation

  • Document intended flows per zone before writing rules; remove any any rules.
  • Block workstation to workstation administrative protocols with host firewall policy.
  • Restrict management protocols to dedicated administrative sources.
  • Filter server egress to named destinations; alert on anything else.
  • Place management interfaces of infrastructure on an out of band network.

Evidence

Zone to zone flow matrix, rule review date, count of any any rules remaining.

Reduces

ApplicationsCIS Control 9NIST CSF PR.DSISO 27001 A.8.23

Email authentication and message hygiene

Your domains cannot be trivially spoofed, and inbound messages are inspected at delivery and after it.

Implementation

  • Publish SPF, DKIM and a DMARC policy that moves beyond monitoring to reject.
  • Enable link and attachment inspection, including time of click evaluation.
  • Block or quarantine external senders impersonating internal display names.
  • Alert on mail forwarding rules created to external destinations.
  • Give users a one click report path with a triage service behind it.

Evidence

DNS record export, DMARC aggregate reports, forwarding rule alert history.

Reduces

OperationsCIS Control 7NIST CSF ID.RAISO 27001 A.8.8

Vulnerability and patch cadence

Exposure is measured continuously, and remediation timescales are defined by exposure and exploitation, not by convenience.

Implementation

  • Authenticated scanning across servers, endpoints, cloud workloads and appliances.
  • Separate emergency lane for internet facing and actively exploited vulnerabilities.
  • Defined remediation windows by severity, agreed with service owners in advance.
  • Track exceptions with a compensating control and an expiry date.
  • Report trend and ageing, not raw vulnerability counts.

Evidence

Ageing report by severity, patch compliance percentage, open exception register.

Reduces

DetectionCIS Control 8NIST CSF DE.CMISO 27001 A.8.15 A.8.16MITRE ATT&CK

Logging and detection coverage

The sources that matter are collected, retained long enough to investigate, and mapped to the techniques you care about.

Implementation

  • Collect identity provider, endpoint, network edge, cloud control plane and email telemetry as a minimum.
  • Retain at least twelve months for identity and authentication data.
  • Map detection rules to technique coverage and record the gaps deliberately.
  • Alert on absence of telemetry, not only on events.
  • Write each alert with a triage procedure, or do not deploy it.

Evidence

Source inventory with ingestion status, retention settings, technique coverage map.

Reduces

ResilienceCIS Control 11NIST CSF PR.DS & RC.RPISO 27001 A.8.13

Protected and tested recovery

At least one backup copy cannot be destroyed by an intruder holding production administrative rights, and restores are proven.

Implementation

  • Immutable retention on at least one copy, plus one logically isolated or offline copy.
  • Backup administration on separate credentials, outside the production directory.
  • Protect configuration and identity data, not just file and database content.
  • Test restores on a schedule and record actual elapsed time against the agreed objective.
  • Document dependency order for recovery, including DNS, identity and certificates.

Evidence

Restore test records with elapsed times, immutability settings, isolation design.

Reduces

GovernanceCIS Control 15NIST CSF GV.SCISO 27001 A.5.19 A.5.22

Third party and integration access control

Every external party and application integration has a named owner, bounded access and an expiry.

Implementation

  • No standing privileged access for providers; use approved, time bound activation.
  • Inventory application registrations and integration accounts with granted scopes.
  • Review and expire granted permissions on a fixed cycle.
  • Require your own multi factor and device conditions on partner identities.
  • Record notification and log sharing obligations in the contract.

Evidence

Third party access register, application permission review records, contract clauses.

Reduces

ResponseCIS Control 17NIST CSF RS.MANIST SP 800-61ISO 27001 A.5.24 A.5.28

Tested incident response capability

Response authority, communications and evidence handling are agreed before an incident, and rehearsed.

Implementation

  • Named incident commander role and a documented authority to disconnect systems.
  • Out of band communication channel that survives loss of the production estate.
  • Evidence preservation steps that precede remediation, including identity data that ages out.
  • Contact list covering legal, insurance, regulator and key suppliers, kept current.
  • Exercise at least annually, including a scenario where the identity provider is compromised.

Evidence

Plan version and approval date, exercise report, contact list review date.

Reduces