CIS Benchmark Scanning
Utilize CIS Benchmark Scanning to verify your compliance with industry standard security best practices.
What is CIS Benchmark Scanning?
According to CIS Security, CIS Benchmarks are best practices for the secure configuration of a target system.
We support the following CIS Benchmarks:
| Windows |
|---|
| CIS Windows 10 Enterprise v4.0.0 |
| CIS Windows 10 Enterprise with BitLocker v4.0.0 |
| CIS Windows 10 Enterprise with BitLocker, NextGen v4.0.0 |
| CIS WIndows 11 Enterprise v4.0.0 |
| CIS Windows 11 Enterprise with BitLocker v4.0.0 |
Create a CIS Scan
There are a couple of ways to access and use CIS Benchmark Scans. If auto-enabled credentials are being used for the CIS Benchmark scanning, the default CIS Benchmark Scan profile can be used.
- Create a new scan policy or copy an already existing one. For more information on creating and running scans, see Create and Run Scans.
- From the navigation menu, select Scans > Scan Policies.
- Look for CIS Benchmark Scan, and then select the Copy & edit button. A new window opens.
- Rename the Scan Policy to something unique.
- Select Credentials from the top tab.
- Toggle Compliance Scanning to ON.
- Under Select Credentials, select the credentials you want to add.
- If needed, add credentials by selecting + Add Credential.
- Complete the rest of the fields as needed.
- Select Save, or Add Another (if necessary).
Run a CIS Scan
- From the , select Scans > Scan Activity.
- Select + New scan.
- Under General Settings, select Advanced.
- Under Policy Options, select the CIS Compliance scan you renamed in step 4 of Create a CIS Scan from the Scan Policy list.
- Complete the rest of the settings as needed.
- Select Create and run.
The new scan will be added to the Upcoming Scheduled Scans list. From this screen you can edit or delete the scan.