Server Audit

Server security audit overview. For a focused single-server technical audit, see YourServerAudit.com.

A server audit reviews the security configuration of an individual Linux server — from OS hardening and SSH access to the web stack, mail services, firewall rules and backup configuration. Within the context of YourInfraAudit, server-level checks are part of our broader infrastructure reviews.

What We Cover

When a server audit is included as part of an infrastructure engagement, we review:

  • OS and kernel — distribution version, kernel parameters, pending updates, unnecessary packages
  • SSH configuration — authentication methods, key management, root login policy, port configuration, idle timeout
  • Firewall — iptables/nftables/firewalld rules, default policies, open ports, rate limiting
  • Web stack — Apache/Nginx configuration, TLS settings, virtual host isolation, HTTP security headers
  • PHP environment — version, handler, disabled functions, session configuration, open_basedir
  • Mail services — Postfix/Exim configuration, relay restrictions, authentication, TLS enforcement
  • Running services — identification of unnecessary listeners, services bound to public interfaces
  • User accounts — privilege review, dormant accounts, sudo configuration, password policies
  • Logging and monitoring — log rotation, centralised logging, audit trail, intrusion detection
  • Backup — local and remote backup status, schedule, restore readiness

Dedicated Single-Server Audits

If you need a focused, standalone audit of a single server — without the broader infrastructure scope — YourServerAudit.com provides exactly that. It is a dedicated service for in-depth, server-level security review with detailed remediation guidance.

YourServerAudit.com is the right choice when:

  • You have one server that needs a thorough security review
  • You want a standalone report focused entirely on server configuration
  • You need a pre-deployment or post-migration security check

When to Choose YourInfraAudit Instead

Choose the Infrastructure Security Audit when your scope extends beyond a single server:

  • Multiple servers with shared roles (web, mail, DNS, database)
  • Hosting platforms with control panels, billing systems and customer-facing services
  • Operations where server security is one piece of a larger infrastructure picture
  • Environments where the interaction between components matters as much as individual server configuration

Need a server reviewed? Contact us to determine the right scope, or see our pricing. For a dedicated single-server audit, visit YourServerAudit.com.

Need a different audit scope?

We tailor every engagement to your infrastructure. Tell us what you need.

Request an audit View sample report