CIS CAT Controls Assessment Module Server is not working for Windows Server


Product Name

CIS-CAT Pro Assessor

Product Version

4.17.0 +

Date

Sep 6, 2022



 

Problem

Scans for The Controls Assessment Module option in CIS-CAT Pro Assessor shows Platform Mismatch.

Solution

For the Controls Assessment Module for Windows 10 - anything other than a Windows 10 target should indicate a platform mismatch for that. The Controls Assessment Module for Windows Server was designed primarily for Windows Server 2016. While designed primarily for Microsoft Windows Server 2016, this module can also be used to assess other Windows Server versions.  Simply set ignore.platform.mismatch=true in the assessor-cli.properties file in the Assessor config folder, and the Controls Assessment Module for Windows Server will be able to assess machines running other versions such as Microsoft Windows Server 2019.

The Controls Assessment Module for Windows 10 was explicitly designed to evaluate CIS Controls v7.1 IG1 Safeguards only. It's intended to have far fewer checks than the Windows 10 Benchmark. There is documentation for the CIS Controls Assessment Module for Windows 10 in https://ciscat-assessor.docs.cisecurity.org/en/latest/User%20Guide%20for%20Controls%20Assessment%20Module/#cis-cat-pro-assessor-user-guide-for-controls-assessment-module.

Please note disabling the platform checks for all benchmarks, can lead to incorrect scoring of the OS when the Benchmark do not in fact match. Therefore, after you run a Controls Assessment Module, we strongly encourage you to switch the setting back by changing the "True" back to "False".

Keywords;

Content by Label


Copyright © 2022

Center for Internet Security®