The after-hours sweep was the part our auditors latched onto. We had been doing this manually with a spreadsheet for three years.
Endpoint Governance
Branch Fleet Baseline
A hardened, monitored baseline for branch laptops, tellers, and shared kiosks that audit always asks about.
What it does
Branch endpoints carry distinctive risk: shared logins, kiosk lockdown, intermittent connectivity. CrestNode ships a baseline configuration tuned for KR branch banking — kiosk shell, USB control, screen-saver attestation, after-hours sweep — with monthly drift reports and quarterly hardening reviews.
Inclusions
- Pre-tuned kiosk and teller laptop baselines for shared-login environments
- Granular USB and removable-media control with exception ledger
- After-hours sweep with screenshot-free evidence capture
- Branch-tier monthly drift report (no headquarters noise)
- Quarterly baseline hardening review with line-item changelog
Outcomes after rollout
- 01 Bring branch endpoints to a consistent baseline within the first 30 days
- 02 Catch shared-login policy violations the same evening they occur
- 03 Replace branch screen-saver attestation paperwork
Common questions
We do not pretend they do not exist. The baseline sets a session-bounded evidence window per shift, attests on logout, and flags anomalous off-shift activity. It is not a substitute for moving toward per-user identity, which we recommend on the discovery call.
The baseline operates locally. Evidence and exceptions are queued and reconciled when connectivity returns; the next monthly report shows the offline window explicitly.
Not quite. The baseline pairs with the Orchestrator if you want central policy authoring across both branch and headquarters. Alone it is a strong branch-only program.
From clients
Han Ji-won, Compliance Strategist
Eleven years aligning regional bank policy frameworks with FSC and FSS expectations. Builds the control libraries that shape every CrestNode rollout.
No obligation. KR business hours, English or Korean.