D3-OSH
Operating System Hardening
Configure operating systems securely by removing unnecessary services, applying patches, and enforcing security policies.
D3FEND / Harden
Implementation
- Apply OS security baselines
- Remove or disable unnecessary services
- Implement host-based firewall
- Enable audit logging
- Deploy endpoint protection
Tools
- Microsoft Security Baseline
- CIS Hardened Images
- SCAP Compliance Checker
- Ansible Security Automation
- Puppet/Chef