Identifying which CIS Benchmarks are available & supported in Assessor
Product Name
CIS Benchmark™
Product Version
all
Date
Sep 27, 2023
Problem
I would like to know if a CIS Benchmark is available for a specific product or platform, and whether this Benchmark is supported for automated assessments in CIS-CAT Pro Assessor.
Solution
For Benchmarks (manual assessments)
Navigate to CIS WorkBench at https://workbench.cisecurity.org
(an account can be created for free)Search for the desired application or operating system under the “Benchmarks” tab. A combination of keywords for the query may be required; using the below example,
ubuntu 22.04
will not return a match, butubuntu linux 22.04
will:
The %
character can be used as wildcard in the Search dialog, ex.:windows % stand
This will return both Windows 10 & 11 Stand-Alone Benchmarks.
Once the applicable Benchmark has been located, you can then browse each Recommendation category and item on the left, or select the “Files” button to download the Benchmark either as PDF (available to all users) or in Word / Excel format (SecureSuite Members only). If a Build Kit is available for this Benchmark, it will be listed under “Files” as well.
For CIS-CAT Pro Assessor (automated assessments, SecureSuite Members only)
Review the Coverage Guide on the CIS-CAT Pro Assessor documentation page:
https://ciscat-assessor.docs.cisecurity.org/en/latest/Coverage%20Guide/
This document is continually updated to list all supported Benchmarks, operating systems & applications that the current release of Assessor is compatible with.Members can download CIS-CAT Pro Assessor from CIS WorkBench, which will always include the latest supported Benchmarks at the time of release:
https://workbench.cisecurity.org/download/cis-cat/pro
If a Benchmark is not listed in the Coverage Guide, it is not yet supported by CIS-CAT Pro Assessor. If you or your organization would like to express interest in an available Benchmark being included in Assessor, please raise a Feature Enhancement Request ticket.
Feature Enhancement Requests are used by our development teams to gather Member feedback, and apply them to roadmaps for future CIS product releases and capabilities.
Keywords; Assessor Benchmarks WorkBench
Content by Label