Use the platform’s native policy and configuration tooling where practical: device-management policy, configuration-management systems, infrastructure as code, image pipelines, cloud policy, container admission controls, network configuration templates, or vendor management APIs. Manual hardening should be the exception because it is difficult to prove, repeat, and maintain.
Test baseline changes in representative environments before broad deployment. Security changes can affect authentication, management connectivity, application dependencies, monitoring agents, backup software, legacy protocols, and support tooling. Define rollback conditions and validate that emergency access remains available.
Version baselines like code. A change should have an identifier, rationale, approver, effective date, affected population, test result, deployment status, and rollback information. This allows incident responders and auditors to determine what configuration was intended at a particular point in time.