Creating your security baseline
The secure configuration of your endpoints, cloud assets, and network devices is paramount to protecting your company from hackers. Gartner has said that 99% of cloud and network breaches are due to misconfiguration. This is something you can do for free. It’s not an easy task, but it is well worth it and probably one of the most important actions you can take other than MFA and regular patching. We discussed this previously, but CIS is the de facto secure configuration standard for the commercial space, and STIGS are required for US Federal government networks and FedRAMP. The good news is that there are mappings of CIS to SOC2, HIPAA, NIST CSF, and PCI on the CIS website. As I’ve stated before, there are compliance products, such as Drata, that will automate the controls you need to meet. There is also a compliance mapping you can download for free called the Secure Controls Framework (SCF). It offers a master mapping of almost every...