Re: CIS benchmarks



The CIS benchmarks are industry standards. How the benchmarks are developed is through consensus and collaboration with Subject Matter Experts, practitioners, and system administrators. In addition any regulatory stand / practice where applicable are also incorporated for consideration. There are 3 levels of benchmarks. Level 1 is the minimum and the governing principal is that it will not break production. Level 3 is the most hardened and usually they will break a production installation unless due dilligence has been done ahead of time.

The fundamental principal was to establish a basic set of "due care" baselines so that organizations would have a credible and repuable place to begin in establishing configurartion policies. The benchmarks are used by IT organizations globally and the center is supported by both vendors, businesses, and individual contributors through yearly subscriptions. The center was launched in partnership with SANS as well as a number of founding security software vendors.

I hope this helps.

Mike

----- Original Message -----
From: Saif El Sherei [mailto:SSherei@xxxxxxxxxxxx]
Sent: Thursday, May 26, 2011 04:12 PM
To: Catelijne van Antwerpen <cvanantwerpen@xxxxxxxxxxx>
Cc: security-basics@xxxxxxxxxxxxxxxxx <security-basics@xxxxxxxxxxxxxxxxx>
Subject: Re: CIS benchmarks

CIS are one of the best sources for security benchmarks along with NIST

CIS standards are recommend by allot of security standards like PCI-DSS.

Regards,

Saif
OSCP

Sent from my iPhone.

On May 27, 2011, at 12:58 AM, "Catelijne van Antwerpen" <cvanantwerpen@xxxxxxxxxxx> wrote:

Hi,

I'm investigating some standard install procedures with the focus on security.
On the internet I stumbled upon CIS (Center for Internet Security).
http://www.cisecurity.org/index.cfm
The have put together a lot of security benchmarks for different kinds of products.
It looks good at first sight, but I don't how well this organization is known by the community.

Do you know whether these benchmarks are being used frequently?
Or do you guys use other benchmarks/listen to other authorities?

Cheers,


Cat.


Catelijne van Antwerpen
Applicatiebeheerder




Mirabeau | Managed Services H.J.E. Wenckebachweg 108, 1096 AR Amsterdam
+31(0)20-5950550 - www.mirabeau.nl
Parttime: oneven weken op woensdag afwezig.


Please consider the environment before printing this email

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------




------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------



Relevant Pages

  • Re: CIS benchmarks
    ... CIS standards are recommend by allot of security standards like PCI-DSS. ... The have put together a lot of security benchmarks for different kinds of products. ...
    (Security-Basics)
  • Group proposes minimum security benchmark
    ... +international Internet security organization to support a set of ... +benchmarks aimed at guaranteeing a minimum security standard for ... +among the government organizations that have teamed up with the ... +the security of Windows 2000 workstations. ...
    (comp.os.linux.security)
  • Group proposes minimum security benchmark
    ... +international Internet security organization to support a set of ... +benchmarks aimed at guaranteeing a minimum security standard for ... +among the government organizations that have teamed up with the ... +the security of Windows 2000 workstations. ...
    (comp.security.unix)
  • RE: SMB enumation in Win2000/03
    ... Make absolutely sure that you test the benchmarks on a sacrificial server ... I am having difficulity locking down a couple of Windows Server 2003 domain ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
    (Security-Basics)
  • CIS benchmarks
    ... I'm investigating some standard install procedures with the focus on security. ... On the internet I stumbled upon CIS. ... The have put together a lot of security benchmarks for different kinds of products. ...
    (Security-Basics)