Skip to main content

CIS Benchmarks

The Center for Internet Security (CIS) Benchmarks are the global standard and recognized best practices for securing IT systems and data against today's evolving cyber threats. Klarity ImageFactory uses these benchmarks as the foundation for its automated hardening process.

Understanding CIS Benchmarks​

CIS Benchmarks are developed through a unique consensus-based process involving a global community of cybersecurity professionals. They provide highly detailed, step-by-step configuration guidance for various operating systems, cloud providers, and software applications.

Level 1 vs. Level 2​

CIS Benchmarks are typically divided into two profiles:

  • Level 1 (L1): Intended to be practical and prudent, providing a clear security benefit without inhibiting the utility of the technology beyond acceptable means.
  • Level 2 (L2): Intended for environments where security is paramount. It includes all Level 1 controls plus additional, more restrictive settings that may have an impact on system performance or functionality.

Benchmark Categories​

A typical CIS Benchmark covers a wide range of system configuration areas. In ImageFactory, our hardening scripts address the following categories:

  1. Filesystem Configuration: Securing mount points, disabling unused filesystems, and setting proper permissions on system files.
  2. Software Updates: Ensuring that the system is configured to receive regular security updates and that package manager integrity is maintained.
  3. Filesystem Integrity Checking: Implementing tools like AIDE to monitor changes to critical system files.
  4. Boot Settings: Securing the bootloader (GRUB/LILO) and restricting access to single-user mode.
  5. Process Hardening: Enabling features like ASLR and restricting core dumps.
  6. Mandatory Access Control: Configuring and enforcing SELinux or AppArmor policies.
  7. Network Configuration: Disabling unused network protocols (e.g., IPv6 if not needed), securing the TCP/IP stack, and configuring firewall rules.
  8. Logging and Auditing: Setting up comprehensive system logging (rsyslog/journald) and audit rules (auditd) to track security-relevant events.
  9. System Access, Authentication, and Authorization: Securing SSH, configuring PAM, and enforcing strong password policies.
  10. User Environment: Setting secure default umasks and restricting access to system accounts.
  11. System Maintenance: Removing legacy services and ensuring that system file permissions are regularly audited.

Implementation Details​

ImageFactory maintains a library of hardening scripts tailored to each supported distribution.

Linux Implementation​

Linux hardening is built using Ansible, allowing us to maintain a high degree of consistency while accounting for the nuances of different Linux families (e.g., Debian vs. RedHat).

Windows Implementation​

Windows hardening utilizes Ansible playbooks that execute PowerShell tasks. These tasks interact with the Windows Registry and Group Policy Objects (GPOs) to apply the benchmark settings.

Implemented Rule Coverage​

ImageFactory maintains dedicated hardening tasks for every supported distribution and version below. Follow View rules to see the exact rule IDs and titles implemented for that distribution — grouped by CIS section, for both Level 1 and Level 2.

Linux​

DistributionLevel 1Level 2
Amazon Linux 2View rules✓
Amazon Linux 2023View rules✓
CentOS 7View rules✓
Oracle Linux 7View rules✓
Oracle Linux 8View rules✓
Oracle Linux 9View rules✓
RHEL 7View rules✓
RHEL 8View rules✓
RHEL 9View rules✓
RHEL 10View rules✓
Rocky Linux 8View rules✓
Rocky Linux 9View rules✓
SLES 12View rules✓
SLES 15View rules✓
Ubuntu 16.04View rules—
Ubuntu 18.04View rules✓
Ubuntu 20.04View rules✓
Ubuntu 22.04View rules✓
Ubuntu 24.04View rules✓

Windows​

DistributionLevel 1Level 2
Windows Server 2012 R2View rules✓
Windows Server 2016View rules✓
Windows Server 2019View rules✓
Windows Server 2022View rules✓
Windows Server 2025View rules✓
note

A rule listed as a documented exception for a given distribution is not always a rule ImageFactory chose to skip out of ones it otherwise automates. Many exceptions describe infrastructure-layer requirements outside the scope of an in-guest task entirely — for example, CIS rules requiring separate disk partitions for /home, /var, or /var/log depend on the base image's partition layout, not a setting ImageFactory's hardening scripts can apply.

Compliance Scoring and Reporting​

After an image build, ImageFactory performs an automated scan to verify compliance with the selected CIS profile.

  1. Scan Execution: A specialized scanning tool runs against the finalized image, checking every rule defined in the benchmark.
  2. Data Collection: The results are collected and processed to calculate the percentage of passed checks.
  3. Report Generation: ImageFactory generates a comprehensive JSON report for machine consumption and a formatted PDF report for human review.
  4. Score Storage: The final compliance scores (Level 1 and Level 2) are stored with the image metadata and can be viewed in the ImageFactory UI or retrieved via the API.