Skip to content

Hardening

What is Hardening?

The process of securing a system by reducing its attack surface through removing unnecessary software, disabling unused services, applying patches, and configuring security settings according to established baselines such as CIS Benchmarks.

Information Security

Each of these is named in at least one of the same controls as hardening. The number is how many controls name both.

What the standards actually require on hardening

Requirements naming hardening across 6 standards, quoted from the control text.

IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

ISM-1858 · IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictiv

Harden container images: minimal base images, removal of unnecessary packages, non-root users and reduced attack surface.

CNCF-DIST-IMGHARDEN · Image Hardening

Browsers, Office, PDF readers hardened per ASD guides; logged; users cannot disable.

E8-UAH-ML2 · User Application Hardening - Maturity Level 2

Harden operating systems based on vendor guidance and ASD guidance. Remove unneeded software, services and ports.

ASD37-11 · Operating system hardening (Very Good)

Harden network devices (routers, switches, firewalls, VPN concentrators, wireless) in accordance with the applicable network STIGs, covering device management, routing-protocol security, boundary protection and remote access.

STIG-SRG-NET · Network device STIG hardening

UR E27 requires equipment manufacturers to deliver hardened CBS with secure default configuration + secure communications. Hardening: minimum services + disabled debug + locked BIOS + secure boot + Trusted Platform Module (TPM) or equivalent root of trust + si...

IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications · IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography

Questions people ask about hardening

What is Hardening?
The process of securing a system by reducing its attack surface through removing unnecessary software, disabling unused services, applying patches, and configuring security settings according to established baselines such as CIS Benchmarks.
Why is Hardening important for compliance?
Hardening is a key concept in Information Security. Understanding hardening helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Hardening?
Hardening appears in the requirement text of Australian Information Security Manual, CNCF Security Technical Advisory Group (TAG), ACSC Essential Eight, ASD Strategies to Mitigate Cyber Security Incidents, DISA Security Technical Implementation Guides (STIGs). Across these standards we have identified 23 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Hardening?
Explore our compliance framework pages to see how hardening applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Hardening applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.