/
Fredonia Minimum Security Standards: Servers

Fredonia Minimum Security Standards: Servers

A server is defined as a host that provides a network accessible service.

Follow the minimum security standards in the table below to safeguard your servers.

STANDARDS

RECURRING TASK

WHAT TO DO

LOW RISK

MODERATE RISK

HIGH RISK

Patching

Based on National Vulnerability Database (NVD) ratings, apply high severity security patches within seven days of publish and all other security patches within 30 days. Use a supported OS version.

Vulnerability Management

Perform a monthly Vulnerability scans via Enterprise Vulnerability Management System. Remediate severity Critical and High within seven days of discovery and severity Medium vulnerabilities within 90 days.

Inventory

Review and update records quarterly. Maximum of one node per record.

Firewall



Enable host-based firewall in default deny mode and permit the minimum necessary services.

Credentials and Access Control

Review existing accounts and privileges quarterly.

Two-Factor Authentication



Require two-factor authentication for all interactive user and administrator logins. Two-facto