The attributes behind your decision
- Decision input
- Measured workload
- Primary variables
- Capacity, control, operations
- Validation
- Representative testing
- Next step
- Swiss hosting privacy
Reduce administrative exposure
Use unique administrator accounts where supported, strong authentication and restricted management access. Protect private keys and recovery credentials outside the server.
Patch the operating system and services
Maintain supported software, remove unused packages and services, and schedule security updates with a rollback plan. Application dependencies require patching as well as the base system.
Limit network paths and privileges
Allow only required inbound and outbound connections, apply least privilege and separate services where compromise would create unacceptable impact. Review exposed ports regularly.
Log, monitor and prepare recovery
Centralize important logs when appropriate, alert on suspicious access and configuration change, and maintain tested backups. Hardening lowers risk but cannot eliminate incidents.
