Identifying which CIS Benchmarks are available & supported in Assessor


Product Name

CIS Benchmark™

Product Version

all

Date

Sep 27, 2023



Problem

I would like to know if a CIS Benchmark is available for a specific product or platform, and whether this Benchmark is supported for automated assessments in CIS-CAT Pro Assessor.

Solution

For Benchmarks (manual assessments)

  • Navigate to CIS WorkBench at https://workbench.cisecurity.org
    (an account can be created for free)

  • Search for the desired application or operating system under the “Benchmarks” tab. A combination of keywords for the query may be required; using the below example, ubuntu 22.04 will not return a match, but ubuntu linux 22.04 will:

The % character can be used as wildcard in the Search dialog, ex.:
windows % stand
This will return both Windows 10 & 11 Stand-Alone Benchmarks.

 

  • Once the applicable Benchmark has been located, you can then browse each Recommendation category and item on the left, or select the “Files” button to download the Benchmark either as PDF (available to all users) or in Word / Excel format (SecureSuite Members only). If a Build Kit is available for this Benchmark, it will be listed under “Files” as well.


For CIS-CAT Pro Assessor (automated assessments, SecureSuite Members only)

If a Benchmark is not listed in the Coverage Guide, it is not yet supported by CIS-CAT Pro Assessor. If you or your organization would like to express interest in an available Benchmark being included in Assessor, please raise a Feature Enhancement Request ticket.

Feature Enhancement Requests are used by our development teams to gather Member feedback, and apply them to roadmaps for future CIS product releases and capabilities.

Keywords; Assessor Benchmarks WorkBench

Content by Label


Copyright © 2023

Center for Internet Security®