Security checklist

This checklist is a practical baseline for people who administer and use RMON. Adapt it to your organization's security policy and network design.

First login

Users, groups, and access

See Groups and roles for the user workflow.

Connections and credentials

Checks and integrations

See Notifications and alerting for channel setup and testing.

Status pages and runbooks

Use the Status pages guide before publishing or changing a page.

Routine review

If a secret is exposed

  1. Disable or revoke the exposed credential at its source.
  2. Create a replacement with the minimum required access.
  3. Update the corresponding RMON credential, check, or notification channel.
  4. Use Test or run the affected check to confirm that the replacement works.
  5. Review RMON history, provider activity, and affected systems for unauthorized use.
  6. Remove the secret from descriptions, runbooks, tickets, or messages where it was exposed.