Skip to main content

Security Standards

The security baseline for every DTC-managed client environment. Each line says what the standard is and what enforces it — almost all of it is converged by ninja-one-automation scripts running under the NinjaOne agent, so the standard is what the fleet actually runs, not an aspiration.

Principles

  • One EDR, one anti-malware engine, deployed by us. A second security agent on an endpoint fights the first — duplicated kernel filters, mutual quarantine, hours lost diagnosing it.
  • Converged, not configured once. Every control below has a configuration script that re-applies it on a schedule, and an inventory or condition that reports drift.
  • Alert on the gap. If a control cannot be applied (legacy BIOS, missing site key), the device reports it rather than silently going without.

Endpoint

ControlStandardEnforced by
EDR / MDRBlackpoint Cyber MDR on every managed endpoint and server. Unified Agent v3 is the current agent; legacy SNAP sites migrate to v3. Vendor-bundled endpoint security (CrowdStrike, Norton, McAfee, OEM add-ons) is removed from the purchase quote, never just left uninstalled.security/blackpoint/configuration/blackpoint-agent-v3-provision.ps1; inventory blackpoint-snapagent-inventory.ps1 (reports v3 and outdated agents)
Anti-malwareMicrosoft Defender Antivirus, real-time protection always on, per-client exclusions applied. Core Isolation (HVCI) disabled by default for application performance, without disabling Hyper-V/VBS; re-enable per device via defenderDisableCoreIsolation.security/defender/configuration/defender-provision.ps1, security/defender/inventory/defender-inventory.ps1
Disk encryptionBitLocker on OS drives: TPM + 48-digit recovery password, XtsAes256, recovery password escrowed to AD and/or Entra ID before encryption begins. Suspended, unprotected, or keyless volumes alert.security/bitlocker/*
Secure BootOn wherever the firmware supports it. A UEFI machine with Secure Boot off alerts; legacy-BIOS machines are reported, not alerted (fixing them needs a reimage). 2026 certificate-rollover readiness is inventoried.endpoint/oem/configuration/oem-firmware-configure.ps1, security/secure-boot/*
Application controlAppLocker blocks executables launched from user download locations — audit first, then enforce, per client.security/applocker/*
Unapproved remote toolsRMM / remote-access software not on the approved list is detected and removed. Only NinjaOne (and NinjaRemote) and Cloudflare WARP are our remote paths; see Remote Access.security/shadow-it/* (removal dry-run unless Execute is set)
Local admindtcadmin via LAPS, 16+ random, rotated. See Client Credential Administration Standard.identity/local-identity/configuration/laps.ps1

Network

ControlStandardWhere
IPSOn every VLAN, all categories, notify and block.Network Architecture
DNS filteringUpstream DNS is DNSFilter or Cloudflare (1.1.1.1) — nothing else. On DNSFilter sites, roaming laptops run the DNSFilter Roaming Client.DHCP & DNS; security/dnsfilter/*
SegmentationRole-based VLANs, guests isolated, unused switch ports disabled or on a blackhole VLAN.Network Architecture
Remote workersCloudflare WARP (ZTNA), one Cloudflare tenant per client; traditional VPN is being phased out.Remote Access; network/cloudflare-warp/*

Logging and detection

  • Firewall activity forwards to the client's SIEM (Blumira, provided by DTC) where the client has one; otherwise stored on the firewall.
  • SaaS audit logs (M365, Google Workspace) are monitored by SaaS Alerts where licensed.
  • DTC's own approved stack is listed in Approved SIEM and Logging Stack.

Vendor tooling and incidents

  • No vendor or third-party tooling on a production server without an isolated VM, senior-technician approval and client notice (decision D-038, 2026-09-29).
  • An isolated machine stays online long enough to verify the threat is gone before it is wiped (D-038).
  • Response procedures: Security Incident Response Playbook; patching cadence: Vulnerability Remediation SOP.

Open

  • Defender exclusions source of truth. Agreed direction (2026-09-29): a NinjaOne custom field with client → location → device inheritance, built from installed software per client, Blackpoint as the base policy. Not yet built; tamper protection versus a per-device Defender override is unresolved.