CIS Benchmark
Definition
A technology-specific configuration hardening guide published by CIS for operating systems, cloud services, databases, and applications. Each Benchmark provides Level 1 (broadly applicable, low disruption) and Level 2 (higher security, may reduce functionality) recommendations with specific audit commands.
- Publisher
- Center for Internet Security (CIS)
- Scope
- OS, cloud service, database and application hardening configs
- Level 1
- Broadly applicable, low disruption to function
- Level 2
- Higher security, may reduce functionality
- Includes
- Specific audit commands per recommendation
Common questions
How does a Level 1 recommendation differ in practice from Level 2?+
Level 1 settings are intended to be applied broadly without breaking normal operations, such as disabling an unused legacy protocol, while Level 2 settings tighten security further but may disable features some environments still rely on, such as certain remote administration paths.
Are CIS Benchmarks legally mandated?+
No, they are voluntary industry guidance, though many regulatory frameworks and contracts reference CIS Benchmark compliance, or map to it, as evidence of a reasonable security baseline during audits or after an incident.
How does an auditor verify a system meets a Benchmark?+
Each recommendation ships with a specific audit command or check the auditor runs against the live configuration, then compares the output to the documented expected state to score compliance rather than relying on a policy document alone.
Related terms
- CIS Controls Self-Assessment Tool (CSAT)
- A free web-based tool provided by CIS that allows organisations to score their current implementation status for each Safeguard and generate a...
- CIS Controls V8
- The eighth version of the CIS Critical Security Controls, released in May 2021. It consolidates 18 Controls and 153 Safeguards, reorganised from...
- Crosswalk
- A published table that aligns controls from two frameworks side by side to show which controls address the same security objective. NIST,...
- Implementation Group (IG)
- A CIS Controls concept that divides the 153 safeguards across three tiers by organisational size and risk profile. IG1 (56 safeguards) covers...
- Safeguard
- The individual action item within a CIS Control. Each Safeguard specifies a concrete activity (for example, 'establish and maintain an accurate inventory...