Definition · Security Headers

What is CIS Benchmarks?

CIS Benchmarks are published by the Center for Internet Security (CIS), a US non-profit. Each benchmark is a detailed configuration guide for one technology — a Linux distribution, Windows Server, a cloud provider, a web server, a database, a browser, a network device — developed through a community consensus process with vendors and practitioners, and revised as the technology changes.

Structure and profile levels

Recommendations are individually written with a rationale, an audit procedure and remediation steps, which is what makes them usable as evidence rather than advice. They are grouped into profiles:

  • Level 1 — settings that improve security with limited risk of breaking normal function
  • Level 2 — stricter settings for environments needing defence in depth, accepting reduced functionality or compatibility

Some benchmarks add specialised profiles, for example for domain controllers or for particular server roles. CIS also publishes hardened images and the separate CIS Critical Security Controls, which are a prioritised control set rather than per-technology configuration guidance.

How they relate to external exposure

Benchmarks are host-level guidance applied from the inside, so they are not a substitute for looking at your perimeter — but a significant share of what external scanning finds is a benchmark recommendation that was never applied. Weak TLS versions and cipher suites, missing security headers, directory listing left enabled, verbose version banners exposed to banner grabbing, management services listening on public interfaces and unchanged default credentials all appear in the relevant benchmarks.

The gap that matters is coverage. Benchmarks get applied to the servers a team knows about, so shadow IT and forgotten hosts drift furthest from the standard while looking compliant on paper.

Benchmarks are often cited as the implementation detail behind ISO 27001 configuration controls, Cyber Essentials secure configuration and PCI DSS hardening requirements. See also security misconfiguration and least privilege.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.