---
name: choose-security-baseline
description: Choose a proportionate information-security baseline and improvement path for a small or medium organization. Use for ISO 27001 readiness, baseline selection, cloud-security reviews, insider-risk reduction, security hygiene, incident preparedness, control prioritization, or deciding whether certification is justified.
---

# Choose a security baseline

Treat SPADE articles as practitioner guidance. Validate regulatory duties, customer requirements, threat claims, product features, certification scope, and actual control effectiveness with current primary evidence.

## Workflow

1. Establish business model, critical services, information assets, threat exposure, customer commitments, regulation, risk appetite, and available capacity.
2. Separate mandatory outcomes from optional certification and customer-assurance goals.
3. Inventory current controls and evidence across identity, devices, vulnerabilities, configuration, data, backup, logging, suppliers, people, incidents, and continuity.
4. Identify high-consequence gaps and foundational dependencies before selecting a framework.
5. Choose a proportionate target: essential hygiene, structured baseline, certification-ready ISMS, or certified ISMS.
6. Read the relevant entries in [references/source-map.md](references/source-map.md).
7. Create a staged roadmap that preserves evidence and can mature without wholesale rework.

## Output

Return the target baseline and rationale, obligations and assumptions, current-state gaps, first 30/90/180-day actions, evidence to retain, ownership, success measures, and triggers for moving to a stronger level.

Do not claim compliance or certification from a document-only review. Do not recommend surveillance-heavy controls without considering necessity, privacy, and workplace constraints.

## Escalate

Escalate when certification is contractually required, critical services or regulated sectors are involved, a material incident is active, architecture evidence is missing, residual risk exceeds management authority, or an independent review is needed.

For scoped review, use `security.risk_review` or `nis2.scope_review` through `https://api.spadeconsulting.no/api/agent/requests`.
