• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Security Architecture

MIS 5214 - Section 001 - David Lanter

Security Architecture

MIS 5214.001 ■ Spring 2024 ■ David Lanter
  • Homepage
  • Instructor
  • Syllabus
  • Deliverables
    • Assignments
    • Case Studies
      • Case Study 1 – A High Performance Computing Cluster Under Attack: The Titan Incident
      • Case Study 2 – Data Breach at Equifax
    • Participation
    • Team Project
  • Harvard Coursepack

NIST 800-123 Guide to General Server Security

March 13, 2024 by David Lanter 16 Comments

Filed Under: 09 - Host Hardening Tagged With:

Reader Interactions

Comments

  1. Jon Stillwagon says

    March 16, 2024 at 2:20 pm

    In the NIST SP 800 -123 for securing the server software after it has been installed and eliminated any known vulnerabilities through its patches/ upgrades. It needs to configure the access controls and with the proper setting of access controls helps prevent disclosure of sensitive or restricted information. Access controls can enforce the segregation of duties so people can’t harm the company in any way and in this case it will ensure that the server logs cannot be modified by server administrators. With servers they can support a range of technologies that can identify and authenticate users for accessing information. Even encryption of the servers can help by not just letting anyone on to the network traffic that can possibly alter the content of sensitive information.

    Log in to Reply
    • Eyup Aslanbay says

      March 19, 2024 at 10:52 pm

      NIST SP 800-123 regarding server software security is spot-on! You’ve captured the essence of configuring access controls and their role in safeguarding sensitive information, along with the importance of user authentication and encryption in maintaining network integrity.

      Log in to Reply
  2. Ooreofeoluwa Koyejo says

    March 17, 2024 at 12:55 am

    Some management practices critical to operating and maintaining a secure server and the supporting network infrastructure include:
    1. Organizational Information System Security Policy
    2. Configuration/Change Control and Management
    3. Risk Assessment and Management
    4. Standardized Configurations
    5. Secure Programming Practices
    6. Security Awareness and Training
    7. Contingency, Continuity of Operations, and Disaster Recovery Planning
    8. Certification and Accreditation

    Log in to Reply
  3. Yannick Rugamba says

    March 17, 2024 at 5:27 pm

    The NIST 800 123 guide highlights the importance of planning. Prioritizing security measures right, from the start when setting up a new server. It suggests creating a deployment strategy that takes into account the servers intended use, services, user accounts, authentication requirements, physical placement, management protocols staffing needs and various other aspects. Adequate planning in advance can play a role in ensuring that servers are configured correctly and in alignment with the organizations security guidelines, before being put into operation.

    Log in to Reply
    • Celinemary Turner says

      March 18, 2024 at 9:09 pm

      That’s very correct, Yannick. Organizations can ensure that their servers are configured correctly and aligned with security guidelines before deployment by prioritizing security measures from the start and creating a comprehensive deployment strategy.

      Log in to Reply
    • Edge Kroll says

      March 19, 2024 at 11:28 pm

      Hi Yannick,

      I completely agree by prioritizing security measures from the outset when setting up a new server, organizations can mitigate potential risks and ensure that their systems are configured in accordance with security guidelines.

      Log in to Reply
    • Ooreofeoluwa Koyejo says

      March 20, 2024 at 12:10 am

      With the availability of these documents, security professionals can improve their competencies and strengthen the protection measures implemented in their organisations from the recommendations in the documents. They can also align the guidelines with the risk appetite level of the organisation.

      Log in to Reply
  4. Edge Kroll says

    March 17, 2024 at 7:26 pm

    NIST Special Publication 800-123 offers guidance on securing cloud computing environments, addressing various aspects including security considerations, recommendations for safeguarding cloud-based applications and data, risk management strategies, and compliance requirements. It delves into authentication, authorization, encryption, data integrity, and incident response, providing detailed insights to help organizations enhance the security of their cloud-based systems. The publication serves as a valuable resource for organizations looking to leverage cloud computing while maintaining robust security measures to protect their sensitive information and assets.

    Log in to Reply
    • Bo Wang says

      March 19, 2024 at 9:00 pm

      I agree with you that this publication is a valuable resource for organizations that need it, and nist 800-123 is essential for companies at a time when cloud computing services are increasingly valued and popular.

      Log in to Reply
    • Ooreofeoluwa Koyejo says

      March 20, 2024 at 12:08 am

      With the wide adoption of cloud services in organisations and government services due to the lessons from the pandemic, it has become inevitable for organisations to strength their cloud services for the protection of information and assured security objectives of availability, integrity and confidentiality through secure practices.

      Log in to Reply
  5. Eyup Aslanbay says

    March 17, 2024 at 7:48 pm

    The NIST 800-123 Guide to General Server Security aims to assist organizations in securing their main servers. Safeguarding the operating system involves applying patches, setting up robust authentication, and enhancing the host. The release of a new patch indicates increased vulnerability for older systems, emphasizing the need for administrators to promptly apply updates. Effective server maintenance involves consistent backups, audit log management, and frequent testing of server security.

    Log in to Reply
    • Celinemary Turner says

      March 18, 2024 at 9:03 pm

      Yes, Eyup, you accurately summarize the main focus areas of the NIST 800-123 Guide to General Server Security by implementing the measures mentioned, such as applying patches to address vulnerabilities and
      setting up robust authentication to restrict access.
      Organizations can effectively safeguard their central server.

      Log in to Reply
  6. Celinemary Turner says

    March 17, 2024 at 8:44 pm

    The NIST SP 800-123 Guide to General Server Security contains NIST recommendations on securing your servers. It offers general advice and guidelines on how you should approach this mission. Regulations such as HIPAA, HITRUST, CMMC, and others rely on those recommendations, demanding organizations enforce and comply with the guide.

    Log in to Reply
    • Yannick Rugamba says

      March 18, 2024 at 8:00 pm

      Good point on regulatory alignment. To add briefly – the guide also stresses ongoing security maintenance activities like log monitoring, regular backups, patching, and periodic security testing. Proactive planning is critical, but sustained processes are key too.

      Log in to Reply
  7. Bo Wang says

    March 17, 2024 at 9:38 pm

    NIST SP 800-123 mention that the secure installation and configuration of server applications should align with the principles applied to operating systems. This involves installing only necessary services and eliminating vulnerabilities through patches or upgrades. Any unnecessary applications, services, or scripts should be promptly removed post-installation. Securing server applications typically involves patching and upgrading, removing unnecessary components, configuring user authentication and access controls, setting up resource controls, and testing the security of the server application and content.

    Log in to Reply
    • Celinemary Turner says

      March 18, 2024 at 8:51 pm

      The Key security practices mentioned in NIST 123 include Installing only necessary services and eliminating vulnerabilities through patches or upgrades. These practices minimize the attack surface, reduce potential vulnerabilities, and ensure the server application is securely configured and maintained.

      Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • 01 – Introduction (1)
  • 01 – Threat Environment (3)
  • 02 – System Security Plan (6)
  • 03 – Planning and Policy (7)
  • 04 – Cryptography (4)
  • 05 – Secure Networks (7)
  • 06 – Firewalls (5)
  • 08 – Access Control (7)
  • 09 – Host Hardening (5)
  • 10 – Application Security (6)
  • 11 – Data Protection (4)
  • 12 – Incident and Disaster Response (5)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in