How do the CIS benchmarks here map to the ones published by CIS? #6893
Replies: 4 comments 8 replies
-
Hello @alexhaydock , currently CIS profiles do not distinguish among various CIS mappings at all. I believe you could use CIS references to keep track of levels, but I understand this is not what you want. |
Beta Was this translation helpful? Give feedback.
-
Great to hear that. You can see ANSSI definitions here, it should be prety self-explanatory. |
Beta Was this translation helpful? Give feedback.
-
@alexhaydock Hi.. I am new to ComplianceAsCode and would like to contribute.. please let me know if you need any help with the work you were planning to start |
Beta Was this translation helpful? Give feedback.
-
@alexhaydock and @gunchamalik , thanks for the interest and participation. |
Beta Was this translation helpful? Give feedback.
-
I've been looking at the CIS benchmarks provided here and I'm struggling to understand or find any documentation about how they map to the benchmarks published by CIS.
CIS publishes 4 different levels of benchmark (at least for RHEL, which is what I've been testing with):
Can anyone help me understand how the one "unified" CIS benchmark file maps to the published standards?
Is there any appetite to expand coverage to the Level 2 benchmarks in future?
Beta Was this translation helpful? Give feedback.
All reactions