Choose a baseline that fits
Record the platform, version, deployment model and business purpose. A hardening recommendation may not apply to every system. Use a relevant baseline, evaluate its assumptions and document exceptions with an owner and rationale.
Identity and administrative access
- Identify privileged users, service identities and inherited permissions.
- Review multi-factor controls and account recovery for sensitive access.
- Confirm that management interfaces are restricted to their intended audience.
- Check whether unused accounts and unnecessary permissions can be removed.
Exposure, defaults and data
- Compare effective network rules with the intended access model.
- Review public storage, debug features and unnecessary services.
- Check secret distribution and avoid including secret values in reports.
- Review transport settings without disabling certificate verification.
Logging and evidence
Identify the events needed to investigate privileged actions and sensitive data access. Check whether the relevant configuration enables those events and where records are retained. A logging setting is not proof that detection or incident response is effective; those are separate questions.
Validate context before assigning risk
For each deviation, capture the affected setting, intended control and practical consequence. Distinguish a confirmed exposure from a recommendation whose impact remains unverified. Record accepted exceptions separately so they are not silently lost in a pass/fail checklist.
Plan the change and verify it
Hardening can affect compatibility. Assign an owner, test the proposed change and define rollback criteria before production rollout. Retesting should confirm both the security expectation and the required business behavior, within the agreed scope.
Preparing for an assessment
Identify the systems, versions, baseline and review objective. Share sanitized configuration exports or arrange least-privilege access securely. Agree how business-required exceptions should be evaluated.
Keep scope, access assumptions and exclusions explicit. Use redacted evidence and representative test data. Report what was verified, what remains uncertain and which checks could not be completed.
Where identity, hosts and networks interact, consider an infrastructure security assessment.
Related resources
Guides
Cloud Security Fundamentals
Review identity, exposure and configuration within your cloud responsibilities.
Read articleGuides
Vulnerability Management Basics
Prioritize remediation using exposure, validation and business context.
Read article