What is a security baseline?
A plain-English definition · all security terms → · updated August 2026
A security baseline is a pre-defined set of recommended security configuration settings applied consistently across your devices, so every system starts from a known, hardened state. Instead of configuring each laptop or server by hand, you push one vetted baseline — firewall on, secure protocols only, sensible defaults locked down — and reduce the attack surface everywhere at once.
Common security baselines
- Microsoft security baselines — recommended settings for Windows, Edge and Microsoft 365, delivered through Group Policy or Intune.
- CIS Benchmarks — consensus hardening guides from the Center for Internet Security, covering operating systems, cloud and applications.
- DISA STIGs — Security Technical Implementation Guides used in US government and defense environments.
How a baseline is applied
Centrally and repeatably. On Windows that means Group Policy or, increasingly, Microsoft Intune configuration profiles and security baselines — the same hardened settings land on every managed device, and configuration drift is detected and corrected automatically. It is a core step in any secure device build.
Baseline vs patching — you need both
- Security baseline — hardens configuration: settings, permissions, protocols and defaults.
- Patching — fixes flaws in the code: the CVEs in the software itself.
A perfectly baselined device still ships vulnerable if its software is on a known-exploited or end-of-life version. That is the gap IsItPatched closes — verifying the versions you run, while baselines lock down how they’re configured.
Check your own software
- Check a version — confirm the software in your baseline image isn’t already vulnerable.
- End-of-life calendar — don’t bake unsupported software into a gold image.
- Compliance editions — see which frameworks expect a documented, enforced baseline.
Read the secure build checklist →
Frequently asked questions
What is a security baseline?
A security baseline is a pre-defined set of recommended security configuration settings for an operating system, application or device — applied consistently so every system starts from a known, hardened state. It reduces the attack surface and removes the guesswork of configuring each device by hand.
What are some common security baselines?
Widely used baselines include the Microsoft security baselines (delivered via Group Policy or Intune), the CIS Benchmarks from the Center for Internet Security, and DISA STIGs (Security Technical Implementation Guides) used in US government environments.
How is a security baseline applied?
Centrally. On Windows, baselines are pushed through Group Policy or, increasingly, Microsoft Intune configuration profiles and security baselines — so the same hardened settings land on every managed device and drift is detected and corrected.
Is a security baseline the same as patching?
No — they are complementary. A baseline hardens configuration (settings, permissions, protocols, defaults). Patching fixes flaws in the code itself. A perfectly baselined device still needs its software kept current and off end-of-life versions; a fully patched device still needs hardening. You need both.
Do compliance frameworks require security baselines?
Most expect them. Standards such as CIS Controls, ISO 27001, NIST CSF, PCI DSS and Cyber Essentials all call for secure, consistent configuration of systems — a documented, enforced baseline is the usual way to evidence it.
IsItPatched is an independent service. Baseline names (Microsoft security baselines, CIS Benchmarks, DISA STIGs) belong to their respective owners. Always implement baselines from the official source — see our disclaimer. 638 products tracked · 431 CVEs actively exploited now.