Securing and Hardening Your On-premises IT Environment — SCCM Security Implementation
IT Partner helps organizations improve the security of their existing on-premises IT environment by analyzing infrastructure and applying security best practices to systems, devices, administrative access, endpoints, storage, operating systems, firewall and network settings, and update policies. This is an SCCM Implementation service, SKU ITPWW150IMPOT, priced at $90 per hour, with a duration of 1 week and Mike Mackey as manager.
What this engagement is
This service focuses on making your on-premises IT infrastructure safer and more secure using the systems, devices, and technologies you already use. IT Partner analyzes the environment, helps apply security best practices, verifies the changes, and provides a project closeout report. Security requirements can vary for different types of workloads. Service details: SKU ITPWW150IMPOT; price $90 per hour; duration 1 week; manager Mike Mackey; product taxonomy SCCM; service type Implementation; date 2018-07-30.
Success criteria
What you receive
How the work unfolds
Start the project with a kickoff meeting.
Perform an on-premises health check.
Begin the securing process.
Verify the changes made during the securing process.
Finalize the changes.
Complete post-assessment tasks, if any.
Prerequisites
Who does what
IT Partner
- Analyze IT infrastructure
- Use Privileged Access Workstations
- Use Multi-Factor Authentication
- Limit and constrain administrative access
- Control and limit endpoint access
- Encrypt virtual disks and disk storage
- Manage operating systems
- Firewall and network settings
- Update policy and software review
Your team
- Provide a dedicated point of contact responsible for working with IT Partner and coordinate any outside vendor resources and schedules
- Configure all networking equipment, such as load balancers, routers, firewalls, and switches
- Provide access to physical and virtual servers and/or systems and services, as needed. Provide remote and/or physical access to facility and systems required to complete work.
What's not included
Limitations & technical notes
Frequently asked questions
What is included in IT Partner’s Securing and Hardening Your On-premises IT Environment service?
IT Partner’s Securing and Hardening Your On-premises IT Environment service includes analysis of your on-premises IT infrastructure and application of security best practices to systems, devices, administrative access, endpoints, storage, operating systems, firewall and network settings, and update policies. The engagement also includes verification of changes and a project closeout report documenting final status, evidence of meeting acceptance criteria, outstanding issues, and final budget.
What is the main outcome of this on-premises security hardening service?
The main outcome is a more secure on-premises environment in accordance with best practices. IT Partner achieves this by reviewing the existing infrastructure, applying agreed security improvements, verifying the changes, and documenting the final project status.
How long does the Securing and Hardening Your On-premises IT Environment engagement take?
The stated duration for IT Partner’s Securing and Hardening Your On-premises IT Environment service is 1 week. The actual plan may vary depending on your needs, so any environment-specific scheduling details should be confirmed with IT Partner during scoping or kickoff.
How is this service priced?
IT Partner’s Securing and Hardening Your On-premises IT Environment service is priced at $90 per hour. The service SKU is ITPWW150IMPOT, and the listed service duration is 1 week.
What happens during the engagement?
The engagement starts with a kickoff meeting, followed by an on-premises health check, the start of the securing process, verification of changes, finalization of changes, and any post-assessment tasks. This sequence helps IT Partner understand the current environment, apply hardening measures, and confirm the work before closeout.
What security areas does IT Partner review or harden?
IT Partner reviews and hardens areas such as administrative access, endpoint access, virtual disks and disk storage, operating systems, firewall and network settings, and update policies. The service also includes practices such as using Privileged Access Workstations, using Multi-Factor Authentication, and limiting or constraining administrative access where appropriate.
Does this service include migration or deployment work?
No, migration and deployment are specifically not included in this service. The engagement is focused on securing and hardening the existing on-premises IT environment rather than moving workloads or deploying new infrastructure.
What are the customer prerequisites for this service?
The customer must provide a dedicated point of contact to work with IT Partner and coordinate any outside vendor resources and schedules. The customer is also responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches, and for providing remote and/or physical access to required facilities, servers, systems, and services.
What is IT Partner responsible for during the hardening engagement?
IT Partner is responsible for analyzing the IT infrastructure and applying security best practices across areas such as privileged access, MFA, administrative access constraints, endpoint access, storage encryption, operating system management, firewall and network settings, and update policy and software review. IT Partner also verifies changes and provides a project closeout report.
What is the client responsible for during the hardening engagement?
The client is responsible for assigning a dedicated point of contact, coordinating any outside vendors, configuring required networking equipment, and providing access to physical and virtual servers, systems, services, and facilities. These responsibilities matter because IT Partner needs timely access and coordination to complete the hardening work within the planned engagement.
Will this service cause downtime or business disruption?
The service description does not specify whether downtime is required. Because security changes to firewalls, operating systems, endpoint access, administrative access, storage, or update policies can affect operations, downtime expectations and maintenance windows should be confirmed with IT Partner during kickoff and planning.
Does IT Partner configure firewalls, routers, switches, and other network equipment?
The client is responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches. IT Partner’s scope includes firewall and network settings as part of the security hardening review, but any exact division of hands-on configuration work should be confirmed with IT Partner before the engagement begins.
Does the service include Multi-Factor Authentication and Privileged Access Workstations?
Yes, the service scope includes using Multi-Factor Authentication and Privileged Access Workstations as part of security best practices. It also includes limiting and constraining administrative access to reduce risk in the on-premises environment.
Does this service address endpoint access and storage encryption?
Yes, IT Partner’s responsibilities include controlling and limiting endpoint access and encrypting virtual disks and disk storage. These activities are part of the broader hardening effort to improve the security posture of the existing on-premises environment.
Does IT Partner review update policies and installed software?
Yes, the service includes update policy and software review. IT Partner also addresses operating system management as part of the on-premises hardening effort.
What deliverables are provided at the end of the service?
The deliverables are a more secure on-premises environment in accordance with best practices and a project closeout report. The closeout report includes final project status, evidence of meeting acceptance criteria, any outstanding issues, and the final budget.
Are measurable acceptance criteria defined for this service?
The service states that the closeout report includes evidence of meeting acceptance criteria, but it does not define specific measurable acceptance criteria in the provided scope. Customers should confirm the exact acceptance criteria with IT Partner during kickoff or project planning.
Can the hardening plan vary by workload or environment?
Yes, the service notes that security requirements can vary for different types of workloads and that the plan may vary depending on customer needs. IT Partner’s recommendations should therefore be confirmed against the specific systems, workloads, and risks in the customer’s on-premises environment.
Is detailed documentation included with the service?
The included documentation is the project closeout report showing final project status, evidence of meeting acceptance criteria, outstanding issues, and final budget. More extensive documentation can be provided for an additional fee.
Who manages this service and what is its service classification?
The service manager listed for Securing and Hardening Your On-premises IT Environment is Mike Mackey. The service is classified under the SCCM product taxonomy as an Implementation service, with SKU ITPWW150IMPOT.