Assessment and Audit

Build and Maintain a Secure Network and Systems

  1. Install and maintain a firewall configuration to protect data.

  2. Do not use vendor-supplied defaults for system passwords and other security parameters.

Maintain a Vulnerability Management Program

  1. Protect all systems against malware and regularly update anti-virus software or programs.

  2. Develop and maintain secure systems and applications.

Implement Strong Access Control Measures
  • Identify and authenticate access to system components.

Regularly Monitor and Test Networks

  1. Track and monitor all access to network resources.

  2. Regularly test security systems and processes.

Maintain an Information Security Policy
  • Maintain a policy that addresses information security for all personnel.