Security Basics mailing list archives

Re: CIS benchmarks


From: Mike Mychalczuk <Michael.Mychalczuk () netiq com>
Date: Thu, 26 May 2011 22:30:39 +0000

The CIS benchmarks are industry standards.  How the benchmarks are developed is through consensus and collaboration 
with Subject Matter Experts, practitioners, and system administrators.  In addition any regulatory stand / practice 
where applicable are also incorporated for consideration.  There are 3 levels of benchmarks.  Level 1 is the minimum 
and the governing principal is that it will not break production.  Level 3 is the most hardened and usually they will 
break a production installation unless due dilligence has been done ahead of time.

The fundamental principal was to establish a basic set of "due care" baselines so that organizations would have a 
credible and repuable place to begin in establishing configurartion policies.  The benchmarks are used by IT 
organizations globally and the center is supported by both vendors, businesses, and individual contributors through 
yearly subscriptions. The center was launched in partnership with SANS as well as a number of founding security 
software vendors.

I hope this helps.

Mike

----- Original Message -----
From: Saif El Sherei [mailto:SSherei () npcegypt com]
Sent: Thursday, May 26, 2011 04:12 PM
To: Catelijne van Antwerpen <cvanantwerpen () mirabeau nl>
Cc: security-basics () securityfocus com <security-basics () securityfocus com>
Subject: Re: CIS benchmarks

CIS are one of the best sources for security benchmarks along with NIST

CIS standards are recommend by allot of security standards like PCI-DSS. 

Regards,

Saif
OSCP

Sent from my iPhone. 

On May 27, 2011, at 12:58 AM, "Catelijne van Antwerpen" <cvanantwerpen () mirabeau nl> wrote:

Hi,

I'm investigating some standard install procedures with the focus on security.
On the internet I stumbled upon CIS (Center for Internet Security).
http://www.cisecurity.org/index.cfm
The have put together a lot of security benchmarks for different kinds of products.
It looks good at first sight, but I don't how well this organization is known by the community.

Do you know whether these benchmarks are being used frequently?
Or do you guys use other benchmarks/listen to other authorities?

Cheers,


Cat.


Catelijne van Antwerpen
Applicatiebeheerder




Mirabeau | Managed Services    H.J.E. Wenckebachweg 108, 1096 AR Amsterdam
+31(0)20-5950550  -  www.mirabeau.nl
Parttime: oneven weken op woensdag afwezig.


Please consider the environment before printing this email

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, 
how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, 
purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for 
set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital 
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------




------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: