Secure by default

Configuration baselines

Define a baseline per asset class (Linux server, Windows server, container, network device). Track

drift against the baseline and remediate or formally accept.

AreaBaseline expectation
SSHKey-only, no root login, MFA for privileged
EndpointEDR active, disk encryption, screen lock
CloudNo public buckets, least-privilege IAM, logging on
ContainersNon-root, read-only FS, no privileged

Secrets management

Drift & integrity

Assume breach: if a control fails silently, defence-in-depth should still catch it. Test that assumption.
← Administrator Guide  ·  All guidelines