Skip to content

CIS Benchmark

Definition

A technology-specific configuration hardening guide published by CIS for operating systems, cloud services, databases, and applications. Each Benchmark provides Level 1 (broadly applicable, low disruption) and Level 2 (higher security, may reduce functionality) recommendations with specific audit commands.

Publisher
Center for Internet Security (CIS)
Scope
OS, cloud service, database and application hardening configs
Level 1
Broadly applicable, low disruption to function
Level 2
Higher security, may reduce functionality
Includes
Specific audit commands per recommendation

Common questions

How does a Level 1 recommendation differ in practice from Level 2?+

Level 1 settings are intended to be applied broadly without breaking normal operations, such as disabling an unused legacy protocol, while Level 2 settings tighten security further but may disable features some environments still rely on, such as certain remote administration paths.

Are CIS Benchmarks legally mandated?+

No, they are voluntary industry guidance, though many regulatory frameworks and contracts reference CIS Benchmark compliance, or map to it, as evidence of a reasonable security baseline during audits or after an incident.

How does an auditor verify a system meets a Benchmark?+

Each recommendation ships with a specific audit command or check the auditor runs against the live configuration, then compares the output to the documented expected state to score compliance rather than relying on a policy document alone.

Related terms

CIS Controls Self-Assessment Tool (CSAT)
A free web-based tool provided by CIS that allows organisations to score their current implementation status for each Safeguard and generate a...
CIS Controls V8
The eighth version of the CIS Critical Security Controls, released in May 2021. It consolidates 18 Controls and 153 Safeguards, reorganised from...
Crosswalk
A published table that aligns controls from two frameworks side by side to show which controls address the same security objective. NIST,...
Implementation Group (IG)
A CIS Controls concept that divides the 153 safeguards across three tiers by organisational size and risk profile. IG1 (56 safeguards) covers...
Safeguard
The individual action item within a CIS Control. Each Safeguard specifies a concrete activity (for example, 'establish and maintain an accurate inventory...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.