1. Administrators must work in browsers in in-private mode
2. Administrators are prohibited from saving passwords in browsers
3. Administrators are prohibited from saving files with password lists on their computers or shared resources, as well as sending them by e-mail
4. All users are forbidden to open suspicious mail, punish with money. Allocate for this one computer without connection to the corporate network
5. Administrators work in virtual machines. Virtual machines must be in cryptocontainers
6. Configure firewalls so that administrator's computers do not have direct access to critical servers, but virtual machines have it (firewall rules and network ranges)
7. Limit the list of domain administrators. Split domain administrator password between security department and administration department (password is very long)
8. Delegate small roles to administrators for daily work (resetting passwords, creating users)
9. Use strong antivirus, Cylaence or Сarbon Black or Cortex (we do not advertise antivirus, think byr yourself)
10. Limit access to the Internet on servers and admin's computers. Create a terminal server in the DMZ and use the terminal browser applications
11. All suspicious letters with links should be sent to the IT department for verification on a stand alone virtual machine.
12. Configure mail filters to work with white lists. Anything that is not included in the whitelist must be moderated.
13. Prevent users from launching scripting programming languages (vbs, js and others) and unknown file extensions. If you doubt about openning link, transfer it to the IT department for verification on a stand alone virtual machine.
14. Open documents with macros only from trusted users. If you doubt about openning document, transfer it to the IT department for verification on a stand alone virtual machine.
15. If the user has launched a suspicious file, he should immediately contact the IT department.
16. Disable remote launch for powershell
17. Set 2FA Authorisation for network infrustructure. (Backups)
2 days ago