Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Product Name

CIS Hardened Images® (AWS)

Product Version

All

Date



Problem

Info

I am having issues with my HI due to the CIS security recommendations in place.

Solution

Reviewing the content within the corresponding Hardening Report and exceptions list is imperative for overall success, as there may be some settings that your organization needs to exempt itself from, due to unique operational requirements. The report will be located in C:\CIS Hardening Reports on Windows and \home\CIS_Hardened_Reports on Linux.

To find the specific recommendations that are causing the issue you will need to go through the Hardened Image Report, search key words and read the impact statements of the relating recommendations.

Search through the benchmark for the remediation that is causing the impact.

Through searching keywords, you should find which recommendations are causing the issue and then reverse the remediation directions to turn the recommendation off.

For example, if you are using Windows 2016 Server and you are having an issue with the RDP configuration, you should:

  • Login to CIS WorkBench - https://workbench.cisecurity.org/

  • Go to Benchmarks on the top Navigation bar

  • Search for Windows Server 2016

  • Download the PDF version of the Benchmark
    1. Navigate to the Hardening Report

    2. Open the Hardening Report

    3. Search for the word ‘RDP’ or other related words such as 'remote connection' using ctr+f

    4. Go to the recommendations related to RDP and remote connections

    5. Recommendation 18.9.59.3.9.3 (L1) Ensure 'Require use of specific security layer for remote (RDP) connections' is set to 'Enabled: SSL' (Automated) Relates to RDP.

    6. Read the recommendation

    7. Under the Remediation section, there is an explanation of how to enable or disable the recommendation.

    8. Rinse and repeat for each issue you are having.

    Keywords; Hardened Image HI trouble

    Content by Label

    Filter by label (Content by label)
    showLabelsfalse
    showSpacefalse
    cqllabel = "sbp_fer"

    Copyright © 2020

    Center for Internet Security®


    Page Properties
    hiddentrue

    Action

    Name(s)

    Date

    Linked ticket

    Created by

    Nick Romanzo

    Reviewed by

    Approved by

    Remove by