CMMCDocsCMMCDocs.com

Home / Glossary / Hardening

Hardening

Also known as: System hardening

The process of configuring a system to reduce its attack surface by disabling unnecessary services, applying patches, and enforcing security settings.

Hardening is the process of configuring a system — operating system, application, network device, or database — to reduce its attack surface and resist compromise. Hardening typically involves disabling unnecessary services and ports, removing default accounts, applying current patches, configuring security settings according to a published baseline, and enabling audit logging.

The most common hardening references are the Center for Internet Security (CIS) Benchmarks and the DISA Security Technical Implementation Guides (STIGs).

Stop Googling. Start working.

CMMCDocs has all 110 NIST SP 800-171 Rev 2 requirements built in — with the language, the templates, and the evidence vault you need. Spin up a free demo workspace and click around the way an assessor would.

Get my demo account