TWELVE SECURITY CONTROLS

A detailed map of the assessment.

CSAEC — The assessment examines twelve defined areas. Each result is a point-in-time indicator with a practical next step and an explicit limitation.

01

Windows Firewall Status

Reviews whether host firewall protection is active at a high level.

Why it matters

A disabled or unsuitable firewall can increase exposure to unsolicited connections and make unnecessary services easier to reach.

Practical next step

Enable and review Windows firewall protection under approved policy. Validate every exception before changing it.

Keep in mind

The check does not prove that every firewall rule is appropriate.

02

Disk Encryption Status

Checks available indicators of data-at-rest protection.

Why it matters

Unencrypted storage can expose business data when a device is lost, stolen or accessed without authorisation.

Practical next step

Use organisation-approved disk encryption and protect recovery information securely.

Keep in mind

The check does not evaluate every key-management, recovery or escrow practice.

03

OS Security & Integrity

Reviews operating-system integrity and security configuration signals.

Why it matters

Weakened integrity controls can make unauthorised system changes more difficult to prevent, identify or investigate.

Practical next step

Apply supported security settings and investigate unexpected system changes with qualified personnel.

Keep in mind

Coverage depends on Windows edition, permissions and information exposed to the application.

04

Local Network Port Exposure

Identifies listening ports and potentially exposed services.

Why it matters

Unnecessary listening ports and reachable services increase the attack surface and can expose outdated or misconfigured components.

Practical next step

Confirm the business need for each service, restrict reachability and remove or reconfigure unnecessary exposure after impact review.

Keep in mind

Filtered or closed services and current network conditions can reduce visibility.

05

Local Network Device Discovery

Discovers visible devices to support asset awareness.

Why it matters

Unknown devices may indicate unmanaged assets, guest access, shadow IT or an incomplete inventory that requires review.

Practical next step

Compare discovered devices with an authorised inventory and investigate unexplained systems through the responsible network owner.

Keep in mind

Discovery is not a complete inventory; segmentation, filtering and sleeping devices can hide assets.

06

Automatic Screen Lock

Checks whether unattended access is limited by automatic locking.

Why it matters

An unattended unlocked workstation can permit access to email, files, applications and authenticated business sessions.

Practical next step

Set a suitable inactivity timeout and require authentication on return according to business policy.

Keep in mind

The check cannot measure user behaviour or every possible policy source.

07

Windows Update Configuration

Reviews whether security update mechanisms are enabled.

Why it matters

Delayed or failed security updates can leave known weaknesses unaddressed even when an update policy appears enabled.

Practical next step

Maintain a controlled update process, test business-critical changes and resolve persistent installation failures.

Keep in mind

Configuration does not prove that every security update installed successfully.

08

Antivirus / Endpoint Protection

Checks available indicators of active endpoint protection.

Why it matters

Missing, disabled or outdated endpoint protection can reduce the organisation’s ability to prevent, detect and respond to malicious activity.

Practical next step

Enable a supported protection platform, verify current updates and review alerts according to the incident process.

Keep in mind

CSAEC is not antivirus or EDR and cannot replace continuous endpoint monitoring.

09

Backup Configuration

Looks for indicators that a backup configuration exists.

Why it matters

Without complete, protected and restorable backups, recovery from ransomware, failure or accidental deletion may be slow or impossible.

Practical next step

Maintain isolated or otherwise protected backups and perform regular restoration tests with documented results.

Keep in mind

Configuration evidence does not prove completeness, integrity, isolation or restorability.

10

Wireless & Bluetooth Exposure

Reviews radio-interface exposure and discoverability.

Why it matters

Unused wireless interfaces or discoverable Bluetooth services can create unnecessary nearby opportunities for access or data exposure.

Practical next step

Disable unused radios and limit discoverability according to operational needs, travel policy and device ownership.

Keep in mind

Radio state and discoverability can change immediately after the assessment.

11

Known Vulnerability Assessment

Uses vulnerability-oriented checks, including Nmap where available.

Why it matters

Potentially vulnerable services may allow compromise, but version detection and vulnerability signatures always require validation.

Practical next step

Validate the affected product and version, assess exposure and impact, then use vendor-supported mitigation or updates.

Keep in mind

False positives and false negatives are possible, and a result is not proof of exploitability.

12

Local Web Service Assessment

Uses Wapiti where available against reachable local web services.

Why it matters

Weak locally reachable web services may expose data or application functions, but automated coverage is not equivalent to a full penetration test.

Practical next step

Validate the result within the authorised scope, then update, reconfigure, isolate or remove the affected service.

Keep in mind

Only reachable services are assessed; specialist manual testing may find additional weaknesses.

Controls are related, not isolated.

A workstation may have current antivirus protection but still expose an unnecessary network service. It may use disk encryption but lack tested backups. It may have a strong firewall while an employee session remains available on an unlocked screen. Security emerges from layers that support each other.

This is why CSAEC retains all twelve findings instead of presenting only a total. Improvement should focus on the weaknesses that create the greatest plausible harm for the particular system, users and business processes.

Prioritisation factors

  • Business importance of the workstation
  • Internet or local-network exposure
  • Sensitivity of accessible information
  • Likelihood and ease of exploitation
  • Existing compensating safeguards
  • Potential operational impact of remediation
  • Availability of tested recovery