Administrative activities are conducted through jump servers.

Credentials for local administrator accounts and service accounts are long, unique, unpredictable and managed.

Windows Defender Credential Guard and Windows Defender Remote Credential Guard are enabled.

Privileged access events are centrally logged.

Privileged account and group management events are centrally logged.

Event logs are protected from unauthorised modification and deletion.

Event logs are monitored for signs of compromise and actioned when any signs of compromise are detected.

Beyond Cyber 101 mentorship into cybersecurity and beyond.