Secure Configuration
Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.
Term
description · examples · notesSecure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.
Description
The process includes defining configuration baselines for each system type, automated enforcement, and regular compliance checking. Deviations from the standard are logged and remediated.
Secure configuration is a preventive measure that reduces the number of possible attack vectors, but it requires continuous maintenance as new vulnerabilities and recommendations necessitate updating the standards.
What people often say
- Once configured, systems require no further review.
- The default operating system configuration is secure enough.
Covers / does not cover
Covers
- Elimination of default passwords and unnecessary services
- Applying the principle of least privilege at the system level
- Hardening systems against known security baselines
- Regular configuration compliance checking
Does not cover
- Vulnerabilities in application code (that requires software patching)
- Threats from social engineering and phishing
- Real-time attack detection
Mentioned in the news
- 28. JUL 2026. Microsoftov AI sam testira mrežu i krpi propuste →
- 19. JUL 2026. Naučnik iz Vranja pravi ono u šta Cisco ulaže milione →
- 13. JUL 2026. Trojanac u Visual Studio projektima ostavlja zamke za razvojne inženjere →
- 12. JUL 2026. Apple tuži OpenAI za krađu poslovnih tajni — firmu koju je prethodno pustio u svoje uređaje →
- 11. JUL 2026. Poruka sa WhatsApp-a može da navede OpenClaw da pokrene programski kod na računaru korisnika →
- 11. JUL 2026. AI pregledači odali kredencijale korisnika jer im je rečeno da je to deo igre →
- 11. JUL 2026. Metin novi AI alat koristi sadržaj javnih Instagram naloga za generisanje slika — bez pitanja korisnika →
- 11. JUL 2026. Firewall se ne bira po brendu, nego po ljudima koji će ga održavati →
- 11. JUL 2026. Uloga VPN aplikacije je da štiti privatnost korisnika, ali veliki broj njih to ne radi u potpunosti →
Threats
reduces 38Threats it reduces. Select one to open its page.
- Supply Chain Attack→
- Backdoor→
- Remote Code Execution→
- Accidental Data Leak→
- Privilege Escalation→
- Cloud IAM misconfiguration→
- Shadow IT→
- Authentication Bypass→
- Fileless malware→
- Rootkit→
- SQL Injection→
- Token Theft→
- Brute-force attack→
- Cryptominer→
- IoT Device Compromise→
- Session Hijacking→
- API Abuse→
- Password spraying→
- Cloud storage exposure→
- SSRF→
- Shared Account Abuse→
- Cross-Site Scripting→
- Insecure Deserialization→
- Model theft / extraction→
- Prompt injection→
- DNS Amplification→
- Denial of Service / DoS→
- Service Abuse→
- Resource Exhaustion→
- SCADA/OT Attack→
- Kerberoasting→
- Physical Access Attack→
- BGP Hijacking→
- Cross-Site Request Forgery→
- DNS Poisoning→
- Dependency Confusion→
- Path Traversal→
- USB Drop Attack→
Techniques
neutralizes 22Techniques it neutralizes. Select one to open its page.
- Exploitation→
- Malware Delivery→
- Configuration Abuse→
- Privilege Escalation→
- Persistence→
- Automation & Scripting→
- Resource Exhaustion→
- Brute Force→
- Container Escape→
- Living off the Land→
- OSINT→
- Service Abuse→
- Website Defacement→
- In-Memory Execution→
- DLL Sideloading→
- Supply Chain Compromise→
- Domain Account Discovery→
- Log Tampering→
- Physical Access→
- Forge Kerberos Tickets→
- Access Token Manipulation→
- Rootkit Installation→