System Hardening
System hardening is the process of strengthening a system's security by reducing vulnerabilities and minimizing its attack surface.
“The step-by-step process of reducing the vulnerabilities of a system by applying a security policy and different layers of protection.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is System Hardening?
Hardening includes disabling unnecessary services, applying security patches, configuring secure settings, and enforcing least-privilege principles.
Security strengthening: Reduces potential attack paths.
Configuration management: Applies secure system settings.
Preventive measure: Protects systems before attacks occur.
Real World Example
A regulated product team is preparing a release where System hardening appears in reviews, test design conversations, or defect triage rather than as an isolated glossary word.
The risk is that the team treats System hardening as interchangeable with nearby ISTQB terms. That makes test scope blurry and can lead to weak evidence for the release decision.
The tester anchors the discussion in the official definition, asks where the concept appears in the product, and designs examples that show the difference between System hardening and similar ideas.
The page becomes useful in practice because System hardening is connected to a specific testing decision, not memorized as a detached definition.
Practice Questions
Question 1
Which statement BEST describes System hardening in the context of ISTQB terminology?
Question 2
A tester needs to explain System hardening to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned System Hardening. Test your understanding with topic-specific questions in our Mock Exams.