Hardening an internet-facing lab server
The loop
- ReviewBaseline what is running and what is exposed.
- ReduceRemove services that are not needed and tighten configuration.
- ScanRun a vulnerability scan against the result.
- Remediate and repeatFix what the scan finds, then scan again.
I iterated until two findings remained on the post-hardening scan. Hardening becomes measurable when every change is followed by a fresh scan and the residual risk is understood.