Skip to main content

Pro audit program · v1.0

Workstation Hardening Quick Check

Are your laptops actually hardened — disk encryption, local admin, screen lock, USB control?

  • General target area
  • CIS Benchmarks framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Are your laptops actually hardened — disk encryption, local admin, screen lock, USB control?

Risks addressed

  • High Lost / stolen laptop exposes unencrypted data
  • High User running with local admin all day
  • Medium USB-based malware on workstations

Controls (7)

  1. Full-disk encryption on every workstation

    Critical

    Full-disk encryption on every workstation

    How to test + evidence

    Testing procedure: BitLocker / FileVault / LUKS — 100% coverage tracked in MDM / RMM.

    Evidence to collect: Encryption status report.

  2. No standing local administrator rights

    High

    No standing local administrator rights

    How to test + evidence

    Testing procedure: Users are non-admin by default; elevation via LAPS / Privilege Manager / sudo.

    Evidence to collect: Group membership audit.

  3. Screen lock + idle timeout

    Medium

    Screen lock + idle timeout

    How to test + evidence

    Testing procedure: 15-min idle lock enforced via GPO / MDM.

    Evidence to collect: Policy export.

  4. Application allowlisting where feasible

    High

    Application allowlisting where feasible

    How to test + evidence

    Testing procedure: AppLocker / WDAC / Gatekeeper for high-risk roles.

    Evidence to collect: Policy export.

  5. USB / removable media policy

    Medium

    USB / removable media policy

    How to test + evidence

    Testing procedure: USB mass storage blocked by default or routed through DLP scanning.

    Evidence to collect: Endpoint policy.

  6. Personal firewall on by default

    Medium

    Personal firewall on by default

    How to test + evidence

    Testing procedure: Host firewall enforced via policy.

    Evidence to collect: Policy export.

  7. Local browser config managed (cookies, downloads)

    Low

    Local browser config managed (cookies, downloads)

    How to test + evidence

    Testing procedure: Browser policy template applied via GPO / MDM.

    Evidence to collect: Policy export.