Security hardening is a systematic method to reduce the attack surface by applying configuration, architectural, and operational controls across systems and services. It comprises baseline configurations, patching, access control, network restrictions, and automated verification of configuration drift to prevent common vulnerabilities. Applied to infrastruct…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
Security hardening reduces a system’s attack surface by removing or securing unnecessary functions, access paths, and unsafe settings.
The term grew in systems and network security from the need to adapt default installations to concrete threats. Guides such as NIST SP 800-53 classify these measures as controls, and tools automate their application.
Work layer by layer: inventory, disable unnecessary components, restrict access, configure securely, patch, and measure again. Every change needs a recovery path.
It includes reachable functions, interfaces, and permissions.
A baseline defines permitted configurations and settings.
Scans and tests show whether hardening remains effective.
Hardening lowers the likelihood of successful attacks and limits their consequences. It belongs in operations, deployment, and change management so secure settings persist.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.