Security Standards
The security baseline for every DTC-managed client environment. Each line says what the standard is and what enforces it — almost all of it is converged by ninja-one-automation scripts running under the NinjaOne agent, so the standard is what the fleet actually runs, not an aspiration.
Principles
- One EDR, one anti-malware engine, deployed by us. A second security agent on an endpoint fights the first — duplicated kernel filters, mutual quarantine, hours lost diagnosing it.
- Converged, not configured once. Every control below has a configuration script that re-applies it on a schedule, and an inventory or condition that reports drift.
- Alert on the gap. If a control cannot be applied (legacy BIOS, missing site key), the device reports it rather than silently going without.
Endpoint
| Control | Standard | Enforced by |
| EDR / MDR | Blackpoint Cyber MDR on every managed endpoint and server. Unified Agent v3 is the current agent; legacy SNAP sites migrate to v3. Vendor-bundled endpoint security (CrowdStrike, Norton, McAfee, OEM add-ons) is removed from the purchase quote, never just left uninstalled. | security/blackpoint/configuration/blackpoint-agent-v3-provision.ps1; inventory blackpoint-snapagent-inventory.ps1 (reports v3 and outdated agents) |
| Anti-malware | Microsoft Defender Antivirus, real-time protection always on, per-client exclusions applied. Core Isolation (HVCI) disabled by default for application performance, without disabling Hyper-V/VBS; re-enable per device via defenderDisableCoreIsolation. | security/defender/configuration/defender-provision.ps1, security/defender/inventory/defender-inventory.ps1 |
| Disk encryption | BitLocker on OS drives: TPM + 48-digit recovery password, XtsAes256, recovery password escrowed to AD and/or Entra ID before encryption begins. Suspended, unprotected, or keyless volumes alert. | security/bitlocker/* |
| Secure Boot | On wherever the firmware supports it. A UEFI machine with Secure Boot off alerts; legacy-BIOS machines are reported, not alerted (fixing them needs a reimage). 2026 certificate-rollover readiness is inventoried. | endpoint/oem/configuration/oem-firmware-configure.ps1, security/secure-boot/* |
| Application control | AppLocker blocks executables launched from user download locations — audit first, then enforce, per client. | security/applocker/* |
| Unapproved remote tools | RMM / remote-access software not on the approved list is detected and removed. Only NinjaOne (and NinjaRemote) and Cloudflare WARP are our remote paths; see Remote Access. | security/shadow-it/* (removal dry-run unless Execute is set) |
| Local admin | dtcadmin via LAPS, 16+ random, rotated. See Client Credential Administration Standard. | identity/local-identity/configuration/laps.ps1 |
Network
| Control | Standard | Where |
| IPS | On every VLAN, all categories, notify and block. | Network Architecture |
| DNS filtering | Upstream DNS is DNSFilter or Cloudflare (1.1.1.1) — nothing else. On DNSFilter sites, roaming laptops run the DNSFilter Roaming Client. | DHCP & DNS; security/dnsfilter/* |
| Segmentation | Role-based VLANs, guests isolated, unused switch ports disabled or on a blackhole VLAN. | Network Architecture |
| Remote workers | Cloudflare WARP (ZTNA), one Cloudflare tenant per client; traditional VPN is being phased out. | Remote Access; network/cloudflare-warp/* |
Logging and detection
- Firewall activity forwards to the client's SIEM (Blumira, provided by DTC) where the client has one; otherwise stored on the firewall.
- SaaS audit logs (M365, Google Workspace) are monitored by SaaS Alerts where licensed.
- DTC's own approved stack is listed in Approved SIEM and Logging Stack.
- No vendor or third-party tooling on a production server without an isolated VM, senior-technician approval and client notice (decision D-038, 2026-09-29).
- An isolated machine stays online long enough to verify the threat is gone before it is wiped (D-038).
- Response procedures: Security Incident Response Playbook; patching cadence: Vulnerability Remediation SOP.
Open
- Defender exclusions source of truth. Agreed direction (2026-09-29): a NinjaOne custom field with client → location → device inheritance, built from installed software per client, Blackpoint as the base policy. Not yet built; tamper protection versus a per-device Defender override is unresolved.