Skip to main content

5.5 Workstations & Endpoints


5.5 Workstations & Endpoints

  • Configuration Standards:

    • a. Disable Windows Management Instrumentation (WMI), PowerShell, and Secure Shell (SSH) on workstations. SSH may be temporarily enabled by a DTC technician for troubleshooting and disabled upon task completion.

    • b. Disable PowerShell Remoting on servers.

    • c. Enable SSH on servers for secure remote management.

  • Security Agents:

    • d. Deploy Managed Detection and Response (MDR) or Endpoint Detection and Response (EDR) agents.

    • e. Install VPN clients where applicable.

    • f. Deploy DNS content filtering agents on laptops.

  • User Lockout Policy:

    • g. Trigger a 5-minute lockout period after 10 failed login attempts.

  • Screen Lock Policy:

    • h. Activate screen lock after 12 hours of inactivity.

  • Software Maintenance:

    • i. Deploy operating system patches according to the [Patch Schedule Link].

    • j. Install drivers as per the [Driver Schedule Link].

    • k. Deploy essential third-party applications following the [Essential Apps Schedule Link].

    • l. Install Line of Business (LOB) applications according to the [LOB Apps Schedule Link].

Technical Controls:

Control ID Description Tools/Methods
a Disable WMI, PowerShell, and SSH on workstations; enable SSH temporarily for troubleshooting. GroupDTC's PolicyRMM, ObjectsMicrosoft (GPO);Windows ConfigurationPowerShell, Management Tools; Manual enable/disable procedures.SOP
b Disable PowerShell Remoting on servers. GPO;DTC's PowerShell scripts; Configuration Management Tools.RMM
c Enable SSH on servers for secure remote management. SSHDTC's server configuration; GPO; Configuration Management Tools.RMM
d Deploy MDR/EDR agents on endpoints. MDR/EDRDTC's solutionsRMM, (e.g.,Blackpoint MicrosoftSNAP Defender for Endpoint, CrowdStrike); Deployment scripts.Agent
e Install VPN clients where applicable. VPNDTC's solutionsRMM, (e.g.,Cloudflare CiscoWARP, AnyConnect, OpenVPN); Deployment scripts; Configuration policies.ZeroTier
f Deploy DNS content filtering agents on laptops. DNSDTC's filteringRMM, solutionsDNSFilter (e.g.,Roaming Cisco Umbrella, OpenDNS); Deployment scripts; Configuration policies.Agent
g Implement a 5-minute lockout after 10 failed login attempts. AccountDTC's lockout policies configured via GPO; Security baseline policies.RMM
h Activate screen lock after 12 hours of inactivity. ScreenDTC's saver timeout policies configured via GPO; Configuration Management Tools.RMM
i Deploy operating system patches as per schedule. WindowsDTC's ServerRMM, Update Services (WSUS); Patch management tools (e.g., SCCM); Automated deployment scripts.SOP
j Install drivers according to the deployment schedule. DriverDTC's managementRMM, tools; Deployment scripts; Configuration Management Tools.SOP
k Deploy essential third-party applications per schedule. SoftwareDTC's deploymentRMM, tools (e.g., SCCM, Intune); Deployment scripts; Application catalogs.SOP
l Install Line of Business (LOB) applications as scheduled. SoftwareDTC's deploymentRMM, tools; Deployment scripts; Configuration Management Tools.SOP