WHAT IS A SECURE HOST BASELINE?
As identified in the NSA's Slicksheet_SecureHostBaseline_Web "A Secure Host Baseline (SHB) is a pre-configured and security-hardened machine-ready image that contains an organization’s common Operating Systems (OS) and application software. SHB images are developed with the latest relevant standards and policies which include a layered security architecture enabling the implementation of best practice mitigation strategies to counter cyber threats... An SHB image can be generated for any OS and common application software used by an organization. The image can be deployed across an office’s host systems to include desktops, laptops, servers, tablets, and mobile devices. This provides administrators with a common core operating picture that makes it easier to identify and isolate anomalies. An SHB simplifies the implementation of robust security practices and technologies such as Application Whitelisting, Host Intrusion Prevention Systems (HIPS), Enhanced Experience Mitigation Toolkit (EMET), and other anti-exploitation capabilities. It also ensures that the security features of each host residing on a network are consistent with the organization’s security policies and directives."
Organizations needing to maintain secure host baselines (SHB) face a considerable challenge. Unless they have an automated compliance platform, they must be prepared to provide continual updates for all hardware and software OS and applications. Without a platform to perform these operations, even a successful SHB deployment leaves IT with the daunting task of maintaining business IT alignment to update all secure host images with every notification for baseline improvement. Longer term, organizations must manage lifecycle and end-of-life timelines for OS and applications to ensure that the security features remain current.
LEVERAGING IS0 27002 CLIENTS TO:
- Identify information assets and their associated security requirements
- Assess information security and treat risks according to their relative tolerance
- Select and implement relevant controls to manage or mitigate threats
- Monitor, maintain and improve the effectiveness of controls associated with the organization’s information assets

THE SOLUTION
EnterpriseGRC Solutions recommends using products that connect SCAP and OVAL/JOVAL protocols to the following conditions of security.
- Settings that indicate missing patches for operating systems and applications.
- Monitoring and detecting sensitive data loss (data exfiltration)
- Locating policies that enable weak passwords.
- Lack of logs and audit trails necessary to conduct forensics
- Security validation for new systems
- Missing or outdated anti-malware technology
- Settings that enable encryption of sensitive information in transit
- The information necessary to remediate deficiencies that would otherwise be impossible to manage due to the lack of trained staff maintaining security controls.
COMPLIANCE IN ANY ENVIRONMENT
- Cloud Native platform supporting 12-factor patterns (things like port binding, logs, concurrency…)
- A “hyperplane” of integrated “risk assessment” amongst segmented vulnerability domains
- Works with Private, Hybrid, and Public Clouds
- Support AWS, Azure, GCP (Google Cloud Platform)
- Manages thousands of out-of-box policies, well-curated and certified (SCAP, XCCDF, OVAL)
- Supports current compliance authority (PCI DSS, HIPAA, NIST, SOC2, FedRamp, CIS Benchmark, DISA, CIS CSC, CSF)
- Is CIS Certified security content (Multiple OS, Docker, AWS Cloud)
- Complies with DISA standards in all aspects of delivery and reported results


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics