control baseline
Term · Cybersecurity · MLC-T-CYB-000930
1. Hardware, software, databases, and relevant documentation for an information system at a given point in time.
2. Formally approved version of a configuration item, regardless of media, formally designated and fixed at a specific time during the configuration item’s life cycle.
3. Hardware, software, and relevant documentation for an information system at a given point in time.
4. See control baseline.
5. The set of controls that are applicable to information or an information system to meet legal, regulatory, or policy requirements, as well as address protection needs for the purpose of managing risk.
6. Predefined sets of controls specifically assembled to address the protection needs of groups, organizations, or communities of interest. See privacy control baseline or security control baseline.
7. The set of security and privacy controls defined for a low-impact, moderate-impact, or high-impact system or selected based on the privacy selection criteria that provide a starting point for the tailoring process.
8. Formally approved version of a configuration item, regardless of media, formally designated and fixed at a specific time during the configuration item's life cycle.
Note: The engineering process generates many artifacts that are maintained as a baseline over the course of the engineering effort and after its completion. The configuration control processes of the engineering effort manage baselined artifacts. Examples include stakeholder requirements baseline, system requirements baseline, architecture/design baseline, and configuration baseline.
| Identifier | MLC-T-CYB-000930 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | baseline |
| References | NIST SP 800-161r1-upd1 [11/1/2024 errata update] from CNSSI 4009-2015, CNSSI 4009-2022; NIST SP 800-160v1r1 from IEEE Std. 828-2012; CNSSI 4009-2015; NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5; NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5 from NIST SP 800-53B; NIST SP 800-53A Rev. 5 from NIST SP 800-53B; NIST SP 800-53B from FIPS 200 (Adapted); NIST SP 800-160 Vol. 1 from IEEE 828; NIST CSRC Glossary |
| See also | security control baseline |
Record as JSON
{
"id": "MLC-T-CYB-000930",
"term": "control baseline",
"field": "Cybersecurity",
"definition": "1. Hardware, software, databases, and relevant documentation for an information system at a given point in time.\n\n2. Formally approved version of a configuration item, regardless of media, formally designated and fixed at a specific time during the configuration item’s life cycle.\n\n3. Hardware, software, and relevant documentation for an information system at a given point in time.\n\n4. See control baseline.\n\n5. The set of controls that are applicable to information or an information system to meet legal, regulatory, or policy requirements, as well as address protection needs for the purpose of managing risk.\n\n6. Predefined sets of controls specifically assembled to address the protection needs of groups, organizations, or communities of interest. See privacy control baseline or security control baseline.\n\n7. The set of security and privacy controls defined for a low-impact, moderate-impact, or high-impact system or selected based on the privacy selection criteria that provide a starting point for the tailoring process.\n\n8. Formally approved version of a configuration item, regardless of media, formally designated and fixed at a specific time during the configuration item's life cycle.\nNote: The engineering process generates many artifacts that are maintained as a baseline over the course of the engineering effort and after its completion. The configuration control processes of the engineering effort manage baselined artifacts. Examples include stakeholder requirements baseline, system requirements baseline, architecture/design baseline, and configuration baseline.",
"abbreviation": "baseline",
"see_also": [
"security control baseline"
],
"references": [
"NIST SP 800-161r1-upd1 [11/1/2024 errata update] from CNSSI 4009-2015, CNSSI 4009-2022",
"NIST SP 800-160v1r1 from IEEE Std. 828-2012",
"CNSSI 4009-2015",
"NIST SP 800-37 Rev. 2; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5",
"NIST SP 800-37 Rev. 2",
"NIST SP 800-53 Rev. 5 from NIST SP 800-53B; NIST SP 800-53A Rev. 5 from NIST SP 800-53B",
"NIST SP 800-53B from FIPS 200 (Adapted)",
"NIST SP 800-160 Vol. 1 from IEEE 828",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/control-baseline/"
}
Record 930 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.