How to access the out-of-the-box configuration report for CIS Hardened Images.
Product Name
CIS Hardened Images
Product Version
all
Date
Nov 15, 2023
Problem
How can I find the out-of-the-box configuration report for my CIS Hardened Image?
Solution
For all CIS Hardened Images (excluding the images that will be end-of-life in the first half of 2023), the file location for the configuration reports will always be in the CIS_Hardening_Reports folder (C:\CIS Hardening Reports on Windows and \home\CIS_Hardened_Reports on Linux).
All Hardened Image contains the following files in the CIS_Hardening_Reports folder:
CIS-CAT_Report.html
- This provides a report of CIS-CAT Pro run against the instance after the corresponding CIS Benchmark was applied to the image.Exceptions.txt
- This provides a list of recommendations that are not applied because the configuration of those recommendations may inhibit the use of this image in this Cloud Service Provider, require environment-specific expertise, or hinder integration of this image with Cloud Service Provider services or extensions.
For Windows, the only additional file that accounts for the release notes is the Base CIS-CAT Report
(since Windows does not have the same "package" set up as Linux and is based on end-user feedback). The Base CIS-CAT Report provides a report of CIS-CAT Pro run against the instance before any change is made by CIS (e.g., software updates, CIS hardening).
For Linux, there are three additional files that account for the release notes:
Base_CIS-CAT_Report.html
- this provides a report of a CIS-CAT run against the instance prior to any change being made by CIS (updates, hardening, etc.)basevm.txt
- this text file provides a list of the packages resident on the instance prior to any change being made by CIS (e.g., software updates, CIS hardening).afterhardening.txt
- this text file provides a list of packages resident on the instance after the corresponding CIS Benchmark was applied to the image.
The screenshot below shows the three files in the /home/CIS_Hardened_Reports
directory:
Example Table
This table compares four CIS Hardened Images and files found within their CIS_Hardening_Reports folder:
| Base_CIS-CAT_Report.html | CIS-CAT_Report.html | Exceptions.txt | afterhardening.txt | basevm.txt |
Debian Linux 10 v2.0.0, Level 1 | X | X | X | X | X |
Microsoft Windows Server 2019 v2.0.0.3, Level 1 | X | X | X |
|
|
Microsoft Windows Server 2022 v2.0.0.3 - Level 1 | X | X | X |
|
|
Ubuntu Linux 22.04 LTS v1.0.0.11 - Level 1 | X | X | X | X | X |
Keywords; Hardened Images configuration report out-of-the-box hardening, CIS_Hardening_Reports folder files,
Content by Label