Standards are detailed statements of the minimum requirements for hardware, software, or security configurations. They are used to define the minimum security controls required for user workstations. Reference = CISM Review Manual, 16th Edition, page 69.