Why: The practice's documented, portable baselines — written per core system and inherited by new tools through a secure-configuration checklist — are the establish-and-document half of this requirement, and its drift detection is the signal that deployed settings still match documented ones.
What this does not claim: May partially address the requirement: the practice does not itself select organization-defined settings against a most-restrictive-mode test, and its portability emphasis is not this requirement's concern. Fleet-wide enforcement and a maintained deviation register are separate work that the baseline documents enable but do not perform.
- Document baseline settings per core system with a named owner
- Run new tools through the secure-configuration checklist before adoption
- Detect and investigate drift between documented and deployed configuration
- Baseline documents with their benchmark sources
- Secure-configuration checklist records for adopted tools
- Drift reports with dispositions
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06