02 — Capability · BC-760.40
Infrastructure & Endpoint Protection
Reduce the attack surface of servers, networks, cloud environments and devices by finding weaknesses, closing them on a schedule and hardening what remains.
- Vulnerability Management
- Endpoint Security
- Network Security
In scope
- Vulnerability scanning and remediation tracking
- Endpoint protection and device hardening
- Network security controls and segmentation policy
- Cloud security posture management
Out of scope
- Operating the networks and servers themselves (see BC-730)
- Device provisioning and support (see BC-780)
Realized by · 3
Used in · 0
- Not yet placed on a value stream.
Build it · 4
- pattern Zero Trust via BC-760.40.30
- pattern Service Mesh via BC-760.40.30
- book Building Secure and Reliable Systems
- book Zero Trust Networks
Decomposes into · 4
- BC-760.40.10Vulnerability ManagementScan continuously, prioritize by exploitability and exposure, and hold owners to remediation deadlines that match the severity.
- BC-760.40.20Endpoint ProtectionKeep laptops, servers and mobile devices defended with current protection, hardened configuration and the ability to isolate one in seconds.
- BC-760.40.30Network Security ControlsDefine and enforce firewall policy, segmentation and remote access controls so a breach in one zone stays in that zone.
- BC-760.40.40Cloud Security PostureCheck cloud configurations against the secure baseline continuously and correct the misconfigurations that expose data or services.