Center for Internet Security (CIS)Benchmarks

Patient Tools

Read, save, and share this guide

Use these quick tools to make this medical article easier to read, print, save, or share with a family member.

Patient Mode

Understand this article easily

Switch between simple English and easy Bangla patient notes. This is for education and does not replace a doctor consultation.

CIS Benchmarks from the Center for Internet Security (CIS) are a set of globally recognized and consensus-driven best practices to help security practitioners implement and manage their cybersecurity defenses. Developed with a global community of security experts, the guidelines help organizations proactively safeguard against emerging risks....

For severe symptoms, danger signs, pregnancy, child illness, or sudden worsening, seek urgent medical care.

বাংলা রোগী নোট এখনো যোগ করা হয়নি। পোস্ট এডিটরে “RX Bangla Patient Mode” বক্স থেকে সহজ বাংলা সারাংশ যোগ করুন।

এই তথ্য শিক্ষা ও সচেতনতার জন্য। এটি ডাক্তারি পরীক্ষা, রোগ নির্ণয় বা প্রেসক্রিপশনের বিকল্প নয়।

Article Summary

CIS Benchmarks from the Center for Internet Security (CIS) are a set of globally recognized and consensus-driven best practices to help security practitioners implement and manage their cybersecurity defenses. Developed with a global community of security experts, the guidelines help organizations proactively safeguard against emerging risks. Companies implement the CIS Benchmark guidelines to limit configuration-based security vulnerabilities in their digital assets. Why are CIS Benchmarks important?...

Key Takeaways

  • This article explains Why are CIS Benchmarks important? in simple medical language.
  • This article explains What types of IT systems do CIS Benchmarks cover? in simple medical language.
  • This article explains What are CIS Benchmark levels? in simple medical language.
  • This article explains How are CIS Benchmarks developed? in simple medical language.
Educational health guideWritten for patient understanding and clinical awareness.
Reviewed content workflowUse writer and reviewer profiles for stronger trust.
Emergency safety firstUrgent warning signs are highlighted below.

Seek urgent medical care if you notice

These warning signs are general safety guidance. Local emergency numbers and clinical judgment should always come first.

  • Severe symptoms, breathing difficulty, fainting, confusion, or rapidly worsening illness.
  • New weakness, severe pain, high fever, or symptoms after a serious injury.
  • Any symptom that feels urgent, unusual, or unsafe for the patient.
1

Emergency now

Use emergency care for severe, sudden, rapidly worsening, or life-threatening symptoms.

2

See a doctor

Book a professional medical evaluation if symptoms persist, worsen, recur often, affect daily activities, or occur in a high-risk patient.

3

Learn safely

Use this article to understand possible causes, tests, treatment options, prevention, and questions to ask your clinician.

Before reading

RX Patient Tools

Use these quick guides before reading the article, or return to them when you need help preparing questions for a doctor.

Start here Choose the right pathway for symptoms, reports, medicines, or urgent warning signs. Disease article roadmap Read this topic step by step: meaning, symptoms, warning signs, diagnosis, treatment, prevention, and follow-up. Treatment planner Prepare questions about treatment choices, benefits, risks, side effects, and follow-up. Family & caregiver guide Organize symptoms, reports, medicines, questions, and follow-up safely. Nutrition & diet guide Prepare food, hydration, supplement, and medicine-timing questions safely. Prevention guide Organize risk factors, protective habits, screening, and warning signs. Recovery guide Prepare a safe plan for activity, rehabilitation, warning signs, and follow-up.
Definition

CIS Benchmarks from the Center for Internet Security (CIS) are a set of globally recognized and consensus-driven best practices to help security practitioners implement and manage their cybersecurity defenses. Developed with a global community of security experts, the guidelines help organizations proactively safeguard against emerging risks. Companies implement the CIS Benchmark guidelines to limit configuration-based security vulnerabilities in their digital assets.

Why are CIS Benchmarks important?

Tools such as the CIS Benchmarks are important because they outline security best practices, developed by security professionals and subject matter experts, for deploying over 25 different vendor products. These best practices are a good starting point for creating a new product or service deployment plan or for verifying that existing deployments are secure.

When you implement CIS Benchmarks, you can better secure your legacy systems against common and emerging risks by taking steps such as these:

  • Disabling unused ports
  • Removing unnecessary app permissions
  • Limiting administrative privileges

IT systems and applications also perform better when you disable unnecessary services.

CIS Benchmarks example

For example, admins can follow the step-by-step CIS AWS Foundations Benchmark guidelines to help them set up a strong password policy for AWS Identity and Access Management (IAM). Password policy enforcement, multi-factor authentication (MFA) usage, disabling root, ensuring access keys are rotated every 90 days, and other tactics are distinct, but related, identity guidelines to improve the security of an AWS account.

By adopting CIS Benchmarks, your organization can gain several cybersecurity benefits, such as the following:

Expert cybersecurity guidelines

CIS Benchmarks provide organizations with a framework of security configurations that are expert-vetted and proven. Companies can avoid trial-and-error scenarios that put security at risk and benefit from the expertise of a diverse IT and cybersecurity community.

Globally recognized security standards

CIS Benchmarks are the only best practice guides that are globally recognized and accepted by governments, businesses, research, and academic institutions alike. Thanks to the global and diverse community that works on a consensus-based decision-making model, CIS Benchmarks have far wider applicability and acceptability than regional laws and security standards.

Cost-effective threat prevention

The CIS Benchmark documentation is freely available for anyone to download and implement. Your company can get up-to-date, step-by-step instructions for all kinds of IT systems at no cost. You can achieve IT governance and avert financial and reputational damage from preventable cyberthreats.

Regulatory compliance

CIS Benchmarks align with major security and data privacy frameworks such as these:

  • National Institute of Standards and Technology (NIST) Cybersecurity Framework
  • Health Insurance Portability and Accountability Act (HIPAA)
  • Payment Card Industry Data Security Standard (PCI DSS)

Implementing CIS Benchmarks is a big step toward achieving compliance for organizations that operate in heavily regulated industries. They can prevent compliance failures due to misconfigured IT systems.

What types of IT systems do CIS Benchmarks cover?

CIS has published over 100 benchmarks that span 25+ vendor product families. When you apply and monitor CIS Benchmarks across all types of IT systems, you build an inherently secure IT environment that you can further defend with security solutions. Technologies that CIS Benchmarks cover can be broadly grouped into the following seven categories.

Operating systems

CIS Benchmarks for operating systems provide standard security configurations for popular operating systems, including Amazon Linux. These benchmarks include best practices for features such as these:

  • Operating system access control
  • Group policies
  • Web browser settings
  • Patch management

Cloud infrastructure and services

CIS Benchmarks for cloud infrastructure provide security standards that companies can use to securely configure cloud environments, such as those provided by AWS. The guidelines include best-practice guidelines for virtual network settings, AWS Identity and Access Management (IAM) configurations, compliance and security controls, and more.

Server software

CIS benchmarks for server software provide configuration baselines and recommendations for server settings, server admin controls, storage settings, and server software from popular vendors.

Desktop software

CIS Benchmarks cover most of the desktop software that organizations typically use. The guidelines include best practices for managing desktop software features, such as these:

  • Third-party desktop software
  • Browser settings
  • Access privileges
  • User accounts
  • Client device management

Mobile devices

CIS Benchmarks for mobile devices cover security configurations for operating systems that run on mobile phones, tablets, and other hand-held devices. They provide recommendations for mobile browser settings, application permissions, privacy settings, and more.

Network devices

CIS Benchmarks also provide security configurations for network devices such as firewalls, routers, switches, and virtual private networks (VPNs). They contain both vendor-neutral and vendor-specific recommendations to ensure the secure setup and management of these network devices.

Multi-function print devices

CIS Benchmarks for network peripherals such as multi-function printers, scanners, and photocopiers cover secure configuration best practices such as file sharing settings, access restrictions, and firmware updates.

What are CIS Benchmark levels?

To help organizations achieve their unique security goals, the CIS assigns a profile level to each CIS Benchmark guideline. Each CIS profile includes recommendations that provide a different level of security. Organizations can choose a profile based on their security and compliance needs.

Level 1 profile

Configuration recommendations for the Level 1 profile are basic security recommendations for configuring IT systems. They are easy to follow and do not impact business functionality or uptime. These recommendations reduce the number of entry points into your IT systems, thereby reducing your cybersecurity risks.

Level 2 profile

Level 2 profile configuration recommendations work best for highly sensitive data where security is a priority. Implementing these recommendations requires professional expertise and diligent planning to achieve comprehensive security with minimal disruptions. Implementing Level 2 profile recommendations also helps with achieving regulatory compliance.

STIG profile

The Security Technical Implementation Guide (STIG) is a set of configuration baselines from the Defense Information Systems Agency (DISA). The US Department of Defense publishes and maintains these security standards. STIGs are specifically written to meet US government requirements.

CIS Benchmarks also specify a Level 3 STIG profile that is designed to help organizations comply with the STIG. The STIG profile contains Level 1 and Level 2 profile recommendations that are STIG-specific and provides more recommendations that the other two profiles do not cover but that are required by DISA’s STIGs.

When you configure your systems according to the CIS STIG Benchmarks, your IT environment will be both CIS and STIG compliant.

How are CIS Benchmarks developed?

CIS communities follow a unique consensus-based process to develop, approve, and maintain CIS Benchmarks for different target systems. Overall, the CIS Benchmark development process looks like this:

  1. The community identifies the need for a specific benchmark.
  2. They establish the scope of the benchmark.
  3. Volunteers create discussion threads on the CIS WorkBench community website.
  4. Experts from the specific IT system’s CIS community spend time reviewing and discussing the working draft.
  5. The experts create, discuss, and test their recommendations until they reach a consensus.
  6. They finalize the benchmark and publish it on the CIS website.
  7. More volunteers from the community join in on the CIS Benchmark discussion.
  8. The consensus team considers the feedback from those who implement the benchmark.
  9. They make revisions and updates in the new versions of the CIS Benchmark.

The release of new versions of the CIS Benchmarks also depends on changes or upgrades to the corresponding IT systems.

How can you implement CIS Benchmarks?

Each CIS Benchmark includes a description of the recommendation, the reason for the recommendation, and instructions that system admins can follow to implement the recommendation correctly. Each benchmark can consist of several hundred pages because it covers each area of the target IT system.

Implementing CIS Benchmarks and keeping up with all the version releases gets complicated if you do it manually. That’s why many organizations use automated tools to monitor CIS compliance. The CIS also offers free and premium tools that you can use to scan IT systems and generate CIS compliance reports. These tools alert system admins if the existing configurations don’t meet CIS Benchmark recommendations.

What other security resources are included with the CIS Benchmarks?

The CIS also publishes other resources to improve an organization’s internet security, including the following two main resources.

CIS Controls

CIS Controls (formerly called CIS Critical Security Controls) is another resource that the CIS publishes as a comprehensive best-practice guide for system and network security. The guide contains a checklist of 20 safeguards and actions that are high priority and have proven effective against the most pervasive and destructive cybersecurity threats on IT systems.

CIS Controls map to most of the major standards and regulatory frameworks, such as these:

  • National Institute of Standards and Technology (NIST) Cybersecurity Framework
  • NIST 800-53
  • Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI DSS), Federal Information Security Management Act (FISMA), and others in the ISO 27000 series of standards

CIS Controls give you a starting point for following any of these compliance frameworks.

CIS Benchmarks vs. CIS Controls

CIS Controls are rather generic guidelines for securing entire systems and networks, but CIS Benchmarks are very specific recommendations for secure system configurations. CIS Benchmarks are a critical step for implementing CIS Controls because each CIS Benchmark recommendation refers to one or more of the CIS Controls.

For example, CIS Control 3 suggests secure hardware and software configurations for computer systems. CIS Benchmarks provide vendor-neutral and vendor-specific guidance along with detailed instructions that admins can follow to implement CIS Control 3.

CIS Hardened Images

A virtual machine (VM) is a virtual computing environment that emulates dedicated computer hardware. VM images are templates that system admins use to quickly create multiple VMs with similar operating system configurations. However, if the VM image is configured improperly, the VM instances created from it will also be misconfigured and vulnerable.

The CIS offers CIS Hardened Images, which are VM images that have already been configured to CIS Benchmark standards.

Benefits of using CIS Hardened Images

CIS Hardened Images are useful because they offer the following features:

  • Preconfigured to CIS Benchmark baselines
  • Easy to deploy and manage
  • Updated and patched by CIS

Depending on your security and compliance needs, you can choose CIS Hardened Images that are configured to a Level 1 or Level 2 profile.

Doctor visit helper

Prepare before seeing a doctor

A simple rural-patient checklist to help you explain symptoms clearly, ask better questions, and avoid unsafe self-treatment.

Safety note: This is not a prescription or diagnosis. For severe symptoms, pregnancy danger signs, children with serious illness, chest pain, breathing difficulty, stroke-like weakness, or major injury, seek urgent care.

Which doctor may help?

Start with a registered doctor or the nearest qualified health center.

What to tell the doctor

  • Write when the problem started and how it changed.
  • Bring old prescriptions, investigation reports, and current medicines.
  • Write allergies, pregnancy status, diabetes, kidney/liver disease, and major past illnesses.
  • Bring one family member if the patient is weak, elderly, confused, or a child.

Questions to ask

  • What is the most likely cause of my symptoms?
  • Which danger signs mean I should go to hospital quickly?
  • Which tests are necessary now, and which can wait?
  • How should I take medicines safely and what side effects should I watch for?
  • When should I come for follow-up?

Tests to discuss

  • Vital signs: temperature, pulse, blood pressure, oxygen saturation
  • Basic physical examination by a clinician
  • CBC, urine test, blood sugar, or imaging only when clinically needed

Avoid these mistakes

  • Do not use antibiotics, steroid tablets/injections, or strong painkillers without proper medical advice.
  • Do not hide pregnancy, kidney disease, ulcer, allergy, or blood thinner use.
  • Do not delay emergency care when danger signs are present.

Medicine safety and first-aid guide

This section is for patient education only. It does not replace a doctor, pharmacist, or emergency care.

Safe first steps

  • Avoid heavy lifting, sudden bending, and prolonged bed rest.
  • Use comfortable posture and gentle movement as tolerated.
  • Discuss physiotherapy, X-ray, or MRI only when clinically needed.

OTC medicine safety

  • For mild back pain, pain-relief medicine may be discussed with a doctor or pharmacist.
  • Avoid repeated painkiller use if you have kidney disease, stomach ulcer, uncontrolled blood pressure, or are taking blood thinners.

Avoid these mistakes

  • Do not start antibiotics without a proper medical decision.
  • Do not use steroid tablets or injections casually for quick relief.
  • Do not delay emergency care because of home remedies.

Get urgent help if

  • Back pain with leg weakness, numbness around private area, loss of urine/stool control, fever, cancer history, or major injury needs urgent care.
Medicine names, dose, and timing must be decided by a qualified clinician or pharmacist after checking age, pregnancy, allergy, other diseases, and current medicines.

For rural patients and family caregivers

Patient health record and symptom diary

Write your symptoms, medicines already taken, test results, and questions before visiting a doctor. This note stays on your device unless you print or copy it.

Doctor to discuss: Doctor / qualified healthcare provider
Tests to discuss with doctor
  • Basic vital signs: temperature, pulse, blood pressure, oxygen level if needed
  • Relevant blood, urine, imaging, or specialist tests only after clinical assessment
Questions to ask
  • What is the most likely cause of my symptoms?
  • Which warning signs mean I should go to emergency care?
  • Which tests are really needed now?
  • Which medicines are safe for my age, pregnancy status, allergy, kidney/liver/stomach condition, and current medicines?

Emergency warning signs such as chest pain, severe breathing difficulty, sudden weakness, confusion, severe dehydration, major injury, or loss of bladder/bowel control need urgent medical care. Do not wait for online information.

Safe pathway to proper treatment

Care roadmap for: Center for Internet Security (CIS)Benchmarks

Use this simple roadmap to understand the next safe steps. It is educational and does not replace examination by a doctor.

Go to emergency care if you notice:
  • Severe or rapidly worsening symptoms
  • Breathing difficulty, chest pain, fainting, confusion, severe weakness, major injury, or severe dehydration
Doctor / service to discuss: Qualified healthcare provider; specialist depends on symptoms and examination.
  1. Step 1

    Check danger signs first

    If danger signs are present, seek emergency care and do not wait for online information.

  2. Step 2

    Record the symptom story

    Write when symptoms started, severity, medicines already taken, allergies, pregnancy status, and test results.

  3. Step 3

    Visit a qualified clinician

    A doctor, nurse, or qualified healthcare provider can examine you and decide which tests or treatment are needed.

  4. Step 4

    Do only useful tests

    Do tests after clinical assessment. Avoid unnecessary tests, random antibiotics, or repeated medicines without diagnosis.

  5. Step 5

    Follow up and return early if worse

    If symptoms worsen, new warning signs appear, or treatment is not helping, return for review quickly.

Rural patient practical tips
  • Take a written symptom diary and all previous prescriptions/test reports.
  • Do not hide medicines already taken, even herbal or over-the-counter medicines.
  • Ask which warning signs mean urgent referral to hospital.

This roadmap is for education. A real diagnosis and treatment plan requires history, examination, and clinical judgment.

RX Patient Help

Ask a health question safely

Write your symptom story. A health professional or site editor can review it before any answer is prepared. This box is not for emergency care.

Emergency first: Severe chest pain, breathing trouble, unconsciousness, stroke signs, severe injury, heavy bleeding, or rapidly worsening symptoms need urgent local medical care now.

Frequently Asked Questions

Why are CIS Benchmarks important?

Tools such as the CIS Benchmarks are important because they outline security best practices, developed by security professionals and subject matter experts, for deploying over 25 different vendor products. These best practices are a good starting point for creating a new product or service deployment plan or for verifying that existing deployments are secure. When you implement CIS Benchmarks, you can better secure your legacy systems against common and emerging risks by taking steps such as these: Disabling unused ports…

CIS Benchmarks example For example, admins can follow the step-by-step CIS AWS Foundations Benchmark guidelines to help them set up a strong password policy for AWS Identity and Access Management (IAM). Password policy enforcement, multi-factor authentication (MFA) usage, disabling root, ensuring access keys are rotated every 90 days, and other tactics are distinct, but related, identity guidelines to improve the security of an AWS account. By adopting CIS Benchmarks, your organization can gain several cybersecurity benefits, such as the following: Expert cybersecurity guidelines CIS Benchmarks provide organizations with a framework of security configurations that are expert-vetted and proven. Companies can avoid trial-and-error scenarios that put security at risk and benefit from the expertise of a diverse IT and cybersecurity community. Globally recognized security standards CIS Benchmarks are the only best practice guides that are globally recognized and accepted by governments, businesses, research, and academic institutions alike. Thanks to the global and diverse community that works on a consensus-based decision-making model, CIS Benchmarks have far wider applicability and acceptability than regional laws and security standards. Cost-effective threat prevention The CIS Benchmark documentation is freely available for anyone to download and implement. Your company can get up-to-date, step-by-step instructions for all kinds of IT systems at no cost. You can achieve IT governance and avert financial and reputational damage from preventable cyberthreats. Regulatory compliance CIS Benchmarks align with major security and data privacy frameworks such as these: National Institute of Standards and Technology (NIST) Cybersecurity Framework Health Insurance Portability and Accountability Act (HIPAA) Payment Card Industry Data Security Standard (PCI DSS) Implementing CIS Benchmarks is a big step toward achieving compliance for organizations that operate in heavily regulated industries. They can prevent compliance failures due to misconfigured IT systems. What types of IT systems do CIS Benchmarks cover?

CIS has published over 100 benchmarks that span 25+ vendor product families. When you apply and monitor CIS Benchmarks across all types of IT systems, you build an inherently secure IT environment that you can further defend with security solutions. Technologies that CIS Benchmarks cover can be broadly grouped into the following seven categories.

Operating systems CIS Benchmarks for operating systems provide standard security configurations for popular operating systems, including Amazon Linux. These benchmarks include best practices for features such as these: Operating system access control Group policies Web browser settings Patch management Cloud infrastructure and services CIS Benchmarks for cloud infrastructure provide security standards that companies can use to securely configure cloud environments, such as those provided by AWS. The guidelines include best-practice guidelines for virtual network settings, AWS Identity and Access Management (IAM) configurations, compliance and security controls, and more. Server software CIS benchmarks for server software provide configuration baselines and recommendations for server settings, server admin controls, storage settings, and server software from popular vendors. Desktop software CIS Benchmarks cover most of the desktop software that organizations typically use. The guidelines include best practices for managing desktop software features, such as these: Third-party desktop software Browser settings Access privileges User accounts Client device management Mobile devices CIS Benchmarks for mobile devices cover security configurations for operating systems that run on mobile phones, tablets, and other hand-held devices. They provide recommendations for mobile browser settings, application permissions, privacy settings, and more. Network devices CIS Benchmarks also provide security configurations for network devices such as firewalls, routers, switches, and virtual private networks (VPNs). They contain both vendor-neutral and vendor-specific recommendations to ensure the secure setup and management of these network devices. Multi-function print devices CIS Benchmarks for network peripherals such as multi-function printers, scanners, and photocopiers cover secure configuration best practices such as file sharing settings, access restrictions, and firmware updates. What are CIS Benchmark levels?

To help organizations achieve their unique security goals, the CIS assigns a profile level to each CIS Benchmark guideline. Each CIS profile includes recommendations that provide a different level of security. Organizations can choose a profile based on their security and compliance needs.

Level 1 profile Configuration recommendations for the Level 1 profile are basic security recommendations for configuring IT systems. They are easy to follow and do not impact business functionality or uptime. These recommendations reduce the number of entry points into your IT systems, thereby reducing your cybersecurity risks. Level 2 profile Level 2 profile configuration recommendations work best for highly sensitive data where security is a priority. Implementing these recommendations requires professional expertise and diligent planning to achieve comprehensive security with minimal disruptions. Implementing Level 2 profile recommendations also helps with achieving regulatory compliance. STIG profile The Security Technical Implementation Guide (STIG) is a set of configuration baselines from the Defense Information Systems Agency (DISA). The US Department of Defense publishes and maintains these security standards. STIGs are specifically written to meet US government requirements. CIS Benchmarks also specify a Level 3 STIG profile that is designed to help organizations comply with the STIG. The STIG profile contains Level 1 and Level 2 profile recommendations that are STIG-specific and provides more recommendations that the other two profiles do not cover but that are required by DISA’s STIGs. When you configure your systems according to the CIS STIG Benchmarks, your IT environment will be both CIS and STIG compliant. How are CIS Benchmarks developed?

CIS communities follow a unique consensus-based process to develop, approve, and maintain CIS Benchmarks for different target systems. Overall, the CIS Benchmark development process looks like this: The community identifies the need for a specific benchmark. They establish the scope of the benchmark. Volunteers create discussion threads on the CIS WorkBench community website. Experts from the specific IT system’s CIS community spend time reviewing and discussing the working draft. The experts create, discuss, and test their recommendations until they reach…

How can you implement CIS Benchmarks?

Each CIS Benchmark includes a description of the recommendation, the reason for the recommendation, and instructions that system admins can follow to implement the recommendation correctly. Each benchmark can consist of several hundred pages because it covers each area of the target IT system. Implementing CIS Benchmarks and keeping up with all the version releases gets complicated if you do it manually. That’s why many organizations use automated tools to monitor CIS compliance. The CIS also offers free and premium…

What other security resources are included with the CIS Benchmarks?

The CIS also publishes other resources to improve an organization’s internet security, including the following two main resources.

References

Add references, clinical guidelines, textbooks, journal articles, or trusted medical sources here. You can edit this area from the RX Article Professional Blocks panel.