Specify measurable security requirements for servers, clients, mobile, IoT, embedded, OT, and ICS assets while respecting operational and safety constraints.
Segment endpoint classes
Servers, user devices, mobile devices, IoT, and operational technology have different owners, lifecycles, and failure consequences. Define asset classes and a minimum baseline for each rather than forcing one control set onto every device.
Write requirements that can be verified
Baseline requirements can include supported operating systems, secure boot, encryption, endpoint detection, host firewalls, application control, vulnerability and patch processes, configuration management, local privilege restrictions, logging, and isolation procedures.
Control local administration
Windows Local Administrator Password Solution manages unique, rotated local administrator passwords and can store them in Active Directory or Microsoft Entra ID according to the chosen design. Limit who can retrieve passwords and monitor retrieval and reset activity.
Respect OT and ICS constraints
Safety, availability, vendor support, and long replacement cycles can limit agents and patching. Use passive discovery, network segmentation, controlled remote access, allowlisting, secure engineering workstations, and tested maintenance windows. Microsoft Defender for IoT can provide monitoring for supported environments.
Plan for containment
Every endpoint class needs a safe isolation and recovery path. For OT, an automatic containment action that interrupts a physical process may create more harm than the cyber event, so define human decision authority in advance.