Control Objectives: System hardening through configuration management

No control objectives match the current filters.
Approve each system's Configurable Items (and changes to those Configurable Items).
SNow
Classification: PreventiveState: Published
Approve each system's Configurable Items (and changes to those Configurable Items).
Block and/or remove unused software and unauthorized software.
SNow
Classification: PreventiveState: Published
Block and/or remove unused software and unauthorized software.
Change all default passwords.
SNow
Classification: PreventiveState: Published
Change all default passwords.
Change the default community string for Simple Network Management Protocol.
SNow
Classification: PreventiveState: Published
Change the default community string for Simple Network Management Protocol.
Change vendor-supplied default configurations as appropriate.
SNow
Classification: PreventiveState: Published
Change vendor-supplied default configurations as appropriate.
Configure Session Configuration settings in accordance with organizational standards.
SNow
Classification: PreventiveState: Published
Configure Session Configuration settings in accordance with organizational standards.
Configure System Integrity settings in accordance with organizational standards.
SNow
Classification: PreventiveState: Published
Configure System Integrity settings in accordance with organizational standards.
Configure accounts with administrative privilege.
SNow
Classification: PreventiveState: Published
Configure accounts with administrative privilege.
Configure additional custom Wireless Access Points, Intrusion Detection System and Intrusion Prevention System settings in accordance with organizational standards.
SNow
Classification: PreventiveState: Published
Configure additional custom Wireless Access Points, Intrusion Detection System and Intrusion Prevention System settings in accordance with organizational standards.
Configure additional log settings.
SNow
Classification: PreventiveState: Published
Configure additional log settings.
Configure automatic logout to terminate sessions based on inactivity according to organizational standards.
SNow
Classification: PreventiveState: Published
Configure automatic logout to terminate sessions based on inactivity according to organizational standards.
Configure each user's authentication mechanism (system attribute) properly.
SNow
Classification: PreventiveState: Published
Configure each user's authentication mechanism (system attribute) properly.
Configure mobile environment Portable Electronic Device settings in accordance with organizational standards.
SNow
Classification: PreventiveState: Published
Configure mobile environment Portable Electronic Device settings in accordance with organizational standards.
Configure passwords so that group passwords or shared passwords are prohibited.
SNow
Classification: PreventiveState: Published
Configure passwords so that group passwords or shared passwords are prohibited.
Configure passwords so that users will change their passwords on a regular basis.
SNow
Classification: PreventiveState: Published
Configure passwords so that users will change their passwords on a regular basis.
Configure passwords to comply with organizational standards.
SNow
Classification: PreventiveState: Published
Configure passwords to comply with organizational standards.
Configure sufficient log storage capacity, and configure the system to prevent the capacity from being exceeded.
SNow
Classification: PreventiveState: Published
Configure sufficient log storage capacity, and configure the system to prevent the capacity from being exceeded.
Configure system accounting/system events.
SNow
Classification: PreventiveState: Published
Configure system accounting/system events.
Configure system clocks for synchronization (SYN) of time to an accurate and universal time source, preferably an organizational Network Time Protocol (NTP) server.
SNow
Classification: PreventiveState: Published
Configure system clocks for synchronization (SYN) of time to an accurate and universal time source, preferably an organizational Network Time Protocol (NTP) server.
Configure the "Turn off AutoPlay" setting.
SNow
Classification: PreventiveState: Published
Configure the "Turn off AutoPlay" setting.
Configure the "require new users to change their password on first logon" password setting to organizations standards.
SNow
Classification: PreventiveState: Published
Configure the "require new users to change their password on first logon" password setting to organizations standards.
Configure the Access Control List to restrict connections between untrusted networks and any system that holds restricted data or restricted information.
SNow
Classification: PreventiveState: Published
Configure the Access Control List to restrict connections between untrusted networks and any system that holds restricted data or restricted information.
Configure the Lockout duration to a predefined time period.
SNow
Classification: PreventiveState: Published
Configure the Lockout duration to a predefined time period.
Configure the Password Complexity setting.
SNow
Classification: PreventiveState: Published
Configure the Password Complexity setting.
Configure the Password history setting so that users cannot submit a new password that is the same as the previous few used.
SNow
Classification: PreventiveState: Published
Configure the Password history setting so that users cannot submit a new password that is the same as the previous few used.
Configure the Password length to the least allowable.
SNow
Classification: PreventiveState: Published
Configure the Password length to the least allowable.
Configure the Wireless Access Point transmit power setting to the lowest level possible.
SNow
Classification: PreventiveState: Published
Configure the Wireless Access Point transmit power setting to the lowest level possible.
Configure the account lockout duration to organizational standards.
SNow
Classification: PreventiveState: Published
Configure the account lockout duration to organizational standards.
Configure the amount of idle time required before disconnecting an idle session.
SNow
Classification: PreventiveState: Published
Configure the amount of idle time required before disconnecting an idle session.
Configure the detailed data elements to be captured for all logs so that events are identified by type, location, subject, user, what data was accessed, etc.
SNow
Classification: PreventiveState: Published
Configure the detailed data elements to be captured for all logs so that events are identified by type, location, subject, user, what data was accessed, etc.
Configure the log settings for specific Operating System functions.
SNow
Classification: PreventiveState: Published
Configure the log settings for specific Operating System functions.
Configure the log to capture Object access to key directories or key files.
SNow
Classification: DetectiveState: Published
Configure the log to capture Object access to key directories or key files.
Configure the log to capture access to restricted data or restricted information.
SNow
Classification: DetectiveState: Published
Configure the log to capture access to restricted data or restricted information.
Configure the log to capture actions taken by individuals with root privileges or administrative privileges and add logging option to the root file system.
SNow
Classification: DetectiveState: Published
Configure the log to capture actions taken by individuals with root privileges or administrative privileges and add logging option to the root file system.
Configure the log to capture all access to the audit trail.
SNow
Classification: DetectiveState: Published
Configure the log to capture all access to the audit trail.
Configure the log to capture audit log initialization, along with auditable event selection.
SNow
Classification: DetectiveState: Published
Configure the log to capture audit log initialization, along with auditable event selection.
Configure the log to capture both access and access attempts to security-relevant objects and security-relevant directories.
SNow
Classification: DetectiveState: Published
Configure the log to capture both access and access attempts to security-relevant objects and security-relevant directories.
Configure the log to capture changes to User privileges, audit policies, and trust policies by enabling audit policy changes.
SNow
Classification: DetectiveState: Published
Configure the log to capture changes to User privileges, audit policies, and trust policies by enabling audit policy changes.
Configure the log to capture configuration changes.
SNow
Classification: PreventiveState: Published
Configure the log to capture configuration changes.
Configure the log to capture each auditable event's origination.
SNow
Classification: DetectiveState: Published
Configure the log to capture each auditable event's origination.
Configure the log to capture each event's success or failure indication.
SNow
Classification: PreventiveState: Published
Configure the log to capture each event's success or failure indication.
Configure the log to capture hardware access attempts and software access attempts.
SNow
Classification: DetectiveState: Published
Configure the log to capture hardware access attempts and software access attempts.
Configure the log to capture identification and authentication mechanism use.
SNow
Classification: DetectiveState: Published
Configure the log to capture identification and authentication mechanism use.
Configure the log to capture logons, logouts, logon attempts, and logout attempts.
SNow
Classification: DetectiveState: Published
Configure the log to capture logons, logouts, logon attempts, and logout attempts.
Configure the log to capture remote access information.
SNow
Classification: DetectiveState: Published
Configure the log to capture remote access information.
Configure the log to capture successful hardware and software access.
SNow
Classification: DetectiveState: Published
Configure the log to capture successful hardware and software access.
Configure the log to capture system level object creation and deletion.
SNow
Classification: DetectiveState: Published
Configure the log to capture system level object creation and deletion.
Configure the log to capture the type of each event.
SNow
Classification: PreventiveState: Published
Configure the log to capture the type of each event.
Configure the log to capture the user's identification information.
SNow
Classification: PreventiveState: Published
Configure the log to capture the user's identification information.
Configure the log to capture user authenticator changes.
SNow
Classification: DetectiveState: Published
Configure the log to capture user authenticator changes.
Configure the log to contain a timestamp.
SNow
Classification: PreventiveState: Published
Configure the log to contain a timestamp.
Configure the log to send alerts for each auditable events success or failure.
SNow
Classification: PreventiveState: Published
Configure the log to send alerts for each auditable events success or failure.
Configure the log to track date entries and time entries.
SNow
Classification: PreventiveState: Published
Configure the log to track date entries and time entries.
Configure the log to uniquely identify each asset.
SNow
Classification: PreventiveState: Published
Configure the log to uniquely identify each asset.
Configure the maximum password age.
SNow
Classification: PreventiveState: Published
Configure the maximum password age.
Configure the minimum password age.
SNow
Classification: PreventiveState: Published
Configure the minimum password age.
Configure the password policy to ban or allow passwords as words found in dictionaries as appropriate.
SNow
Classification: PreventiveState: Published
Configure the password policy to ban or allow passwords as words found in dictionaries as appropriate.
Configure the security parameters for all logs.
SNow
Classification: PreventiveState: Published
Configure the security parameters for all logs.
Configure the storage parameters for all logs.
SNow
Classification: PreventiveState: Published
Configure the storage parameters for all logs.
Configure the system account settings and the permission settings in accordance with the organizational access control policies.
SNow
Classification: PreventiveState: Published
Configure the system account settings and the permission settings in accordance with the organizational access control policies.
Configure the system logon banner contents.
SNow
Classification: PreventiveState: Published
Configure the system logon banner contents.
Configure the system security parameters to prevent system misuse or information misappropriation.
SNow
Classification: PreventiveState: Published
Configure the system security parameters to prevent system misuse or information misappropriation.
Configure the system to encrypt passwords.
SNow
Classification: PreventiveState: Published
Configure the system to encrypt passwords.
Configure the system to lock out User IDs after not more than a predefined number of access attempts.
SNow
Classification: PreventiveState: Published
Configure the system to lock out User IDs after not more than a predefined number of access attempts.
Configure the system to log all access attempts to all systems.
SNow
Classification: PreventiveState: Published
Configure the system to log all access attempts to all systems.
Configure the system to prevent unencrypted password use.
SNow
Classification: PreventiveState: Published
Configure the system to prevent unencrypted password use.
Configure the system to require a password before it unlocks the Screen saver.
SNow
Classification: PreventiveState: Published
Configure the system to require a password before it unlocks the Screen saver.
Configure the system to use asterisks to mask passwords.
SNow
Classification: PreventiveState: Published
Configure the system to use asterisks to mask passwords.
Configure the time server in accordance with organizational standards.
SNow
Classification: PreventiveState: Published
Configure the time server in accordance with organizational standards.
Configure the time server to synchronize with specifically designated hosts.
SNow
Classification: PreventiveState: Published
Configure the time server to synchronize with specifically designated hosts.
Configure the user account expiration date.
SNow
Classification: PreventiveState: Published
Configure the user account expiration date.
Create a baseline configuration document before releasing the system into a production environment.
SNow
Classification: PreventiveState: Published
Create a baseline configuration document before releasing the system into a production environment.
Create a secure system image of the baseline configuration to be used for building new systems.
SNow
Classification: PreventiveState: Published
Create a secure system image of the baseline configuration to be used for building new systems.
Create an access control list on Network Access and Control Components to restrict access.
SNow
Classification: PreventiveState: Published
Create an access control list on Network Access and Control Components to restrict access.
Disable CD Autorun.
SNow
Classification: PreventiveState: Published
Disable CD Autorun.
Disable DHCP Server unless DHCP Server is absolutely necessary.
SNow
Classification: PreventiveState: Published
Disable DHCP Server unless DHCP Server is absolutely necessary.
Disable Internet Protocol version 6 unless it is absolutely necessary.
SNow
Classification: PreventiveState: Published
Disable Internet Protocol version 6 unless it is absolutely necessary.
Disable all unnecessary User IDs.
SNow
Classification: PreventiveState: Published
Disable all unnecessary User IDs.
Disable all unnecessary applications unless otherwise noted in a policy exception.
SNow
Classification: PreventiveState: Published
Disable all unnecessary applications unless otherwise noted in a policy exception.
Disable all unnecessary hardware and unnecessary physical interfaces.
SNow
Classification: PreventiveState: Published
Disable all unnecessary hardware and unnecessary physical interfaces.
Disable all unnecessary services unless otherwise noted in a policy exception.
SNow
Classification: PreventiveState: Published
Disable all unnecessary services unless otherwise noted in a policy exception.
Disable unnecessary applications, ports, and protocols on Wireless Access Points.
SNow
Classification: PreventiveState: Published
Disable unnecessary applications, ports, and protocols on Wireless Access Points.
Document and justify system hardening standard exceptions.
SNow
Classification: PreventiveState: Published
Document and justify system hardening standard exceptions.
Enable Network Address Translation or Port Address Translation for internal networks on all network access and control points.
SNow
Classification: PreventiveState: Published
Enable Network Address Translation or Port Address Translation for internal networks on all network access and control points.
Enable WiFi Protected Access or Wi-Fi Protected Access-2.
SNow
Classification: PreventiveState: Published
Enable WiFi Protected Access or Wi-Fi Protected Access-2.
Enable data-at-rest encryption.
SNow
Classification: PreventiveState: Published
Enable data-at-rest encryption.
Enable logon authentication management techniques.
SNow
Classification: PreventiveState: Published
Enable logon authentication management techniques.
Enable or disable all BIOS wireless devices, as appropriate.
SNow
Classification: PreventiveState: Published
Enable or disable all BIOS wireless devices, as appropriate.
Enable or disable all wireless interfaces, as appropriate.
SNow
Classification: PreventiveState: Published
Enable or disable all wireless interfaces, as appropriate.
Enable the appropriate tunneling protocol for Internet Protocol version 6.
SNow
Classification: PreventiveState: Published
Enable the appropriate tunneling protocol for Internet Protocol version 6.
Enable the firewall and configure it to meet organizational standards.
SNow
Classification: PreventiveState: Published
Enable the firewall and configure it to meet organizational standards.
Enable two-factor authentication for identifying and authenticating Wireless Local Area Network users.
SNow
Classification: PreventiveState: Published
Enable two-factor authentication for identifying and authenticating Wireless Local Area Network users.
Encrypt non-console administrative access.
SNow
Classification: PreventiveState: Published
Encrypt non-console administrative access.
Establish and maintain a Configuration Management Plan.
SNow
Classification: PreventiveState: Published
Establish and maintain a Configuration Management Plan.
Establish and maintain a system hardening standard and system hardening procedures.
SNow
Classification: PreventiveState: Published
Establish and maintain a system hardening standard and system hardening procedures.
Establish and maintain an account lockout policy.
SNow
Classification: PreventiveState: Published
Establish and maintain an account lockout policy.
Establish and maintain an accurate Configuration Management Database with accessible reporting capabilities.
SNow
Classification: PreventiveState: Published
Establish and maintain an accurate Configuration Management Database with accessible reporting capabilities.
Establish and maintain appropriate system labeling.
SNow
Classification: PreventiveState: Published
Establish and maintain appropriate system labeling.
Establish and maintain configuration control and Configuration Status Accounting for each system.
SNow
Classification: PreventiveState: Published
Establish and maintain configuration control and Configuration Status Accounting for each system.
Establish and maintain procedures to standardize Operating System software installation.
SNow
Classification: PreventiveState: Published
Establish and maintain procedures to standardize Operating System software installation.
Establish and maintain the interactive logon settings.
SNow
Classification: PreventiveState: Published
Establish and maintain the interactive logon settings.
Establish idle session termination and logout capabilities.
SNow
Classification: PreventiveState: Published
Establish idle session termination and logout capabilities.
Generate an alert when an audit log failure occurs.
SNow
Classification: PreventiveState: Published
Generate an alert when an audit log failure occurs.
Identify and document the system's Configurable Items.
SNow
Classification: PreventiveState: Published
Identify and document the system's Configurable Items.
Implement only one application or primary function per network component or server.
SNow
Classification: PreventiveState: Published
Implement only one application or primary function per network component or server.
Implement safeguards to protect memory from unauthorized code execution.
SNow
Classification: PreventiveState: Published
Implement safeguards to protect memory from unauthorized code execution.
Install all available critical security updates and important security updates in a timely way.
SNow
Classification: PreventiveState: Published
Install all available critical security updates and important security updates in a timely way.
Manufacturing System configuration changes need to be reviewed for conformance with Cybersecurity policies, standards and baselines.
SNow
Classification: IdentifyState: Published
Manufacturing System configuration changes need to be reviewed for conformance with Cybersecurity policies, standards and baselines. In case the manufacturing system, network or any related change is not in line with Roche Manufacturing Cybersecurity requirements, a formal Exception approval need t
Manufacturing System configuration changes need to be reviewed for conformance with Cybersecurity policies, standards and baselines. Any exception needs to be processed according to PL ID 24636342 MC Change and Exceptions Management.
SNow
Classification: CorrectiveState: Published
Manufacturing System configuration changes need to be reviewed for conformance with Cybersecurity policies, standards and baselines. In case the manufacturing system, network or any related change is not in line with Roche Manufacturing Cybersecurity requirements, a formal Exception approval need t
Notify affected parties to keep passwords confidential.
SNow
Classification: PreventiveState: Published
Notify affected parties to keep passwords confidential.
Only traffic with clear business purpose should be allowed for the manufacturing system.
SNow
Classification: ProtectState: Published
Only traffic with clear business purpose should be allowed for the manufacturing system.
Prohibit the use of binary code or machine-executable code from sources with limited or no warranty absent the source code.
SNow
Classification: PreventiveState: Published
Prohibit the use of binary code or machine-executable code from sources with limited or no warranty absent the source code.
Reconfigure the encryption keys from their default setting or previous setting.
SNow
Classification: PreventiveState: Published
Reconfigure the encryption keys from their default setting or previous setting.
Remove all compilers and assemblers from the system.
SNow
Classification: PreventiveState: Published
Remove all compilers and assemblers from the system.
Remove all unnecessary functionality.
SNow
Classification: PreventiveState: Published
Remove all unnecessary functionality.
Remove unnecessary default user accounts.
SNow
Classification: PreventiveState: Published
Remove unnecessary default user accounts.
Restrict access to time server configuration to personnel with a business need.
SNow
Classification: PreventiveState: Published
Restrict access to time server configuration to personnel with a business need.
Review the firewall rules quarterly or when there are network changes.
SNow
Classification: PreventiveState: Published
Review the firewall rules quarterly or when there are network changes.
The manufacturing system configuration should be hardened, including restriction of use of unnecessary functions, closing non-used open ports/protocols and disabling unnecessary services.
SNow
Classification: ProtectState: Published
The manufacturing system configuration should be hardened, including restriction of use of unnecessary functions, closing non-used open ports/protocols and disabling unnecessary services.
The manufacturing system should not utilize dual-homed devices (e.g. servers) to communicate with systems (or system components) located in other segments / security zones.
SNow
Classification: ProtectState: Published
The manufacturing system should not utilize dual-homed devices (e.g. servers) to communicate with systems (or system components) located in other segments / security zones.
Update firmware to the most recent version once upgrade notification has been received.
SNow
Classification: PreventiveState: Published
Update firmware to the most recent version once upgrade notification has been received.
Use only secure communication protocols for remote system management.
SNow
Classification: PreventiveState: Published
Use only secure communication protocols for remote system management.
Use the latest version of all software.
SNow
Classification: PreventiveState: Published
Use the latest version of all software.
Verify only Wireless Local Area Network Network Interface Cards that turn off or disable Peer-To-Peer Wireless Local Area Network communications are used on the system.
SNow
Classification: DetectiveState: Published
Verify only Wireless Local Area Network Network Interface Cards that turn off or disable Peer-To-Peer Wireless Local Area Network communications are used on the system.
Graph Explorer