System Hardening
Hardening the underlying server operating system is an important fundamental task to help protect your web applications.
For example, the Payment Card Industry Data Security Standard (PCIDSS) requirement 2.2 states:
Develop configuration standards for all system components. Assure that these standards address all known security vulnerabilities and are consistent with industry-accepted system hardening standards.
Two United States organisations producing guidance in this field are:
- Security Configuration Benchmarks from the Center for Internet Security (CIS)
- Security Content Automation Protocol (SCAP) Checklists from the National Institute of Standards and Technology (NIST) Computer Security Division (CSD)
These are detailed documents and all the recommendations may not be appropriate for your own situation.
Posted on: 26 May 2009 at 10:56 hrs

Comments are filtered automatically and should appear shortly after they been checked.