Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Hardening and Configuration Review5 services in this practice area

Turn Default Builds into Hardened Ones

Operating System Hardening Review

We measure your Windows and Linux systems against CIS Benchmarks and DISA STIGs, then show you which settings leave you exposed. You get a hardening runbook your build team can fold into your golden images.

See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index

Overview

Every server and workstation ships with settings tuned for convenience, not security. Over time, builds drift further from any standard. This review reads the live configuration of representative Windows and Linux hosts, compares it to CIS Benchmarks and STIGs, and highlights the settings that raise real risk: weak authentication, excess services, missing logging, and loose file permissions. We keep it practical, so the fixes land in your images rather than gathering dust.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Operating System Hardening Review engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We choose representative hosts by role and operating system, then select the matching CIS Benchmark and STIG profile for each build. Activities: Inventory host roles, OS versions and golden image lineage; Pick representative hosts per build and role; Select the CIS Benchmark level and STIG profile per build; Agree scan windows with the platform team. Hands over Host Sample and Baseline Selection. Phase 2, Evidence and Config Collection. We gather configuration with agent-based and agentless checks, capturing policy, services, accounts, logging and file permissions as evidence. Activities: Export local and domain security policy from Windows hosts; Capture running services, open ports and installed packages; Collect local account, sudoers and password policy settings; Record file permissions on system and application directories. Hands over Per-Host Configuration Evidence Set. Phase 3, Benchmark Comparison. We run CIS-CAT Pro, Lynis and OpenSCAP against each host and map results to the relevant CIS and STIG controls. Activities: Run CIS-CAT Pro against Windows and Linux samples; Run Lynis and OpenSCAP for supplementary Linux coverage; Map each failed check to its CIS and STIG control ID; Score each build against its benchmark level. Hands over Benchmark Scorecard Per Build. Phase 4, Manual Review of Risky Settings. We review the settings that carry real weight, checking for weak authentication, unnecessary services, and gaps in audit logging that scanners can misjudge. Activities: Check password, lockout and Kerberos policy against the baseline; Identify unnecessary services and legacy protocols still enabled; Review auditd and Sysmon coverage against the events you need; Test whether local administrator passwords are unique per host. Hands over Validated High-Impact Settings Review. Phase 5, Prioritised Findings. Findings are ranked by exposure and grouped by build, so your team can harden the golden image once rather than patching hosts one by one. Activities: Rank each failed control by exploitability and reach; Group findings by golden image rather than by host; Flag settings likely to break applications if changed; Sequence fixes into image changes and runtime changes. Hands over OS Configuration Findings Report. Phase 6, Remediation and Re-Check. We supply hardening guidance and sample Ansible or Group Policy, then re-scan to confirm the scorecard has improved. Activities: Write hardening steps with the setting name and safe value; Provide sample Ansible roles and Group Policy objects; Advise on staged rollout and rollback for risky settings; Re-scan the hardened image and reissue the scorecard. Hands over Hardening Runbook and Re-Check Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Baseline Selection

We choose representative hosts by role and operating system, then select the matching CIS Benchmark and STIG profile for each build.

What Happens In This Phase

  • Inventory host roles, OS versions and golden image lineage
  • Pick representative hosts per build and role
  • Select the CIS Benchmark level and STIG profile per build
  • Agree scan windows with the platform team

The Handover

Host Sample and Baseline Selection

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Baseline Selection

    We choose representative hosts by role and operating system, then select the matching CIS Benchmark and STIG profile for each build.

    OutputHost Sample and Baseline Selection

    Activities

    • Inventory host roles, OS versions and golden image lineage
    • Pick representative hosts per build and role
    • Select the CIS Benchmark level and STIG profile per build
    • Agree scan windows with the platform team
  2. 02

    Evidence and Config Collection

    We gather configuration with agent-based and agentless checks, capturing policy, services, accounts, logging and file permissions as evidence.

    OutputPer-Host Configuration Evidence Set

    Activities

    • Export local and domain security policy from Windows hosts
    • Capture running services, open ports and installed packages
    • Collect local account, sudoers and password policy settings
    • Record file permissions on system and application directories
  3. 03

    Benchmark Comparison

    We run CIS-CAT Pro, Lynis and OpenSCAP against each host and map results to the relevant CIS and STIG controls.

    OutputBenchmark Scorecard Per Build

    Activities

    • Run CIS-CAT Pro against Windows and Linux samples
    • Run Lynis and OpenSCAP for supplementary Linux coverage
    • Map each failed check to its CIS and STIG control ID
    • Score each build against its benchmark level
  4. 04

    Manual Review of Risky Settings

    We review the settings that carry real weight, checking for weak authentication, unnecessary services, and gaps in audit logging that scanners can misjudge.

    OutputValidated High-Impact Settings Review

    Activities

    • Check password, lockout and Kerberos policy against the baseline
    • Identify unnecessary services and legacy protocols still enabled
    • Review auditd and Sysmon coverage against the events you need
    • Test whether local administrator passwords are unique per host
  5. 05

    Prioritised Findings

    Findings are ranked by exposure and grouped by build, so your team can harden the golden image once rather than patching hosts one by one.

    OutputOS Configuration Findings Report

    Activities

    • Rank each failed control by exploitability and reach
    • Group findings by golden image rather than by host
    • Flag settings likely to break applications if changed
    • Sequence fixes into image changes and runtime changes
  6. 06

    Remediation and Re-Check

    We supply hardening guidance and sample Ansible or Group Policy, then re-scan to confirm the scorecard has improved.

    OutputHardening Runbook and Re-Check Report

    Activities

    • Write hardening steps with the setting name and safe value
    • Provide sample Ansible roles and Group Policy objects
    • Advise on staged rollout and rollback for risky settings
    • Re-scan the hardened image and reissue the scorecard

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Operating System Hardening Review scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: CIS-CAT Pro, Lynis, OpenSCAP, Microsoft Security Compliance Toolkit, Ansible, PowerShell DSC, Nessus (compliance audit), auditd and Sysmon review. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS Microsoft Windows Benchmarks, CIS Linux Benchmarks (Ubuntu, RHEL, Debian), DISA STIGs for Windows and Linux, NIST SP 800-123, NIST SP 800-53, Microsoft security baselines, MITRE ATT&CK.

What We Run

8 tools

  • CIS-CAT Pro
  • Lynis
  • OpenSCAP
  • Microsoft Security Compliance Toolkit
  • Ansible
  • PowerShell DSC
  • Nessus (compliance audit)
  • auditd and Sysmon review

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

7 standards

  • CISMicrosoft Windows
  • CISLinuxUbuntu, RHEL, Debian
  • DISASTIGsWindows and Linux
  • NIST SP 800-123
  • NIST SP 800-53
  • MSMicrosoftSecurity Baselines
  • MITRE ATT&CK
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • OS configuration findings report
  • CIS and STIG benchmark scorecard
  • Hardening runbook with sample automation
  • Re-check report after remediation

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Do you scan every host?

We assess representative hosts per role and build. Because most drift comes from shared images, fixing the image usually fixes the fleet.

Do you support both CIS and STIG?

Yes. We map to CIS Benchmarks by default and can align to DISA STIGs where your contracts or regulators call for them.

Will you help us automate the fixes?

We hand over hardening guidance with sample Ansible and Group Policy so your team can bake the changes into your build pipeline.