[network security]How to establish a secure baseline using MSAT and SCM

Overview

Lab Observations/Information Gathered:

MSAT (Microsoft Security Assessment Tool) assesses network risks. For example, I collect this information to determine the risks

· the basic information about the enterprise

· the infrastructure security information

· Application security information

· operations security information

· People security

· Environment information

It shows the business risk profile and defense-in-depth report to see how the organization’s security can mitigate the threats.

It also can provide an executive summary for submitting to senior management.

Security Compliance Manager (SCM) allows for baseline comparisons.

Install Microsoft Security Assessment Tool and create a new profile.

Provide the basic information about the enterprise

Provide the infrastructure security information

Provide Application security information

Provide operations security information

People security

Environment information

Perimeter Defense information

Authentication information

Management and monitoring information

Deployment and use information (Application)

Application design information

Data storage & communications

Operation Environment

Security policy

Patch & update management

Back and Recovery (Operation)

Requirements & assessments

Conclusion

Security hardening is a crucial part of organizational security, and there are some assessment tools such as MSAT and SCM to evaluate the current security posture. Security engineers need to understand these tools to conduct security assessments to enhance the security level of organizations.

--

--

Cloud security engineer https://www.linkedin.com/in/takahiro-oda-881423197/

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store