In addition to hardening, two other preventive controls should be applied to internal hosts on the network. First, every host needs to be running antivirus software that is regularly updated. Second, every host that stores sensitive information should have a software-based firewall program installed and running. As with antivirus software, it is also important to periodically update firewall software.