Security Basics mailing list archives
Re: CIS benchmarks
From: Mike Mychalczuk <Michael.Mychalczuk () netiq com>
Date: Thu, 26 May 2011 22:30:39 +0000
The CIS benchmarks are industry standards. How the benchmarks are developed is through consensus and collaboration with Subject Matter Experts, practitioners, and system administrators. In addition any regulatory stand / practice where applicable are also incorporated for consideration. There are 3 levels of benchmarks. Level 1 is the minimum and the governing principal is that it will not break production. Level 3 is the most hardened and usually they will break a production installation unless due dilligence has been done ahead of time. The fundamental principal was to establish a basic set of "due care" baselines so that organizations would have a credible and repuable place to begin in establishing configurartion policies. The benchmarks are used by IT organizations globally and the center is supported by both vendors, businesses, and individual contributors through yearly subscriptions. The center was launched in partnership with SANS as well as a number of founding security software vendors. I hope this helps. Mike ----- Original Message ----- From: Saif El Sherei [mailto:SSherei () npcegypt com] Sent: Thursday, May 26, 2011 04:12 PM To: Catelijne van Antwerpen <cvanantwerpen () mirabeau nl> Cc: security-basics () securityfocus com <security-basics () securityfocus com> Subject: Re: CIS benchmarks CIS are one of the best sources for security benchmarks along with NIST CIS standards are recommend by allot of security standards like PCI-DSS. Regards, Saif OSCP Sent from my iPhone. On May 27, 2011, at 12:58 AM, "Catelijne van Antwerpen" <cvanantwerpen () mirabeau nl> wrote:
Hi, I'm investigating some standard install procedures with the focus on security. On the internet I stumbled upon CIS (Center for Internet Security). http://www.cisecurity.org/index.cfm The have put together a lot of security benchmarks for different kinds of products. It looks good at first sight, but I don't how well this organization is known by the community. Do you know whether these benchmarks are being used frequently? Or do you guys use other benchmarks/listen to other authorities? Cheers, Cat. Catelijne van Antwerpen Applicatiebeheerder Mirabeau | Managed Services H.J.E. Wenckebachweg 108, 1096 AR Amsterdam +31(0)20-5950550 - www.mirabeau.nl Parttime: oneven weken op woensdag afwezig. Please consider the environment before printing this email ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------ ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
Current thread:
- CIS benchmarks Catelijne van Antwerpen (May 26)
- Re: CIS benchmarks Saif El Sherei (May 26)
- Re: CIS benchmarks Mike Mychalczuk (May 26)
- Re: CIS benchmarks Saif El Sherei (May 26)