A robust infrastructure audit requires inspecting every layer, from domain name configuration to the isolation of hypervisors and containers.

Identity and Access Management (IAM)

  • Strong authentication: Verify the mandatory deployment of MFA (ideally via FIDO2/YubiKey hardware keys) for all administrator access, VPN and cloud services.
  • Key management: Audit the usage, encryption type, and rotation of SSH keys for Linux server administration.
  • Principle of least privilege: Control that each service, application and user account has only the rights strictly necessary for its function (no generic account).

Network Scope and Connectivity

  • Segmentation (VLAN): Verify the logical isolation of the network (strict separation of management, production, guest and IoT flows on UniFi type switches and access points).
  • DNS and Messaging Security: Control strict configuration of SPF, DKIM and DMARC records (via zone managers like Cloudflare) to prevent domain spoofing.
  • Firewall Rules: Validate the application of the default deny principleforboth inbound and outbound traffic, and audit the exposure of each port redirection rule.

Servers, Hypervisors and Containerization

  • Hardening virtualization: Verify that the hypervisor management interface (e.g., Proxmox VE) is only accessible from a physically or logically restricted administration VLAN.
  • Container security: Control isolated environments (e.g., Docker) to ensure that no container is running with root and that data volumes are properly isolated.
  • Maintaining Security Condition (MCS): Validate the presence of automated security update processes (e.g., unattended upgrades on Ubuntu) and vulnerability (CVE) monitoring.

Data and Endpoint Protection

  • Encryption at rest: Verify that sensitive data storage disks and mobile workstations are encrypted (BitLocker, LUKS).
  • Backup resilience: Audit the backup chain to confirm the existence of immutable copies, tested by regular restores, and disconnected from the main network.
  • Active protection: Confirm the deployment of a modern security agent (EDR) on all servers and user workstations.

Supervision and Traceability (Logging)

  • Centralization: Ensure that system, access, and authentication logs are sent to a remote syslog server and are write-protected.
  • Alerts: Verify that critical events (repeated login failures, privilege escalation) trigger immediate notifications for administrators.

Categories: