Linux server hardening and security best practices
Updated 30 November 2024
Create a sudo user
Use Secure Shell Protocol
Setup a basic firewall
Disable Unwanted Linux Services
Disable ICMP
Enable SELinux
Install and configure fail2ban firewall
Keep Kernel and Packages Updated
Disable USB and Thunderbolt Devices
Enforce strong passwords policies
Restricting Use of Previous Passwords
Purge Unnecessary Packages to minimize vulnerabilities
Set Up Password Aging
Disable Unwanted SUID and SGID Binaries
Logging and Auditing
Perform regular backups
Restricting Use of Previous Passwords
Monitor Listening Network Ports
Separate Disk Partitions For Linux System
Spotted a mistake or want something added? Send me a note.