Fredonia Minimum Security Standards: Servers
A server is defined as a host that provides a network accessible service.
Follow the minimum security standards in the table below to safeguard your servers.
STANDARDS | RECURRING TASK | WHAT TO DO | LOW RISK | MODERATE RISK | HIGH RISK |
Patching | ✔ | Based on National Vulnerability Database (NVD) ratings, apply high severity security patches within seven days of publish and all other security patches within 30 days. Use a supported OS version. | ✔ | ✔ | ✔ |
Vulnerability Management | ✔ | Perform a monthly Vulnerability scans via Enterprise Vulnerability Management System. Remediate severity Critical and High within seven days of discovery and severity Medium vulnerabilities within 90 days. | ✔ | ✔ | ✔ |
Inventory | ✔ | Review and update records quarterly. Maximum of one node per record. | ✔ | ✔ | ✔ |
Firewall | Enable host-based firewall in default deny mode and permit the minimum necessary services. | ✔ | ✔ | ✔ | |
Credentials and Access Control | ✔ | Review existing accounts and privileges quarterly. | ✔ | ✔ | ✔ |
Two-Factor Authentication |