Several other security best practices can be followed, some of them are enumerated here:
- Use a remote access VPN to provide access to remote workers
- Log everything in an immutable manner in a centralized location, and review the logs periodically
- Set up tape rotation for backup, and restrict access to the tapes
- Ensure the backups are encrypted and tested regularly
- Deploy the mail filtering application to protect from phishing, malware, and so on
- Use a central NTP server to synchronize the time everywhere
- Provide access with the Least Privilege mode, which simply means implicitly deny until the access is explicitly given