Service 04Baseline

Server hardening.

Servers configured to a recognised security benchmark, audited against it, and kept there as your estate changes.

Fibre patch leads connected to a rack-mounted switch
Fig. — Edge switching04

Scope

What the service covers
01

CIS and NCSC-aligned baselines

Benchmarks applied per distribution, with justified exceptions recorded rather than silently skipped.

02

Access control

Key-only SSH, MFA where supported, PAM policy and sudo rights scoped to role.

03

Host firewalls

nftables and firewalld on every host, default-deny, with rules held in configuration management.

04

Audit and logging

auditd rules and central log collection, so logins and changes are traceable.

05

Vulnerability management

Scheduled scanning, prioritised findings and tracked remediation.

06

Compromised host assessment

Triage, evidence preservation and clean rebuild for systems suspected of compromise.

Method

4 stages
1

Assess

Current configuration scanned and reviewed against the target benchmark.

2

Plan

Changes, exceptions and maintenance windows agreed in writing.

3

Apply

Changes rolled out through Ansible, tested and reversible.

4

Verify

Hosts re-scanned and compliance reported per server.

You receive

  • +Baseline assessment report
  • +Per-host compliance scores
  • +Exceptions register
  • +Ansible roles for your baseline
  • +Scheduled re-audit

Tooling

OpenSCAPLynisCIS-CATauditdfail2banCrowdSecnftablesOPNsenseWireGuard
Available as
  • Managed
  • Project
  • On call
Other services