A robust infrastructure audit requires inspecting every layer, from domain name configuration to the isolation of hypervisors and containers.
Identity and Access Management (IAM)
- Strong authentication: Verify the mandatory deployment of MFA (ideally via FIDO2/YubiKey hardware keys) for all administrator access, VPN and cloud services.
- Key management: Audit the usage, encryption type, and rotation of SSH keys for Linux server administration.
- Principle of least privilege: Control that each service, application and user account has only the rights strictly necessary for its function (no generic account).
Network Scope and Connectivity
- Segmentation (VLAN): Verify the logical isolation of the network (strict separation of management, production, guest and IoT flows on UniFi type switches and access points).
- DNS and Messaging Security: Control strict configuration of SPF, DKIM and DMARC records (via zone managers like Cloudflare) to prevent domain spoofing.
- Firewall Rules: Validate the application of the default deny principleforboth inbound and outbound traffic, and audit the exposure of each port redirection rule.
Servers, Hypervisors and Containerization
- Hardening virtualization: Verify that the hypervisor management interface (e.g., Proxmox VE) is only accessible from a physically or logically restricted administration VLAN.
- Container security: Control isolated environments (e.g., Docker) to ensure that no container is running with
rootand that data volumes are properly isolated. - Maintaining Security Condition (MCS): Validate the presence of automated security update processes (e.g.,
unattended upgradeson Ubuntu) and vulnerability (CVE) monitoring.
Data and Endpoint Protection
- Encryption at rest: Verify that sensitive data storage disks and mobile workstations are encrypted (BitLocker, LUKS).
- Backup resilience: Audit the backup chain to confirm the existence of immutable copies, tested by regular restores, and disconnected from the main network.
- Active protection: Confirm the deployment of a modern security agent (EDR) on all servers and user workstations.
Supervision and Traceability (Logging)
- Centralization: Ensure that system, access, and authentication logs are sent to a remote syslog server and are write-protected.
- Alerts: Verify that critical events (repeated login failures, privilege escalation) trigger immediate notifications for administrators.