Terminology Index
Glossary
2953 terms
Default Configurations
The out-of-the-box settings software and systems ship with, which prioritize ease of setup over security and often leave unnecessary features, default accounts, and permissive options enabled. Replacing them is a first step in hardening.
Vendors ship defaults that favor getting working quickly, default passwords, open services, verbose features, sample content, which are predictable and widely known, making them easy attacker targets. Hardening replaces these with deliberately chosen secure settings drawn from baselines and benchmarks. Recognizing that defaults are insecure by design is foundational to system hardening and attack surface reduction.
Introduced in: System Hardening Fundamentals
Examples
- A device shipping with a well-known default administrator password.
- A server enabling sample apps and extra services by default.
- Replacing permissive defaults with a hardened configuration baseline.
Related
