Correct Answer: B
The first step in ensuring secure configuration of new IT assets is to establish the baseline configuration requirements those assets must meet. ISACA guidance supports the use of documented security configuration standards, secure baselines, and hardening requirements before deployment. Without predefined hardening standards, vulnerability scanning or remediation lacks a clear benchmark for what "secure" should look like.
Option B is correct because defining and implementing hardening standards establishes the secure baseline for systems, operating systems, applications, and devices. ISACA material notes that resources should adhere to a minimum-security baseline composed of standard security configurations, and secure configurations should be documented and maintained. This makes hardening standards the logical and control-oriented first step.
Option A is not first. Identifying and remediating vulnerabilities is important, but this activity should follow the establishment of hardening standards. Otherwise, there is no approved baseline against which to assess and remediate deviations. In CISA logic, standards come before testing against standards.
Option C is also not first for the same reason. Vulnerability scanning is an assessment technique, but organizations must first define the secure configuration baseline or hardening standard to know what they expect from the asset. Scanning should validate configuration and identify weaknesses after standards have been established.
Option D is clearly incorrect because purchasing tools is not the starting point of good control design. Tools may support implementation and verification, but governance requires that standards be defined first. In ISACA terms, sound control begins with policy, standards, and procedures, not with tool acquisition.
Therefore, the best answer is B because secure configuration starts with defining and applying hardening standards, which then enable scanning, validation, and remediation activities.
References (Official ISACA):
* ISACA-linked guidance, A Look at CIS Controls Version 7.1 - "Establish Secure Configurations" and maintain documented security configuration standards.
* ISACA, Best Practices for Auditable Security Controls - all resources should adhere to a minimum- security baseline of standard security configurations.
* ISACA, Can Hardening Reduce Cyberrisk? - highlights hardening systems and infrastructure to reduce risk.
* ISACA, Digital Businesses Need Tailored Security Solutions and Services - refers to minimum baseline hardening standards and guidelines.