Baseline Documentation by Asset Category
Baselines are created per asset category (Windows workstations, Windows servers, network switches, Linux servers, firewalls, and so on). Each baseline captures the security settings required for that category: password policy parameters, screen lock timeout, audit logging configuration, enabled or disabled services, firewall rules, and encryption settings. The applicable reference standard (CIS Benchmark, STIG, or organizational policy) is cited for each setting.
Each baseline is version-controlled. When the approved settings change (a new password policy is adopted, a service is added or removed), the baseline is updated with a new version, the change is documented, and the prior version is preserved. That version history demonstrates baselines are actively maintained rather than set once and forgotten.