Servers Require More—and More Specific—Security

Servers Require More—and More Specific—Security
Published: Jan 8, 2013
Updated: Feb 2, 2021
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More


Servers Require More—and More Specific—Security

Servers Require More—and More Specific—Security

When it comes to securing these two types of systems, more broad-based policies and controls can be applied to laptops. However, servers require specific policies and controls based on the data, application functions or the environment in which it resides. Servers by nature are set at “default deny.” However, laptops maintain a “default allow” setting.


Servers Are Housed in Data Centers, Laptops Are Everywhere

2

Since servers connect to a multitude of computers, they are exposed to more threats than laptops. Servers present higher-value targets, whereas laptops (which connect to a single endpoint) present a somewhat lower value target. Thus, IT managers should implement reputation-based techniques to identify malware and mitigate risk.


Different Usage Means Different Security Schemes

3

Because they have a standard operating system and applications, most laptops behave the same. Servers, on the other hand, have a diverse set of business functions as well as different workloads. A server generally performs singular tasks for many purposes, and its value to an organization is higher than a single laptop that performs multiple tasks for one person in an organization. Thus, a laptop maintains lower value. Servers require log monitoring to enable organizations to meet compliance requirements; laptops do not. Be sure that the security system you select can be protective in these areas.

Advertisement


Consider Deploying Multiple Layers of Security

4

For laptops, in particular, consider implementing reputation-based techniques to identify malware and mitigate risk. If possible, also use Web gateways armed with malware-detection capabilities to prevent socially engineered attacks. Virtual private networks are sometimes difficult to handle, but they generally do their jobs.


Use Data-Loss-Prevention Tools

5

For both servers and enterprise laptops, users should consider deploying data-loss-prevention tools to identify and protect sensitive data. Otherwise, how would a security admin or data center manager know what’s going out the virtual door?


Keep All Software and Security Patches Up-to-Date

6

Ensure the laptop operating system and software is up-to-date with the most current security patches. Laptop users also should deploy a comprehensive endpoint security solution suite to protect themselves against the constantly evolving threat landscape. Secure your systems between patch cycles.


Obviously, Fewer Users Means Tighter Security

7

Access control for both servers and laptops, especially servers, should adhere to the principle of least privilege. File-integrity monitoring should be enabled for unauthorized modifications.


Monitor, Monitor, Monitor

8

Constant monitoring is always a key best practice for servers, but one might be surprised at how often it’s not followed regularly. Monitor your logs to enable compliance, suspicious activities and access patterns. Be careful with and monitor your server configuration.


Advertisement

Watch and Limit Network Traffic

9

Have access controls in place to limit network traffic, both inbound and outbound. Make sure irrelevant traffic (music downloading, game-playing and so on) isn’t happening under any circumstance.


Keep Up With the Latest Security Products

10

Hackers and security providers are constantly playing cat-and-mouse. But the hackers generally stay ahead of the game. Keep in the loop on trends, new products and use cases by checking in regularly with key vendors, analysts and publications such as eWEEK to find information relevant to your system.

Chris Preimesberger

Chris J. Preimesberger is Editor Emeritus of eWEEK. In his 16 years and more than 5,000 articles at eWEEK, he distinguished himself in reporting and analysis of the business use of new-gen IT in a variety of sectors, including cloud computing, data center systems, storage, edge systems, security and others. In February 2017 and September 2018, Chris was named among the 250 most influential business journalists in the world (https://richtopia.com/inspirational-people/top-250-business-journalists/) by Richtopia, a UK research firm that used analytics to compile the ranking. He has won several national and regional awards for his work, including a 2011 Folio Award for a profile (https://www.eweek.com/cloud/marc-benioff-trend-seer-and-business-socialist/) of Salesforce founder/CEO Marc Benioff--the only time he has entered the competition. Previously, Chris was a founding editor of both IT Manager's Journal and DevX.com and was managing editor of Software Development magazine. He has been a stringer for the Associated Press since 1983 and resides in Silicon Valley.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.