A.4 System Hardening Standards

Version: April 2025
Aligned with: ISO/IEC 27001:2022 (Annex A: A.8.9)
Applies to: All servers, workstations, and deployed systems

Purpose
To define system hardening requirements that reduce the attack surface and improve security posture of organizational systems.

1. Operating System Configuration
(Aligned with A.8.9 – Configuration management)

  • Remove or disable unnecessary services and applications
  • Apply security patches within 30 days of release
  • Enable system logging and log forwarding
  • Configure automatic screen locks and session timeouts

2. Application Security
(Aligned with A.8.9 – Configuration management)

  • Secure coding standards for all development projects
  • Regular vulnerability scanning and penetration testing
  • Code review requirements for security-critical functions
  • Third-party software security assessment before deployment
Direct URL: