GlossaryAttack surface and pentesting

Hardening

Short answer

Hardening is the process of reducing the attack surface of a system by changing its default configuration: removing unnecessary software and services, closing unused ports, disabling insecure settings, changing default passwords and applying security baselines.

Why default settings are not enough

Operating systems, servers, network devices and cloud services ship configured for ease of use, not security. Default passwords, open administration interfaces, legacy protocols, enabled macros and unnecessary services are among the most exploited weaknesses, and they stay in place until someone changes them.

What hardening involves

Typical measures include removing or disabling software and services that are not needed, changing default credentials, disabling legacy protocols such as SMBv1, enforcing disk encryption and screen lock, blocking Office macros from the internet, restricting administrator rights, enabling host firewalls and configuring logging. On laptops and phones, these settings are usually enforced through MDM.

Using baselines

Rather than inventing settings, companies use published baselines: the CIS Benchmarks, security baselines from Microsoft, Apple and the cloud providers, and in Spain the CCN-STIC guides, which are the reference for the ENS. Configurations should then be checked regularly, since they drift over time; in the cloud, this is the role of CSPM.

Where it shows up in compliance

ISO 27001 requires configurations, including security configurations, to be established, documented and monitored (Annex A 8.9). The ENS includes a specific security configuration measure, and the CIS Controls dedicate a control to the secure configuration of assets and software.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub