There are some industry security practices we can refer to for the secure configuration of the infrastructure. Here we will introduce three practices: the Center for Internet Security benchmarks, Security Technical Implementation Guides (STIGs), and the OpenSCAP Security Guide.
Secure configuration best practices
CIS (Center for Internet Security) benchmarks
The Center for Internet Security (CIS) benchmarks provides a wide range of secure configuration recommendations. It covers the following areas:
- Desktops and web browsers
- Mobile devices
- Network devices
- Security metrics
- Servers—operating systems
- Servers—other
- Virtualization platforms and cloud
In addition to providing secure configuration, the CIS also provides...