17

Can anyone point me at some good resources on Windows hardening? From 2003 upwards.

Zuly Gonzalez
  • 394
  • 3
  • 21

4 Answers4

10
Steve
  • 15,155
  • 3
  • 37
  • 66
10

The Center for Internet Security publishes Benchmark configurations for several operating systems and other products, including: servers, workstations, infrastructure devices, and more.

The United States National Institute of Standards and Technology has published configurations for Windows 7 as the United States Government Configuration Baseline, and for XP/Vista as the Federal Desktop Core Configuration.

Iszi
  • 26,997
  • 18
  • 98
  • 163
  • +1. The NSA also publish their own guidelines, or sometimes (in the case of Win7/Vista) link to other appropriate guidelines that match their standards. http://www.nsa.gov/ia/guidance/security_configuration_guides/operating_systems.shtml#microsoft –  Jul 06 '11 at 18:03
4

On the flip side of hardening guides and standards documents, you have the posture assessment angle. These audits can help you either determine how far off standard you are, or how closely you are actually following what you've decided to implement. The two that I have used, and enjoyed are:

  1. Microsoft Baseline Security Analyzer (MBSA)
  2. Nessus Audit Policies

MBSA is an installed application that will audit the security of a Windows system, against the Microsoft recommendations, and produce an excellent report.

The Nessus audit files are included as part of a vulnerability scan and will test against the CIS benchmark.

Both tools produce great reports and can really help with your standards development and/or compliance.

Scott Pack
  • 15,167
  • 5
  • 61
  • 91
2

As mentioned on this post over on SU, another useful product if you are aiming for a locked down Kiosk is the Trishell Kiosk Edition - worth having a look at as well.

Rory Alsop
  • 61,367
  • 12
  • 115
  • 320