166 terms · 75/46/45
Defense № 026 · class: resilience

Secure Configuration

Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.

Term

description · examples · notes

Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the attack surface by eliminating unnecessary functions, default passwords, and insecure settings.

Description

The process includes defining configuration baselines for each system type, automated enforcement, and regular compliance checking. Deviations from the standard are logged and remediated.

Secure configuration is a preventive measure that reduces the number of possible attack vectors, but it requires continuous maintenance as new vulnerabilities and recommendations necessitate updating the standards.

What people often say

  • Once configured, systems require no further review.
  • The default operating system configuration is secure enough.

Covers / does not cover

Covers

  • Elimination of default passwords and unnecessary services
  • Applying the principle of least privilege at the system level
  • Hardening systems against known security baselines
  • Regular configuration compliance checking

Does not cover

  • Vulnerabilities in application code (that requires software patching)
  • Threats from social engineering and phishing
  • Real-time attack detection

Mentioned in the news

Composite

Threats

reduces 38

Techniques

neutralizes 22