Controls

Terug naar overzicht
Version

SB.16.006 Server and Application Infrastructure Not Shared

Medium
Medium
Medium
System Hardening
System Owner
v2.0 (Q1 2024)

IT services run in their own virtual environments, vulnerabilities in one service cannot give access to other services. This includes no multiple websites on the same webserver unless they share the same Security Capability Level and purpose, the same applies to databases between different services.

Specification

Every newly deployed server has a maximum of one role.

ISO 27001 & 27002:2022

A5.8,
A5.36,
A5.37

SURF toetsingskader informatiebeveiliging (NBA-volwassenheidsmodel)

SM.01 Security Baselines