© The Author(s) 2020
D. BlumRational Cybersecurity for Businesshttps://doi.org/10.1007/978-1-4842-5952-8_6

6. Establish a Control Baseline

Dan Blum1 
(1)
Silver Spring, MD, USA
 

All security programs depend on having some basic controls, called a control baseline, in place. After all, one would not deem a house or an office “secure” without locks on the doors to control entry.

There are many technical and nontechnical controls that a business could implement, but few businesses have the time, money, or inclination to implement them all. Some guidance is needed to determine which controls are most needed, and to that end the industry provides various standard control frameworks.

Some control frameworks – such as the International Organization for Standardization ...

Get Rational Cybersecurity for Business: The Security Leaders' Guide to Business Alignment now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.