Keeping your server hardened after the audit
Once you have acted on your reports, the goal is to stay in the secure state the audit helped you reach. Good ongoing practices include:
- Patch promptly. Outdated software is the most common way servers are compromised, so keep the OS and every service updated.
- Only expose what you must. Turn off services you don't use and firewall off anything that doesn't need to face the internet — admin panels and databases especially.
- Enforce encryption on mail, file transfer and web services so credentials never travel in the clear.
- Review permissions and accounts regularly and remove privileges that are broader than needed.
- Watch for the unexpected — the earlier you spot signs of intrusion, the smaller the damage.
These are the same fundamentals the audit assesses. Maintaining them between audits is what keeps a hardened server hardened.

0 comments
Sign in with your TDesk account to comment.