Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CIS Benchhmark By Level #21

Open
Jsitech opened this issue Dec 4, 2018 · 0 comments
Open

CIS Benchhmark By Level #21

Jsitech opened this issue Dec 4, 2018 · 0 comments
Assignees

Comments

@Jsitech
Copy link
Owner

Jsitech commented Dec 4, 2018

What are the Level 1 and Level 2 Profiles within a CIS Benchmark?
Most CIS Benchmarks include multiple configuration profiles. A profile definition describes the configurations assigned to benchmark recommendations.

The Level 1 profile is considered a base recommendation that can be implemented fairly promptly and is designed to not have an extensive performance impact. The intent of the Level 1 profile benchmark is to lower the attack surface of your organization while keeping machines usable and not hindering business functionality.

The Level 2 profile is considered to be "defense in depth" and is intended for environments where security is paramount. The recommendations associated with the Level 2 profile can have an adverse effect on your organization if not implemented appropriately or without due care.

Every recommendation within each CIS Benchmark is associated with at least one profile. Regardless of which level profile you plan to implement in your environment, we recommend applying CIS Benchmark guidance in a test environment first to determine potential impact.

Will separate the Steps run by Jshielder CIS by levels, this will give the user some flexibility. For level 2 , given that the Steps may be a little restrictive, most of them will have description and the user may choose not to run them depending on their environment.

@Jsitech Jsitech self-assigned this Dec 4, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant