Turn Default Builds into Hardened Ones
Operating System Hardening Review
We measure your Windows and Linux systems against CIS Benchmarks and DISA STIGs, then show you which settings leave you exposed. You get a hardening runbook your build team can fold into your golden images.
See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index
Overview
Every server and workstation ships with settings tuned for convenience, not security. Over time, builds drift further from any standard. This review reads the live configuration of representative Windows and Linux hosts, compares it to CIS Benchmarks and STIGs, and highlights the settings that raise real risk: weak authentication, excess services, missing logging, and loose file permissions. We keep it practical, so the fixes land in your images rather than gathering dust.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Operating System Hardening Review engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We choose representative hosts by role and operating system, then select the matching CIS Benchmark and STIG profile for each build. Activities: Inventory host roles, OS versions and golden image lineage; Pick representative hosts per build and role; Select the CIS Benchmark level and STIG profile per build; Agree scan windows with the platform team. Hands over Host Sample and Baseline Selection. Phase 2, Evidence and Config Collection. We gather configuration with agent-based and agentless checks, capturing policy, services, accounts, logging and file permissions as evidence. Activities: Export local and domain security policy from Windows hosts; Capture running services, open ports and installed packages; Collect local account, sudoers and password policy settings; Record file permissions on system and application directories. Hands over Per-Host Configuration Evidence Set. Phase 3, Benchmark Comparison. We run CIS-CAT Pro, Lynis and OpenSCAP against each host and map results to the relevant CIS and STIG controls. Activities: Run CIS-CAT Pro against Windows and Linux samples; Run Lynis and OpenSCAP for supplementary Linux coverage; Map each failed check to its CIS and STIG control ID; Score each build against its benchmark level. Hands over Benchmark Scorecard Per Build. Phase 4, Manual Review of Risky Settings. We review the settings that carry real weight, checking for weak authentication, unnecessary services, and gaps in audit logging that scanners can misjudge. Activities: Check password, lockout and Kerberos policy against the baseline; Identify unnecessary services and legacy protocols still enabled; Review auditd and Sysmon coverage against the events you need; Test whether local administrator passwords are unique per host. Hands over Validated High-Impact Settings Review. Phase 5, Prioritised Findings. Findings are ranked by exposure and grouped by build, so your team can harden the golden image once rather than patching hosts one by one. Activities: Rank each failed control by exploitability and reach; Group findings by golden image rather than by host; Flag settings likely to break applications if changed; Sequence fixes into image changes and runtime changes. Hands over OS Configuration Findings Report. Phase 6, Remediation and Re-Check. We supply hardening guidance and sample Ansible or Group Policy, then re-scan to confirm the scorecard has improved. Activities: Write hardening steps with the setting name and safe value; Provide sample Ansible roles and Group Policy objects; Advise on staged rollout and rollback for risky settings; Re-scan the hardened image and reissue the scorecard. Hands over Hardening Runbook and Re-Check Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Baseline Selection
We choose representative hosts by role and operating system, then select the matching CIS Benchmark and STIG profile for each build.
What Happens In This Phase
- Inventory host roles, OS versions and golden image lineage
- Pick representative hosts per build and role
- Select the CIS Benchmark level and STIG profile per build
- Agree scan windows with the platform team
The Handover
Host Sample and Baseline Selection
The next phase starts from this.
Phase 01 Scoping and Baseline Selection
We choose representative hosts by role and operating system, then select the matching CIS Benchmark and STIG profile for each build.
What Happens In This Phase
- Inventory host roles, OS versions and golden image lineage
- Pick representative hosts per build and role
- Select the CIS Benchmark level and STIG profile per build
- Agree scan windows with the platform team
The Handover
Host Sample and Baseline Selection
The next phase starts from this.
- 01
Scoping and Baseline Selection
We choose representative hosts by role and operating system, then select the matching CIS Benchmark and STIG profile for each build.
OutputHost Sample and Baseline SelectionActivities
- Inventory host roles, OS versions and golden image lineage
- Pick representative hosts per build and role
- Select the CIS Benchmark level and STIG profile per build
- Agree scan windows with the platform team
- 02
Evidence and Config Collection
We gather configuration with agent-based and agentless checks, capturing policy, services, accounts, logging and file permissions as evidence.
OutputPer-Host Configuration Evidence SetActivities
- Export local and domain security policy from Windows hosts
- Capture running services, open ports and installed packages
- Collect local account, sudoers and password policy settings
- Record file permissions on system and application directories
- 03
Benchmark Comparison
We run CIS-CAT Pro, Lynis and OpenSCAP against each host and map results to the relevant CIS and STIG controls.
OutputBenchmark Scorecard Per BuildActivities
- Run CIS-CAT Pro against Windows and Linux samples
- Run Lynis and OpenSCAP for supplementary Linux coverage
- Map each failed check to its CIS and STIG control ID
- Score each build against its benchmark level
- 04
Manual Review of Risky Settings
We review the settings that carry real weight, checking for weak authentication, unnecessary services, and gaps in audit logging that scanners can misjudge.
OutputValidated High-Impact Settings ReviewActivities
- Check password, lockout and Kerberos policy against the baseline
- Identify unnecessary services and legacy protocols still enabled
- Review auditd and Sysmon coverage against the events you need
- Test whether local administrator passwords are unique per host
- 05
Prioritised Findings
Findings are ranked by exposure and grouped by build, so your team can harden the golden image once rather than patching hosts one by one.
OutputOS Configuration Findings ReportActivities
- Rank each failed control by exploitability and reach
- Group findings by golden image rather than by host
- Flag settings likely to break applications if changed
- Sequence fixes into image changes and runtime changes
- 06
Remediation and Re-Check
We supply hardening guidance and sample Ansible or Group Policy, then re-scan to confirm the scorecard has improved.
OutputHardening Runbook and Re-Check ReportActivities
- Write hardening steps with the setting name and safe value
- Provide sample Ansible roles and Group Policy objects
- Advise on staged rollout and rollback for risky settings
- Re-scan the hardened image and reissue the scorecard
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Operating System Hardening Review scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: CIS-CAT Pro, Lynis, OpenSCAP, Microsoft Security Compliance Toolkit, Ansible, PowerShell DSC, Nessus (compliance audit), auditd and Sysmon review. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS Microsoft Windows Benchmarks, CIS Linux Benchmarks (Ubuntu, RHEL, Debian), DISA STIGs for Windows and Linux, NIST SP 800-123, NIST SP 800-53, Microsoft security baselines, MITRE ATT&CK.
What We Run
8 tools
- Lynis
- Microsoft Security Compliance Toolkit
- PowerShell DSC
- auditd and Sysmon review
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
7 standards
- CIS
- CISUbuntu, RHEL, Debian
- DISAWindows and Linux
- MSMicrosoft
Deliverables
What You Receive
- OS configuration findings report
- CIS and STIG benchmark scorecard
- Hardening runbook with sample automation
- Re-check report after remediation
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Do you scan every host?
We assess representative hosts per role and build. Because most drift comes from shared images, fixing the image usually fixes the fleet.
Do you support both CIS and STIG?
Yes. We map to CIS Benchmarks by default and can align to DISA STIGs where your contracts or regulators call for them.
Will you help us automate the fixes?
We hand over hardening guidance with sample Ansible and Group Policy so your team can bake the changes into your build pipeline.
Keep Moving Through Hardening and Configuration Review
Service 2 of 5 in this practice area
Practice Area
More in Hardening and Configuration Review
- Cloud Security Configuration AssessmentBenchmark review of your AWS, Azure and GCP accounts against secure baselines
- Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths
- Database and Web Server ConfigurationHardening review of your databases and web servers against CIS Benchmarks