Baseline (USGCB) and Baseline Security System ISKE

F0000

2 slides · 1 min read · Domain 2

Slide 1

Example: United States Government Configuration Baseline (USGCB)

One such example of this approach can be found by examining the United States Government Configuration Baseline (USGCB). The purpose of the USGCB initiative is to create security configuration baselines for IT products widely deployed across the federal agencies. The USGCB baseline evolved from the Federal Desktop Core Configuration mandate. The USGCB is a federal government-wide initiative that provides guidance to agencies on what should be done to improve and maintain an effective configuration setting focusing primarily on security.

Example: Estonian Information System's Authority IT Baseline Security System Iske

Another example can be found in the Estonian Information System's Authority IT baseline security system ISKE. ISKE is an information security standard developed for the Estonian public sector, which is mandatory for state and local government organizations that handle databases. ISKE is based on a German information security standard - IT Baseline Protection Manual (IT-Grundschutz in German) - that has been adapted to suit the Estonian situation.

ISKE is implemented as a three- level baseline system, meaning that three different sets of security measures for three different security requirements have been developed and are available for implementation based on the needs of the entity managing the databases in question and the type(s) of data that the database contains.etting focusing primarily on security.

Test this domain