Service · CIS · SVC-05

CIS Benchmark Assessment.

Configuration hardening reviews against the latest CIS benchmarks - OS, database, container and cloud baselines, mapped to your control framework.

2 weeks Fixed quote Manual-first methodology
CIS L1 / L2
Both profiles
25+
Benchmark coverage
10 days
Typical delivery
Methodology

Three approaches. One uncompromising standard.

Choose the depth of engagement that matches your risk profile and reporting needs.

Level 1

CIS Level 1

The recommended starting baseline - controls that materially reduce risk with minimal operational impact.

  • Account & authentication hygiene
  • Service hardening
  • Logging & audit defaults
  • Patch & update enforcement
Level 2

CIS Level 2

Defence-in-depth controls for environments handling regulated data or operating under elevated risk.

  • L1 controls in full
  • Cryptographic hardening
  • Network segmentation enforcement
  • Mandatory-access-control review
Custom

Custom mapping

CIS coverage mapped to your applicable framework (ISO 27001, SOC 2, PCI-DSS, HIPAA) with audit-ready evidence.

  • ISO 27001 / SOC 2 mapping
  • PCI-DSS scope alignment
  • HIPAA control crosswalk
  • Evidence pack for auditors
What we cover

The full surface - tested manually.

01Linux & Windows OS baselines
02Database baselines (MySQL, PostgreSQL, MSSQL)
03Container & Kubernetes baselines
04Cloud Foundations (AWS, Azure, GCP)
05Web servers & middleware
06Remediation playbooks per control
Engagement variants

Four ways to scope this service.

OS

OS Baselines

Hardening review of Linux distributions and Windows Server fleets against CIS OS benchmarks.

  • Ubuntu / RHEL / Debian baselines
  • Windows Server 2019/2022
  • Domain & workgroup configurations
Data

Database Baselines

Configuration review for relational database deployments handling sensitive data.

  • PostgreSQL / MySQL benchmarks
  • SQL Server & Oracle baselines
  • Authentication & encryption coverage
K8s

Container & Kubernetes

Container runtime and cluster benchmarks - EKS, AKS, GKE and self-hosted.

  • Docker / containerd baselines
  • Kubernetes Benchmark coverage
  • Pod Security Admission review
Cloud

Cloud Foundations

AWS, Azure and GCP CIS Foundations Benchmarks - the baseline auditors expect.

  • AWS Foundations Benchmark
  • Azure Foundations Benchmark
  • GCP Foundations Benchmark
The process

Six clearly-defined phases.

From scoping call to remediated environment - each step has a deliverable, a check-in and a documented owner.

01
Define Scope

Goals, asset inventory, RoE and success criteria.

02
Information Gathering

Recon, fingerprinting and threat modelling.

03
Identification

Vulnerability discovery and validation.

04
Attack & Penetration

Manual exploitation & chain analysis.

05
Reporting

Executive & technical deliverables.

06
Remediation Support

Fix guidance & debrief session.

Why it matters

Outcomes you can measure.

Level 1 & Level 2

Choose the right profile per asset.

Audit-ready evidence

Control-by-control attestation.

Playbook delivery

Step-by-step remediation per finding.

Continuous re-baseline

Optional quarterly refresh.

What you receive

Deliverables.

Executive summary

Board-ready overview - risk posture, business impact, recommended priorities.

Technical report

Every finding with reproduction steps, evidence, CVSS & business-impact scores.

Remediation tracker

Jira / Linear-ready issue list with severity, owner and acceptance criteria.

Frequently asked

About cis benchmark assessment.

Is this a compliance audit?
Not a formal audit, but the output is audit-ready evidence - mapped to your applicable frameworks.
Do you implement the fixes?
We deliver the playbooks; implementation can be handled by your team or as a separate engagement.
Which benchmark versions do you use?
Always the latest CIS release at engagement start, with version-pinning documented in the report.
Can you scan continuously?
Yes - a quarterly refresh can be folded into a Managed Security engagement so the baseline never drifts.
Do you cover custom internal baselines?
Yes. We start from CIS as the reference, then map your internal control set on top so both are reported.
SVC-05

Let's scope your cis benchmark assessment.

A 30-minute call. A fixed quote within two business days.