相关文章推荐
  • Business continuity management (BCM) and ISO 22301
  • Certified ethical hacker (CEH)
  • Cloud security
  • Cyber Essentials
  • Cyber incident response
  • Cyber resilience
  • Cyber security
  • Information security
  • ISO 27001
  • IT governance
  • NIS Directive and NIS Regulations
  • PCI DSS
  • Penetration testing
  • Risk management
  • Cyber security information pages
  • Business continuity (BCM) and ISO 22301
  • Cyber Defence in Depth
  • Cyber Essentials
  • Cyber incident response
  • Cyber resilience
  • Cyber security
  • Information security
  • ISO 27001
  • IT governance
  • ITIL®
  • Management system standards
  • NIS Directive and NIS Regulations
  • Official Crown Commercial Service Provider
  • PCI DSS
  • Penetration testing & ethical hacking
  • Risk management
  • SOC 2
  • Social engineering attacks
  • SWIFT CSCF
  • Useful Links
  • Cyber Defence in Depth
  • 20 years of IT Governance
  • In-house training options
  • £10 for your feedback
  • Become an IT Governance partner
  • Cyber security free resources
  • Speak to a cyber security expert
  • Staff awareness e-learning courses
  • Staff awareness training
  • Customised staff awareness courses
  • In-house training courses
  • Official Crown Commercial Service Provider
  • Security awareness programme
  • Branded publishing services
  • Useful links
  • GRC eLearning platform
  • Information security for hybrid working
  • Staff awareness free resources
  • E-learning FAQs
  • £10 for your feedback
  • Apply for a corporate account
  • Become an IT Governance partner
  • Request a tailored e-learning quote
  • Speak to an e-learning expert
  • Data security and protection (DSP) toolkit
  • DPO as a service (DPOaaS)
  • Gambling Commision compliance
  • GDPR and data protection
  • ISAE 3402, SSAE 16, SOC 2 and 3
  • ISO 27001
  • IT governance, ISO 38500 and COBIT ®
  • NIS Directive and NIS Regulations
  • Official Crown Commercial Service Provider
  • PCI DSS
  • SWIFT CSCF
  • Useful links
  • Cyber Defence in Depth
  • Consultancy services overview
  • Corporate and enterprise consultancy
  • Consultancy case studies
  • £10 for your feedback
  • Apply for a corporate account
  • Become an IT Governance partner
  • Speak to a consultancy expert
  • Information security for hybrid working
  • £10 for your feedback
  • Security testing free resources
  • Apply for a corporate account
  • Become an IT Governance partner
  • Speak to a security testing expert
  • Secure configuration

    Secure configuration refers to security measures that are implemented when building and installing computers and network devices to reduce unnecessary cyber vulnerabilities.

    Security misconfigurations are one of the most common gaps that criminal hackers look to exploit. According to a recent report by Rapid7, internal penetration tests encounter a network or service misconfiguration 96% of the time.

    Both the SANS Institute and the Council on CyberSecurity recommend that, following an inventory of your hardware and software, the most important security control is to implement secure configuration.

    Why is secure configuration important?

    Manufacturers often set the default configurations of new software and devices to be as open and multifunctional as possible. In the case of a router, for example, this could be a predefined password, or in the case of an operating system, it could be the applications that come installed.

    It’s easier and more convenient to use new devices or software with their default settings, but it’s not the most secure. Accepting the default settings without reviewing them can create serious security issues, and can allow cyber attackers to gain easyaccess to your data.

    Web server and application server configurations play a crucial role in cyber security. Failure to properly configure your servers can lead to significant security problems.

    Computers and network devices should also be configured to minimise the number of inherent vulnerabilities and provide only the services required to fulfil their intended function.

    How to protect yourself

    The UK government’s Cyber Essentials scheme sets out five controls that organisations can implement to achieve a baseline of cyber security, against which they can achieve certification to prove their compliance.

    One of the scheme’s controls is secure configuration.

    Certification to the scheme provides numerous benefits, including reduced insurance premiums, improved investor and customer confidence, and the ability to tender for business where certification to Cyber Essentials is a prerequisite.

    New to the Cyber Essentials scheme? Find out more

    For computers and network devices, your organisation should routinely:

  • Remove and disable unnecessary user accounts;
  • Change default or guessable account passwords to something non-obvious;
  • Remove or disable unnecessary software;
  • Disable any auto-run feature that allows file execution without user authorisation; and
  • Authenticate users before enabling Internet-based access to commercially or personally sensitive data, or data critical to running the organisation.
  • For password-based authentication, your organisation should:

  • Protect against brute-force password guessing by limiting attempts and/or the number of guesses allowed in a certain period;
  • Set a minimum password length of at least eight characters (if supported by MFA or a deny list) or 12 characters , without any maximum password length;
  • Change passwords promptly when the user knows or suspects they have been compromised; and
  • Have a password policy that informs users of best practices.
  • Firewalls

    Firewalls control the incoming and outgoing network traffic based on predetermined security rules. A firewall typically establishes a barrier between a trusted internal network and untrusted external network, such as the Internet.

    Learn more about firewalls

    Patch management

    Patch management is the process of identifying, acquiring, installing and verifying patches for software and hardware components.

     
    推荐文章