Developed by the Center for Internet Security (CIS), the CIS Benchmarks provide practical, community-driven recommendations for securely configuring a wide range of technologies, including operating systems, cloud platforms, databases, network devices, servers, and software.
Here are the most important things to know:
Let’s dive deeper.
At their core, the CIS Benchmarks are configuration guides. Each one focuses on a specific technology or product and provides recommendations for mitigating potential security risks.
Each benchmark explains a security measure, why it matters, the potential impact of implementing it, how to audit the configuration, and how to remediate an issue. This structure helps organizations translate security recommendations into actionable configuration changes.
The recommendations are developed through a consensus-based process involving cybersecurity practitioners, technology vendors, academics, and other subject matter experts. Participants review, test, and provide feedback on recommendations before they are finalized.
The CIS Benchmarks and CIS Controls are closely related, but they serve different purposes.
The CIS Controls provide a prioritized set of cybersecurity best practices that organizations can use to build and strengthen their overall security programs. They address areas such as asset management, vulnerability management, access control, and incident response.
The CIS Benchmarks take a more technical and specific approach. For example, CIS Control 4 focuses on establishing and maintaining secure configurations. The CIS Benchmarks can help organizations put that principle into practice by providing configuration recommendations for specific technologies.
Think of the CIS Controls as what your security program should address and the CIS Benchmarks as how to securely configure many of the technologies that support it.
Organizations can use applicable Benchmarks to establish secure configuration baselines for their technology environments. Security teams can then assess configurations against those baselines to identify gaps and determine where remediation may be needed.
CIS Benchmarks can also support compliance efforts by giving organizations a documented, consistent way to assess security configurations against established recommendations.
While the CIS Controls provide a broader foundation for building a cybersecurity program, the CIS Benchmarks offer more detailed guidance for securely configuring specific technologies. Using the two together can help organizations move from broad security objectives to actionable technical improvements that strengthen their overall security posture.
BARR’s experts can help you align your specific environment with the CIS Benchmarks and other security standards. Contact us today to learn more.