System Hardening aims to perform the updates, adjustments, and changes in the system that are necessary to achieve a high level of security against external and internal attacks. This process should be mandatory for any server that offers services over the Internet, given its predisposition to suffer attacks.
In a hardening process it is necessary to go beyond the essential patching or updating of the machine. It is necessary to know in detail the options offered by Operating Systems and Server applications (options that most of the time remain hidden) in order to make use of them to improve system security.
This process, known as Hardening, consists of the shielding of a server, in which, starting from a machine installed with default options, the result is a maximum security server using the Operating System’s own resources.
The process followed is as follows:
Throughout the entire Hardening process different reports are produced, including:
- Detailed audit of the current state of the machine.
- Details of all recommended actions and changes in the System and Services.
- List of actions performed.
- List of affected parameters and options.
- Enumeration of incidents, causes, and solutions.
- Classification of security issues according to their risk level. This will allow the company to design an efficient action plan to resolve these security issues.
Meeting aimed at explaining the results obtained in the audit and providing advice on the possible solutions available for the security issues identified.