Skip to content

Compliance & frameworks

CIS Benchmarks

CIS Benchmarks for AWS, Azure & GCP

CIS Benchmarks are the consensus configuration baselines for cloud, published by the Center for Internet Security and written by a global community of practitioners. There are dedicated Foundations Benchmarks for AWS, Azure, and Google Cloud — each a detailed, versioned checklist of how to configure identity, logging, networking, and storage securely. Because the recommendations are specific and measurable, CIS Benchmarks are the technical baseline that sits underneath broader frameworks: the concrete settings that an auditor's abstract control actually resolves to.

Who it applies to

CIS Benchmarks are voluntary — no law mandates them. But they are among the most widely adopted technical baselines in cloud security: other frameworks and programs (PCI-DSS, FedRAMP, and the NIST catalogs) reference or map to them, and many enterprises and cyber insurers make CIS conformance a vendor expectation. If leadership asks whether your cloud is configured to a recognized standard, CIS is usually the standard they mean.

Cloud control themes

What CIS Benchmarks asks of your cloud

  • Identity & access baseline — root/owner account protection, MFA, access-key rotation, and password policy
  • Logging baseline — multi-region CloudTrail, Azure Activity Log diagnostic settings, and GCP Cloud Audit Logs enabled, centralized, and retained
  • Monitoring & alerting — metric filters and alarms for high-risk account events
  • Networking baseline — restricted default security groups, NSGs, and firewall rules; no unrestricted access to admin ports; flow logs enabled
  • Storage & encryption baseline — block public access, enforce encryption at rest, and manage keys correctly

Domain × framework

Which assessment domains produce CIS Benchmarks evidence

Assessment domainHow it maps
Configuration & postureDirect benchmark drift measurement — every account, subscription, and project scored against the CIS recommendations that apply to it. This is the domain CIS maps to most directly.
Identity & accessThe IAM section of each benchmark — root/owner MFA, access-key rotation, and password policy — maps straight to identity findings.
Data securityStorage recommendations — S3 Block Public Access, Azure Storage secure transfer, GCS bucket exposure, and encryption at rest — evidence the data-security baseline.
Network exposureNetworking recommendations — restricted default security groups and NSGs, no 0.0.0.0/0 on management ports, and enabled flow logs — evidence the network baseline.
Logging & monitoringLogging & monitoring recommendations — CloudTrail, Azure diagnostic settings, GCP Cloud Audit Logs, and metric-based alerting — map to the logging baseline.
Framework mappingCIS crosswalks let a single benchmark finding show where you also satisfy — or miss — the SOC 2, PCI-DSS, or NIST control that recommendation underpins.

What you get

A CIS-mapped posture report that scores every account, subscription, and project against the relevant Foundations Benchmark for its provider. Findings are grouped by benchmark section, assessed against CIS Level 1 by default with Level 2 flagged where your risk warrants the added friction, and ranked so your team closes the settings that matter most first — not just the longest list. The assessment is read-only readiness evidence: it measures your environment and hands you the ranked gaps, and nothing is changed in production.

Most relevant to: FinTech, Healthcare, Commercial real estate

Questions

Which CIS level do you assess against?

We assess against CIS Level 1 by default — the broadly applicable hardening that rarely breaks functionality — and flag Level 2 recommendations where a workload's sensitivity justifies the added restriction. You decide how far to take Level 2.

Are CIS Benchmarks the same as the CIS Controls?

No. The Benchmarks are per-technology configuration checklists — the AWS, Azure, and GCP Foundations Benchmarks we assess. The CIS Controls are 18 higher-level, program-wide security controls. This assessment measures your cloud against the Benchmarks; the Controls are a broader program conversation.

Do you certify our CIS conformance?

No — CIS Benchmarks carry no certification, and conformance is self-attested. We measure your environment against the benchmark, hand you the ranked gaps with a remediation order, and give you evidence you can show auditors and insurers. The assessment is read-only — nothing is changed in production.

Framework work in practice

Evidence rooms and compliance tables

Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.

Take free readiness check