The secure baseline
An optional infrastructure baseline you deploy into your own accounts: Config recording, Security Hub, GuardDuty, Access Analyzer, CloudTrail, and in an organisation the preventive layer of SCPs, RCPs and declarative policies.
Most accounts have no AWS Config recorder, and the failure is silent: nearly every Security Hub control is evaluated by a Config rule, and with no recorder those controls emit nothing rather than failing — so they never reach the denominator. Roughly 211 of the 638 checks survive that. StationChief refuses to publish a score from an account whose recorder cannot support one, and names the resource types it is missing instead of reporting a precise number over an unstated subset.
AWS Foundational Security Best Practices is the floor and is never replaced, only layered on. CIS, NIST 800-53 r5, FedRAMP Moderate, FedRAMP High, CMMC L2 and PCI DSS 4 layer on top of it. A framework gets a CSPM standard or a Config conformance pack, never both — because both bill separately for the same evaluations.
It is not a landing zone and does not try to be. It is the security baseline, applied to accounts you already have.