top of page

What is the importance of configuration reviews and how can one practice configuration reviews ?

Configuration review is an activity where the current configuration of a component i.e server, firewall, database etc is compared against an industry standard benchmark for example CIS benchmark. 

Industry standard benchmarks help organisations in achieving a good security posture by configuring the given component as per the configurations mentioned in the benchmark. Making these configurations in the given components can help in prevention of certain vulnerabilities that arise due to misconfigurations such as directory listing, default credentials etc. 

One can practice configuration reviews by installing an open source server like NGINX and then downloading the CIS benchmark for the given NGINX version and then comparing the configurations against it. 


0 views

Recent Posts

See All

How to install and configure Burpsuite?

For download, visit this link and choose your Operating system: https://portswigger.net/burp/releases/professional-community-2022-8-1?req...

bottom of page