Document Information
Document Name |
System Hardening Procedure |
Document Reference No. |
RV_IT_SOP_260806_000001 |
Document Version No. |
1.0 |
Document Effective Date |
August 2026 |
Document Owner |
Rouse Legal Vietnam Limited |
Document Control
Name |
Role |
Position |
Date |
Nguyen The Hung |
Author |
IT Manager |
|
|
|
|
|
|
|
|
|
Revision History
Document Name: SOP – System Hardening Procedure
Document Type: Procedure
Review Date: 16/03/2026
Next Review Date: 31/03/2027
Version |
Reviewer |
Details of Change |
Date |
1.0 |
|
First release |
August 2026 |
|
Purpose
The purpose of this procedure is to establish a standardized framework for the secure configuration of all IT assets - including servers, endpoints devices (desktop and laptop computers), and network infrastructure. By implementing these hardening standards, the firm aims to minimize its attack surface, mitigate known vulnerabilities, and maintain compliance with ISO/IEC 27001:2022 and other relevant Vietnamese cybersecurity regulations.
Scope
This procedure applies to all information system owned or managed by Rouse Legal Vietnam Limited (the Company), including:
- Infrastructure: Physical and virtual servers and storage systems.
- Endpoints: Company desktops, laptops, and mobile devices.
- Network Perimeter: Firewalls, switches, wireless access points, and routers.
- Cloud Ecosystems: Managed endpoints and identities within Microsoft 365, and other cloud assets and systems.
- Compliance: All systems subject to legal, regulatory (e.g., Decree 13/2023/NĐ-CP), and contractual security obligations.
Definitions
- Hardening: The technical process of securing a system by removing unnecessary functional capabilities, closing unused ports, and disabling non-essential services to reduce the Attack Surface.
- Baseline Configuration: A documented, “Golden Standard” set of security settings and practices approved by IT Management that must be applied to every new system before it is deployed into production.
- Attack Surface: The sum of all points (the “reachability”) where an unauthorized user can attempt to enter data to or extract data from an environment.
- Vulnerability: A flaw or weakness in a system's design, implementation, or operation and management that could be exploited by threat(s) to violate the firm's security policy.
Roles and Responsibilities (RACI Model)
Activity |
IT Manager |
IT Security |
IT Operations |
Management |
Define Hardening Standards |
A |
R |
C |
I |
Approve Baseline |
A |
R |
C |
I |
Implement hardening controls and practices |
C |
C |
R |
I |
Validate configuration |
A |
R |
C |
I |
Monitor Compliance |
A |
R |
C |
I |
Review and Update Hardening Standards |
A |
R |
C |
I |
Report Compliance Status |
A |
R |
I |
A |
Legend:
R – Responsible: The role that executes the work/tasks.
A – Accountable: The role that owns the outcome and makes final decisions.
C – Consulted: Roles that provide input before decisions are made.
I – Informed: Roles that must be notified of outcomes.
Procedure
Establishment of Hardening Baselines
The IT Team shall define and document security baseline for all system components, based on:
- Principle of Least Functionality: Baselines must strictly disable all services, ports, and features not required for business operations.
- Industry Standards: Baselines will be modeled after CIS (Center for Internet Security) Benchmarks and vendor-specific hardening guides (e.g., Sophos, Microsoft, Cisco).
- Outputs: Every system type must have an approved Configuration Checklist that includes security parameters and version control.
Assets Inventory and Classification
An accurate and up-to-date inventory of all IT assets must be maintained, including:
- Mandatory Data: Asset ID, Owner, Location, Function, and OS/Firmware version.
- Criticality Ranking: Assets are classified as Critical, High, Medium, or Low based on data sensitivity and the business impact of downtime.
Implementation
Operating System Hardening
- Disable or remove all unnecessary ports, protocols, and services to reduce the system attack surface.
- Remove all unused, unauthorized, or unsupported software and applications.
- Enforce organizational password policies, including complexity, expiration, and reuse restrictions.
- Apply security patches and updates in accordance with the Patch Management Procedure.
- Configure and enable local host-based firewalls, if applicable.
- Implement network-level access control rules on firewalls and network devices to restrict unauthorized access.
- Restrict physical access to server environments (e.g., server rooms, data centers) to authorized personnel only.
Account and Access Management
- Enforce the principle of least privilege and need-to-know for all user and system accounts.
- Disable, remove, or rename default accounts to prevent unauthorized access.
- Enforce strong password requirements, including complexity and length.
- Configure account lockout policies to prevent brute-force attacks.
- Enable logging and monitoring of activities on user account (e.g., login attempts, privilege changes).
- Implement Multi-Factor Authentication (MFA) where applicable, especially for:
- Administrative accounts,
- Remote access,
- Cloud services (e.g., Microsoft 365).
Network Hardening
- Disable or restrict unused ports, protocols, and services on network devices.
- Restrict access to network device configurations to authorized administrators only.
- Enforce the use of secure communication protocols (e.g., SSH, HTTPS).
- Enable logging and monitoring on network devices.
- Disable insecure protocols (e.g., Telnet, FTP).
- Regularly upgrade firmware to supported and secured versions.
- Apply security patches and hotfixes in accordance with vendor recommendations.
Application Hardening
- Remove or change all default credentials prior to production use.
- Modify and secure default configurations according to organizational standards.
- Apply the latest security patches and updates.
- Disable unnecessary features, modules, or plugins.
- Implement input validation controls to prevent common attacks (e.g., injection).
- Enable application-level logging and monitoring.
Logging and Monitoring
- Enable system logging for:
- Authentication events (e.g., login success/failure),
- System events (e.g., startup, shutdown, errors),
- User activities and system behaviors, where applicable.
- Ensure logs are:
- Protected from unauthorized access or modification
- Retained in accordance with organizational data retention policies
- Forward logs to a centralized logging or monitoring system (e.g., SIEM), where available.
- Configure alerting mechanisms to detect and notify on:
- Suspicious activities (for example, data exfiltration)
- Unauthorized access attempts
- System anomalies (spike in resource usage).
Configuration Validation
All system configurations must be validated against the approved security hardening baselines to ensure compliance and consistency.
Validation activities should include:
- Configuration reviews using standardized checklists,
- Use of automated compliance and configuration assessment tools, where applicable.
Perform regular vulnerability scanning to identify:
- Misconfigurations,
- Missing patches, updates and security hotfixes,
- Security weaknesses.
Periodically conduct configuration reviews to ensure systems remain aligned with:
- Approved baselines,
- Organizational policies and standards,
- Security best practices from Security Vendor.
Patch and Update Management
- All patches and update packages must be managed through lifecycle approach,
- Patches and updates must be tested in a controlled test environment prior to deployment in the production environment,
- IT Team shall monitor security forums for newly threats, vulnerabilities, risks and fixes.
- Critical security patches must be applied within a defined timeframe based on severity (for example, critical: ≤48 hours, high: ≤7 days).
- All patching activities must be documented and tracked, including:
- Patch identification, linked to CVE, if possible,
- Deployment date and time,
- Systems affected,
- Verification status,
- Failed or problematic updates must follow a rollback procedure and be escalated for further analysis.
Compliance and Exception Management
Configuration and security baselines must be regularly verified to ensure compliance with approved hardening standards, organizational policies, and applicable regulatory requirements.
Compliance verification shall be conducted through:
- Periodic configuration reviews,
- Automated compliance scanning tools (where available)
- Internal audits
Any deviations from defined baselines must be:
- Documented as non-compliance findings,
- Assessed for risk and impact,
- Remediated within defined timeframes.
Compliance status must be:
- Monitored continuously or at defined intervals
- Reported to IT Management and relevant stakeholders
Exceptions to baseline configurations must:
- Be formally documented,
- Include business justification and risk assessment,
- Be approved by authorized personnel,
- Be reviewed periodically.
Review and Continuous Improvement
System hardening baselines shall be reviewed periodically to ensure continued effectiveness and alignment with organizational security requirements.
Reviews must be conducted:
- At least annually, and
- After significant events, including:
- Major security incidents,
- Significant system or infrastructure changes,
- Introduction of new technologies.
Baselines shall be updated accordingly based on:
- Emerging threats and vulnerabilities,
- Security advisories and industry best practices,
- Internal and external audit findings,
- Lessons learned from incidents.
All updates to hardening baselines must be:
- Documented and version-controlled,
- Reviewed and approved by authorized personnel,
- Communicated to relevant stakeholders.
Documentation and Records
To ensure traceability and audit readiness for ISO 27001, all hardening activities must be documented and stored in a centralized and access-controlled repository (e.g., the IT Management folder on Rouse SharePoint).
Mandatory Records:
- Hardening Baseline Documents: Approved and version controlled of security configuration standards for systems and devices,
- System Configuration Records: Actual configurations applied to systems in production environment, and changes made over time, including timestamps and responsible personnel
- Configuration Validation Reports: Results of configuration reviews and compliance checks, vulnerability scan outputs and remediation status,
- Exception Records: Documented deviations from approved baselines, including business justification, risk assessment, approval, and expiry date.
Documentation Control Requirements:
All documents must be:
- Stored in a centralized and access-controlled repository (e.g., SharePoint and/or Worldox),
- Updated immediately following any significant infrastructure change,
- Be protected against unauthorized access or modification,
- Retained in accordance with company data retention policies.
Recommended Tools and Systems
The firm utilizes the following technologies to enforce and monitor these standards:
- Governance and Compliance: SharePoint (Compliance Register, Policies and Standard Operating Procedures).
- Policy Enforcement: Security Policy from Microsoft Intune and Azure AD, local Active Directory Group Policy Objects (GPOs) for Windows endpoints and servers, if applicable.
- Vulnerability Management: Nessus or OpenVAS for identifying misconfigurations (or other tools).
- Patch Deployment: Microsoft WSUS or Microsoft 365 Endpoint Configuration Manager – where applicable - for centralized update control.
Metrics
The effectiveness of this procedure is measured by the following metrics, reported to management quarterly:
- Compliance Rate: Percentage of systems fully aligned with the hardening baseline.
- Vulnerability Density: Number of high/critical vulnerabilities detected by system.
- Patch Velocity: Average time taken to remediate critical vulnerabilities (Target: ≤ 48 hours).
- Exception Ratio: Number of systems operating under an approved exception versus total systems.
Deliverables
- Approved Hardening Policy, Frameworks and Checklists.
- Securely configured (“Hardened”) systems in production.
- Quarterly Compliance and Audit Reports.
- And Managed Exception Log.
Review and Maintenance
This SOP must be reviewed annually or upon significant changes occur in:
- Major updates or modifications to the Company network, infrastructure, firewalls, or core technologies;
- Changes in applicable laws, regulations, or industry standards that may impact to system hardening requirements (e.g., new Vietnamese cybersecurity regulations or updates to ISO/IEC 27001);
- Introduction of new systems, platforms, or cloud services that fall within the scope of this procedure;
- Lessons learned from security incidents, internal audits reports, or vulnerability assessments.
- Any changes resulting from the review must be promptly incorporated into the SOP and other related documentation.
- The updated documents must be stored in the designated, access-controlled repository in accordance with documentation control requirements.
- Regular review and maintenance of this SOP ensure that system hardening practices remain effective, relevant, and aligned with both Company objectives and evolving security threats.