Why: Documented, portable configuration baselines — the practice's mechanism for swapping products without security regressions — are what keep established security settings maintainable when the stack changes underneath them.
What this does not claim: The requirement is to establish and enforce the settings, and the practice does neither: it makes an existing configuration standard survivable through product change. Contributes to the requirement's durability rather than its substance, and the enforcement tooling and drift measurement remain separate work.
- Express security configuration standards in portable, vendor-neutral terms
- Re-verify settings against the standard whenever a product is adopted or swapped
- Portable baseline documentation reused across a product change
- Post-migration verification showing settings carried over
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06