Hardening
What is Hardening?
The process of securing a system by reducing its attack surface through removing unnecessary software, disabling unused services, applying patches, and configuring security settings according to established baselines such as CIS Benchmarks.
Terms that appear alongside hardening
Each of these is named in at least one of the same controls as hardening. The number is how many controls name both.
- system hardening 15 shared controls
- baseline 14 shared controls
- secure configuration 13 shared controls
- vulnerability 12 shared controls
- integrity 12 shared controls
- nist 11 shared controls
- patch management 10 shared controls
- authentication 9 shared controls
Frameworks that govern hardening
What the standards actually require on hardening
Requirements naming hardening across 6 standards, quoted from the control text.
IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-1858 · IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictiv →Harden container images: minimal base images, removal of unnecessary packages, non-root users and reduced attack surface.
CNCF-DIST-IMGHARDEN · Image Hardening →Browsers, Office, PDF readers hardened per ASD guides; logged; users cannot disable.
E8-UAH-ML2 · User Application Hardening - Maturity Level 2 →Harden operating systems based on vendor guidance and ASD guidance. Remove unneeded software, services and ports.
ASD37-11 · Operating system hardening (Very Good) →Harden network devices (routers, switches, firewalls, VPN concentrators, wireless) in accordance with the applicable network STIGs, covering device management, routing-protocol security, boundary protection and remote access.
STIG-SRG-NET · Network device STIG hardening →UR E27 requires equipment manufacturers to deliver hardened CBS with secure default configuration + secure communications. Hardening: minimum services + disabled debug + locked BIOS + secure boot + Trusted Platform Module (TPM) or equivalent root of trust + si...
IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications · IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography →Questions people ask about hardening
What is Hardening?
Why is Hardening important for compliance?
Which compliance frameworks address Hardening?
Where can I learn more about Hardening?
See how Hardening applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.