Security – the best way to harden Windows Server 2008 R2

Securitywindows-server-2008

I need to harden my windows 2008 r2 server for PCI.
What is the best way to do this? The server are behind a CISCO ASA and in the DB servers are in separate vlans. Now i need to know if there are any unnecessary services that i can disable to improve security. These servers are running IIS and .net applications.

Best Answer

Here are two great places to start hardening any server:

  1. Download and run the Windows Server 2008 R2 Best Practices Analyzer.
  2. For a very hard server, run through the DoD's STIGs for Windows Server. They look overwhelming at first, but will take you a long way towards compliance with many regulations. You should also note that some of the DoD's security recommendations are so tight that they can sometimes break apps. Be sure to test before you apply these registry or group policy settings to your machines.
Related Topic