CIS Benchmarks
What is CIS Benchmarks?
Consensus-based configuration guidelines developed by the Center for Internet Security for securely configuring IT systems and applications.
Terms that appear alongside cis benchmarks
Each of these is named in at least one of the same controls as cis benchmarks. The number is how many controls name both.
- patch management 7 shared controls
- secure configuration 6 shared controls
- hardening 6 shared controls
- zero trust 4 shared controls
- vulnerability 4 shared controls
- microsegmentation 4 shared controls
- disa stig 4 shared controls
- firewall 4 shared controls
Frameworks that govern cis benchmarks
What the standards actually require on cis benchmarks
Requirements naming cis benchmarks across 6 standards, quoted from the control text.
ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...
ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC →Section 9.4 of IRS Publication 1075 establishes specific requirements for cloud services and addresses the prohibition on offshore processing of FTI.
IRSPub1075-Section94-Cloud-FedRAMP-Offshore-Prohibition-CSP-USRegion-PrivateGovCloud-AzureGov-AWSGov · IRS Pub 1075 Section 9.4 + Cloud Services + FedRAMP Authorisation Required + Offshore Prohibition + AWS GovCloud + Azure Government + Oracle US Federal + Google Workspace Federal + US-Region Data Residency →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection...
KNCF-Protect-Network-Configuration-Vulnerability-Physical-Secure-SDLC-Hardening-Patching-Drift · Kuwait NCF Protect + Network + Configuration + Vulnerability + Physical + Secure SDLC →Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-C...
LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15 · Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15 →Disclose and operate malware detection + system hardening + cybersecurity upgrade features per MDS2 MLDP + SAHD + CSUP sections. Malware Detection and Protection (MLDP) including anti-malware software support + signature update mechanism + behavioural detectio...
MDS2-Malware-Detection-MLDP-System-Hardening-SAHD-Cybersecurity-Upgrades-CSUP-Patch-Management · MDS2 Malware Detection + MLDP + System Hardening + SAHD + Cybersecurity Upgrades + CSUP + Patch Management →Questions people ask about cis benchmarks
What is CIS Benchmarks?
Why is CIS Benchmarks important for compliance?
Which compliance frameworks address CIS Benchmarks?
Where can I learn more about CIS Benchmarks?
See how CIS Benchmarks applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.