San Antonio managed IT & cybersecurity · 24/7 support available for opt-in clients Call 210-979-1886  ·  info@nexgenguard.com
Resource Center

Our security baseline

What we evaluate in every environment, the outcome each control delivers and how it maps to NIST and CIS.

This is the documented standard we use to evaluate and manage client environments. It doesn't mean every client must buy every product. It means we evaluate the same things every time, explain the risk clearly and recommend what fits your business.

Each area starts with the outcome you're paying for, followed by the controls that achieve it and the related NIST CSF function and CIS Control numbers.

Identity & access

Outcome: Stolen passwords can't be used to get in, and people only have the access they need.

NIST CSF: ProtectCIS Controls: 5, 6

  • MFA on every supported account, phishing-resistant MFA where practical
  • Microsoft Entra ID security policies and Conditional Access
  • Least-privilege access and separate admin accounts
  • Prompt removal of former employees and inactive accounts
  • Password manager and strong password policy

Devices (endpoints)

Outcome: Computers are hardened, patched and watched for attacks around the clock.

NIST CSF: Identify · Protect · DetectCIS Controls: 1, 2, 4, 7, 10

  • Managed endpoint detection and response (EDR), with MDR where appropriate
  • Automated patching of operating systems and apps
  • Full-disk encryption (BitLocker)
  • Device compliance and mobile device management (MDM)
  • Hardware and software inventory

Network

Outcome: Outsiders can't reach what they shouldn't, and guests stay off business systems.

NIST CSF: Protect · DetectCIS Controls: 4, 12, 13

  • Business-grade firewall with current firmware
  • Secure VPN or remote access
  • Separate guest Wi-Fi and network segmentation
  • DNS filtering
  • WPA2/WPA3 wireless and review of exposed ports and services

Email & Microsoft 365

Outcome: Phishing and spoofed emails are stopped or flagged, and files aren't overshared.

NIST CSF: Protect · DetectCIS Controls: 3, 9

  • SPF, DKIM and DMARC
  • Anti-phishing, anti-spam, and link and attachment scanning
  • External sender warnings
  • SharePoint/OneDrive sharing restrictions
  • Microsoft Secure Score reviews and audit logging

Backup & recovery

Outcome: You can recover from ransomware, deletion or hardware failure, and you know how long it takes.

NIST CSF: RecoverCIS Controls: 11

  • Automated, encrypted, offsite backups
  • Immutable or ransomware-resistant copies
  • Backup monitoring and regular restore tests
  • Documented recovery time (RTO) and recovery point (RPO) objectives
  • Business continuity planning

Monitoring & response

Outcome: Threats are noticed quickly and handled with a plan, not panic.

NIST CSF: Detect · RespondCIS Controls: 8, 17

  • Centralized security logging and alert monitoring
  • Vulnerability assessments, prioritizing CISA KEV items
  • Written incident response and escalation procedures
  • Communication plan and post-incident review

People

Outcome: Employees recognize scams and report them.

NIST CSF: ProtectCIS Controls: 14

  • Recurring security awareness training
  • Phishing simulations
  • Guidance on MFA, passwords, remote work and safe browsing
  • Simple process for reporting suspicious activity

Vendors & policies

Outcome: Third parties are held to clear security expectations, and responsibilities are written down.

NIST CSF: GovernCIS Controls: 15

  • Review of third-party and remote access
  • Documented responsibilities between you and your providers
  • Periodic access reviews
  • Data handling and retention policies

Products serve outcomes

Tools like SentinelOne, Cisco Duo, Axcient and Microsoft 365 security features are how we deliver these outcomes, not the goal in themselves. We choose and configure technology to meet the baseline, and we can explain what each one does for you.

Last reviewed: October 2026. Laws and standards change; always confirm with the official source.

Ready for IT that just works?

Book a free consultation or IT security audit. No sales team, no pressure — just straight answers.