
- Home
- Best Practices
- Recommendations
Recommendations
Recommendations
Critical
- Ensure MFA and strong passwords are enforced.
- Ensure regular backup of important data.
- Ensure patching is automated and all systems and server components are updated.
Important
- Ensure network segmentation is implemented.
- Ensure IDS/IPS and WAF are deployed and configured.
- Ensure unused ports and services are disabled.
- Ensure logging and monitoring are enabled.
- Ensure RDP/SSH access is restricted.
- Ensure Principle of Least Privilege is applied.
- Ensure inactive and default accounts are removed.
- Ensure EDR/XDR and endpoint protection deployed and up to date.
- Ensure USB, macros, and scripting tools are restricted.
- Ensure vulnerability assessments are regularly conducted, especially on internet-facing systems.
- Ensure OWASP’s Top 10 is followed for web application security.
- Ensure directory traversal is restricted on websites.
- Ensure services run under service accounts, not administrator accounts.
- Ensure user’s permissions are periodically reviewed.
- Ensure brute force attack protection is in place by limiting login attempts.
- Ensure DNS filtering is configured.
- Ensure employees are educated on cybersecurity threats and best practices.

