Skip to content

CIS Benchmarks

What is CIS Benchmarks?

Consensus-based configuration guidelines developed by the Center for Internet Security for securely configuring IT systems and applications.

Compliance and Regulatory

Each of these is named in at least one of the same controls as cis benchmarks. The number is how many controls name both.

What the standards actually require on cis benchmarks

Requirements naming cis benchmarks across 6 standards, quoted from the control text.

ISMAP (Japan)1 control

ISMAP Cloud Infrastructure controls cover the underlying compute + network + storage + management plane. (1) Virtual Network Segmentation: VPC Virtual Private Cloud isolation + subnets + security groups + NACLs + microsegmentation + service mesh (Istio + Linke...

ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement · ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration Management + IaC

Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;

JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response

Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection...

KNCF-Protect-Network-Configuration-Vulnerability-Physical-Secure-SDLC-Hardening-Patching-Drift · Kuwait NCF Protect + Network + Configuration + Vulnerability + Physical + Secure SDLC

Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-C...

LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15 · Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15

Disclose and operate malware detection + system hardening + cybersecurity upgrade features per MDS2 MLDP + SAHD + CSUP sections. Malware Detection and Protection (MLDP) including anti-malware software support + signature update mechanism + behavioural detectio...

MDS2-Malware-Detection-MLDP-System-Hardening-SAHD-Cybersecurity-Upgrades-CSUP-Patch-Management · MDS2 Malware Detection + MLDP + System Hardening + SAHD + Cybersecurity Upgrades + CSUP + Patch Management

Questions people ask about cis benchmarks

What is CIS Benchmarks?
Consensus-based configuration guidelines developed by the Center for Internet Security for securely configuring IT systems and applications.
Why is CIS Benchmarks important for compliance?
CIS Benchmarks is a key concept in Compliance and Regulatory. Understanding cis benchmarks helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address CIS Benchmarks?
CIS Benchmarks appears in the requirement text of ISMAP (Japan), IRS Publication 1075, Japan FSA Cybersecurity Guidelines for Financial Institutions, Kuwait National Cybersecurity Framework, Lloyd's Minimum Standards - Cyber Security. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about CIS Benchmarks?
Explore our compliance framework pages to see how cis benchmarks applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how CIS Benchmarks applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.