Endpoint security architecture covers the built-in technologies, configuration practices, protective software, and maintenance procedures that keep networked devices secure. Central to this process is hardening — a structured set of steps applied to each device to reduce vulnerabilities before and after deployment.
Endpoint Security Overview
When we're architecting security for our endpoints, we need to think about that big picture, the big picture of security around those endpoints.
When it comes to security, here are some of the devices that we're going to want to make sure remain secure on our network, and here's some of the different aspects that I think about when securing these endpoints.
There's some built-in technologies that we may or may not have to do anything about, that is, they could come preconfigured or pre-installed, or the technology is part of whatever it is that we're implementing. So there are some built-in features that allow us to do some security.
Then how we configure those devices makes a big difference on how secure those devices are. Of course, there's some things that we are going to want to do to protect those systems, like software to be installed on them. There's also some maintenance and monitoring that we're going to want to do to make sure that they maintain a certain level of security. Although this maintenance and this monitoring, I cover that more in depth in a whole other course, so we're not going to hit those as heavily, but we're really going to focus on the built-in technologies and how to configure and protect these different end devices.
Here are some examples of each one of these categories:
So we want to make sure that these bases are all covered.
One way we do that is through a hardening process. A hardening process is these steps that we go through in order to make sure a machine is protected. Let's say we receive a laptop. We've ordered a laptop and we receive that laptop. Now we're going to want to go through a process to deploy that laptop. We're going to go through a hardening process to make sure that that laptop is more secure, that it's hardened against certain threats that are out there.
One of the reasons why this is necessary is because machines often come to us outdated or not set up for proper security. A good example of that is when you receive a new switch. They want it to work for you. They don't want you to plug it in and have to do a bunch of extra stuff and then think that, oh well, it's broken and so I'm going to send it back. So instead, it comes in working order, and it's not the most secure. So we go through this hardening process to start locking things down to make it more secure.
For each one of our devices, there's going to be a separate process, or separate steps, that we're going to do to harden those devices. For instance, a certain piece of hardware like a router: we would want to go through certain steps to harden a router. Even more specifically, if it's a Cisco router, there's probably more specific steps that we would use to harden a Cisco router. And then if it is a specific type of router from Cisco, there's probably even a paper out there on what we need to do to harden that device. So depending on what the manufacturer is, and what product it is, and what specific model it is, there are steps that we want to go through to harden those devices.
For the most part, we're going to be talking about hardening as general rules, general processes that we would follow that would apply to a lot of these devices, if not all of those devices.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →