Hardening has an expiration date
Anyone can harden once: work through the benchmark, tick it off, done. Then everyday operations arrive, and the configuration drifts, quietly and without bad intent. Why configuration drift is the normal state in the absence of measurement, and how isidaten now checks daily against 28 hardening benchmarks, on Linux directly via OpenSCAP.
Anyone can harden once: work through the benchmark, set the values, tick it off. Six months later, reality looks different. An update has reset a setting. A service was opened "briefly" for troubleshooting and never closed again. A new system went live before anyone thought about the benchmark. None of this is failure. Configuration drift is the normal state as soon as nobody re-measures.
Drift is quiet, and it has time
The treacherous thing about drift is its pace: it does not happen all at once but in small, individually reasonable steps. The annual audit measures once, drift works daily. And what gets exploited in the end is exactly what opened up between two measurements: the exposed endpoint, the default credentials, the forgotten service. How quickly such open doors are found and walked through today was covered here yesterday.
The cure for drift is not hardening twice, but measuring
The yardstick has existed for a long time: benchmarks like DISA STIG, CIS, ANSSI BP-028 or the BSI requirements describe, per operating system, what a secure configuration looks like. But the best yardstick is useless in a drawer. It has to be held against the system regularly, automatically, not as an annual project. Only then does "we hardened" become "we are hardened, as of today".
isidaten now measures daily against 28 catalogs
Security configuration management in isidaten has doubled its benchmark bundle from 14 to 28 catalogs: DISA STIGs for RHEL, SLES and macOS among others, plus ComplianceAsCode profiles such as ANSSI BP-028 and CIS for Debian 12 and 13, CIS for Ubuntu and SLES, PCI DSS for RHEL 9 and a BSI profile for RHEL 10. The isidaten agent checks systems daily via cron job, on Linux directly through OpenSCAP on the system itself. Your own XCCDF imports, such as licensed CIS content, are mapped to the agent checks automatically. Score and coverage sit per system and benchmark in the cockpit, justified exceptions remain traceable as waivers, and findings become measures in the ISMS.
What the module can do in detail is shown on the SCM module page. And if you want to know how hardened your systems really are today, talk to us.
Questions about this update?
Talk to us – we are happy to show you this feature in a demo.