CISM · Question #513
Which of the following is the FIRST step when creating security baselines?
The correct answer is D. Establish consistent organization-wide controls. Establishing consistent organization-wide controls (D) is the first step because a security baseline is, by definition, a uniform minimum standard applied across the entire organization - you must define that common foundation before you can do anything else meaningful. Why the…
Question
Which of the following is the FIRST step when creating security baselines?
Options
- AIdentify critical systems storing sensitive data.
- BDetermine needed compliance criteria.
- CEstablish maximum security requirements.
- DEstablish consistent organization-wide controls.
How the community answered
(57 responses)- A5% (3)
- B2% (1)
- C2% (1)
- D91% (52)
Explanation
Establishing consistent organization-wide controls (D) is the first step because a security baseline is, by definition, a uniform minimum standard applied across the entire organization - you must define that common foundation before you can do anything else meaningful.
Why the distractors are wrong:
- A (Identify critical systems) - Asset identification happens after you know what baseline you're building toward; you can't prioritize systems without a baseline framework in place.
- B (Determine compliance criteria) - Compliance mapping refines and validates your baseline but doesn't precede establishing it; some baselines exist independent of regulatory requirements.
- C (Establish maximum security requirements) - Baselines are minimum standards, not maximums. Maximum requirements describe hardening targets that come later, not the baseline itself.
Memory tip: Think of a baseline like a building's foundation - you pour the slab (organization-wide controls) uniformly first, then decide which rooms need reinforced walls (critical systems, compliance overlays). The word baseline = base = foundation = first.
Topics
Community Discussion
No community discussion yet for this question.