AI DEFENCEBY ALTARI SYSTEMS
Menu

Security answers / Continuous protection

What is a security baseline?

A security baseline is an explicit record of the expected, accepted state of an environment. It can include known assets, services, ports, users, packages, network paths, workloads and configuration, together with approved exceptions. Comparing new evidence with that record helps identify unexpected changes, but a baseline needs review and cannot prove that every accepted setting is safe.

Published by Altari Systems · 7 September 2026

Observed state and approved state are different

An inventory records what a collector observed. A baseline adds a decision about what should be expected. Automatically accepting every observed service would turn a suspicious new port into the new normal, undermining drift detection.

A useful baseline is therefore established after findings and authorised changes have been reviewed. Where a risk is accepted, the exception should explain the context. Missing evidence should remain a gap, not be converted into an implicit approval.

Which changes deserve attention?

A new privileged user, an unfamiliar SSH key or a newly exposed database port can be meaningful deviations. A planned release may also change dependencies, processes and network connections. The monitoring process needs enough operational context to distinguish authorised work from unexplained drift.

A change is a signal to assess, not automatic proof of compromise. Its importance depends on the affected system, the authority introduced, exposure and available supporting evidence. Similarly, no detected change does not mean no risk when telemetry is missing or stale.

Keep the baseline connected to verification

After an approved hardening operation, verify the intended security change and the required application behaviour before updating the accepted state. A permissions change that breaks a service should not become an unquestioned baseline merely because the command completed.

AI Defence’s specification records hosts, services, ports, users, packages, network paths, workloads, configuration and approved exceptions. The intended monitoring scope uses that baseline to detect drift and emerging vulnerabilities while preserving the authorisation boundary for responses.

Start with understanding

What does your environment need to defend?

Discuss the assessment scope, current capabilities and the control you need with Altari Systems.

Talk to Altari