Security baseline controls
Baseline means basic requirements. A security baseline means a minimum basic requirement for security. The objective of implementing a security baseline throughout the organization is to ensure that controls are consistently implemented as per acceptable risk levels. The level of the baseline is set as per asset classification. For example, for critical applications it is mandatory too have at least two-factor authentication whereas for non-critical applications it is mandatory to have at least one-factor authentication. In other words, the baseline for critical applications is two-factor authentication whereas the baseline for non-critical applications is one-factor authentication.
Benefits of a security baseline
The following are the benefits of a security baseline:
- It helps to standardize the basic security requirements throughout the organization.
- A baseline provides a point of reference against which improvement can be measured....