-
Vendors
- Security standards are often created by the vendors of IT devices, applications and operating systems.
- Standards from a vendor source are considered the least objective.
-
Example: Microsoft Security Compliance Manager
- A tool that assists with system configuration and management.
- Includes a large number of built-in security configuration baselines for various versions of the Windows server and Windows desktop operating systems, Internet Explorer, Exchange Server and Microsoft Office.
-
Government Agencies
- Instead of a vendor, some organizations may wish for a more objective source of information and expertise when developing security standards. Government agencies such as NIST are an excellent source of security guidance.
-
Example: NIST SP 800-179
- Provides security guidelines Apple's Macintosh OS X 10.10 (Yosemite).
- 126 pages
-
Topics:
- How the guide was developed
- Components of OS 10
- Installation, backup, and patching procedures
- Security Configuration
- Specific NIST Guidelines
- Very Detailed
-
Third Party Organizations
- Some organizations want an even more objective source than the government and seek out third-party organizations that exist solely to provide security advice.
-
Example: The Center for Internet Security (CIS)
- Publishes a series of security benchmarks that represent the consensus opinions of a large number of subject matter experts.
-
Benchmarks (Baselines) Lists:
-
Desktops & Web Browsers
- Apple Desktop OSX
- Apple Safari Browser
- Google Chrome
- Microsoft Internet Explorer
- Microsoft Windows Desktop XP/NT
- Mozilla Firefox Browser
- Opera Browser
-
Mobile Devices
- Apple Mobile Platform iOS
- Google Mobile Platform
-
Network Devices
- Agnostic Print Devices
- Checkpoint Firewall
- Cisco Firewall Devices
- Cisco Routers/Switches IOS
- Cisco Wireless LAN Controller
- Juniper Routers/Switches JunOS
-
Servers (Operating Systems)
- Amazon Linux
- CentOS
- Debian Linux Server
- IBM AIX Server
- Microsoft Windows Server
- Novell Netware
- Oracle Linux
- Oracle Solaris Server
- Red Hat Linux Server
- Slackware Linux Server
- SUSE Linux Enterprise Server
- Ubuntu LTS Server
-
Servers (Other)
- Apache HTTP Server
- Apache Tomcat Server
- BIND DNS Server
- FreeRADIUS
- Microsoft IIS Server
- IBM DB2 Server
- Microsoft Exchange
- Microsoft SharePoint Server
- Microsoft SQL Server
- MIT Kerberos
- MySQL Database Server
- Novell eDirectory
- OpenLDAP Server
- Oracle Database Server
- Sybase Database Server
-
Virtualization Platforms & Cloud
- Agnostic VM Server
- AWS Foundations
- AWS Three-Tier Web Architecture
- Docker
- Kubernetes
- VMware Server
- Xen Server
-
Other
- Microsoft Access
- Microsoft Excel
- Microsoft Office
- Microsoft Outlook
- Microsoft PowerPoint
- Microsoft Word