What are CIS Benchmarks?
The Center for Internet Security (CIS) Benchmarks are a set of globally recognised, consensus-based configuration guidelines for over 100 technology platforms — from Windows Server and Linux distributions to cloud platforms, containers, and network devices. Each benchmark provides a prescriptive list of configuration settings that reduce the attack surface of a system. They are free to download and are referenced as the hardening standard in ISO/IEC 27001:2022, NIST SP 800-53, CIS Controls v8, and explicitly in CERT-In guidance documents for securing critical infrastructure. CIS Benchmarks are not aspirational — they are the minimum expectation for any enterprise claiming compliance maturity.
CIS Benchmark Profiles: Level 1 vs Level 2
| Profile | Description | Suitable For | Compliance Relevance |
|---|---|---|---|
| Level 1 | Recommended, essential security, minimal performance impact | All enterprise systems, workstations, general servers | ISO 27001, CERT-In minimum |
| Level 2 | Defense in depth, higher security, may limit functionality | High-security environments — BFSI, healthcare, critical infra | RBI, SEBI, PCI DSS |
Windows Server Hardening — Key CIS Areas
CIS Benchmark for Windows Server 2022 (and 2019/2016) covers: Account Policies (password complexity, lockout threshold, Kerberos settings), Local Policies (audit policy — success and failure logging for all critical events), Windows Firewall settings, System Services (disabling unused services — Print Spooler, Remote Registry, Bluetooth), Security Options (LAN Manager authentication level — NTLMv2 only, SMB signing required), and Network settings (disabling IPv6 if unused, disabling LLMNR and mDNS). Run the free CIS-CAT Lite tool to generate an automated benchmark compliance score for any Windows Server.
Linux Hardening — Key CIS Areas
CIS Benchmark for Ubuntu LTS, RHEL 9, and Amazon Linux 2 covers: filesystem hardening (separate partitions for /tmp, /var, /home, noexec/nosuid mount options), SSH configuration (disable root login, use SSH keys not passwords, restrict allowed users, disable X11 forwarding), auditd configuration (log all privileged commands, file access to sensitive files, user and group changes), kernel parameters (sysctl hardening — disable IP forwarding if not router, enable SYN cookies, restrict core dumps), and PAM configuration (password quality enforcement, account lockout). Key tool: Lynis — free, open-source Linux hardening audit tool that scores your system against CIS Benchmarks.
Generating Audit Evidence from CIS Assessments
Running CIS-CAT Lite or Lynis generates a scored compliance report — the percentage of CIS Benchmark checks that pass on a given system. This report, dated and archived, is a powerful piece of audit evidence for ISO 27001 A.8.8 (management of technical vulnerabilities) and CERT-In control assessments. Run these scans quarterly on a sample of systems and retain the reports for at least one year. Compare successive reports to demonstrate improvement over time — a hallmark of a mature security programme.
CIS Benchmark Assessment On-Site
InfraVeritas 360 runs CIS Benchmark assessments on Windows and Linux servers during every on-site IGaaS engagement — producing a scored compliance gap report with prioritised remediation.
Get Your CIS Benchmark Score →