Your systems are hardened to a defined secure baseline — and it's enforced.
What it actually means
Having a baseline (3.4.1) isn't enough — you have to enforce hardened security settings on the products you use. In practice that's applying a recognized hardening standard (CIS Benchmarks / DISA STIGs) through group policy, Intune, or your config-management tooling, and keeping machines in that state.
Pass or fail — an assessor needs a "yes" to each
- Security configuration settings are defined (e.g., CIS/STIG-based).
- They're enforced via GPO/Intune/config management, not set by hand.
- Drift from the hardened state is detected/corrected.
What to have ready
- Hardening standard + the enforced policy (GPO/Intune profiles)
- Compliance/drift reports
- Mapping to CIS or STIG where used
Where teams trip up
- Default, out-of-the-box configurations
- A baseline document that isn't actually enforced
- Settings applied once, then drift over time
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Configuration Management (3.4)
3.4.1 — Inventory and baseline your systems3.4.3 — Control and log changes3.4.4 — Check changes before you make them3.4.5 — Restrict who can make changes3.4.6 — Least functionality3.4.7 — Block nonessential ports and services3.4.8 — Control which software can run3.4.9 — Control user-installed software