NS-8 Detect and disable insecure services and protocols
Detect insecure services and protocols at operating system, application and package layers and disable them, applying compensating controls where they cannot be disabled.
4
artefacts
2
held by a system
1
at each review
easy
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Scan results listing insecure services and protocols detected · Vulnerability scanner / patch tooling
- Re-scan evidence confirming remediation · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
- Disablement records or hardening baseline entries · Cloud console / configuration management
governing documentDocuments that govern the control
- Compensating control register for exceptions with expiry dates · Policy repository / GRC workspace
First move
Automate the pull from your Vulnerability scanner / patch tooling. Scan schedule, findings and remediation age straight from the scanner; patch compliance from the patch console.
Common gaps auditors find
- legacy protocols left enabled for one dependency and forgotten
- exceptions granted with no expiry
- scanning limited to the network layer, missing application and package layers
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetNS-7 Simplify network security configuration · NS-9 Connect on-premises or cloud network privately