Compliance & frameworks
CIS Benchmarks
CIS Benchmarks for AWS, Azure & GCP
CIS Benchmarks are the consensus configuration baselines for cloud, published by the Center for Internet Security and written by a global community of practitioners. There are dedicated Foundations Benchmarks for AWS, Azure, and Google Cloud — each a detailed, versioned checklist of how to configure identity, logging, networking, and storage securely. Because the recommendations are specific and measurable, CIS Benchmarks are the technical baseline that sits underneath broader frameworks: the concrete settings that an auditor's abstract control actually resolves to.
Who it applies to
CIS Benchmarks are voluntary — no law mandates them. But they are among the most widely adopted technical baselines in cloud security: other frameworks and programs (PCI-DSS, FedRAMP, and the NIST catalogs) reference or map to them, and many enterprises and cyber insurers make CIS conformance a vendor expectation. If leadership asks whether your cloud is configured to a recognized standard, CIS is usually the standard they mean.
Cloud control themes
What CIS Benchmarks asks of your cloud
- Identity & access baseline — root/owner account protection, MFA, access-key rotation, and password policy
- Logging baseline — multi-region CloudTrail, Azure Activity Log diagnostic settings, and GCP Cloud Audit Logs enabled, centralized, and retained
- Monitoring & alerting — metric filters and alarms for high-risk account events
- Networking baseline — restricted default security groups, NSGs, and firewall rules; no unrestricted access to admin ports; flow logs enabled
- Storage & encryption baseline — block public access, enforce encryption at rest, and manage keys correctly
Domain × framework
Which assessment domains produce CIS Benchmarks evidence
| Assessment domain | How it maps |
|---|---|
| Configuration & posture | Direct benchmark drift measurement — every account, subscription, and project scored against the CIS recommendations that apply to it. This is the domain CIS maps to most directly. |
| Identity & access | The IAM section of each benchmark — root/owner MFA, access-key rotation, and password policy — maps straight to identity findings. |
| Data security | Storage recommendations — S3 Block Public Access, Azure Storage secure transfer, GCS bucket exposure, and encryption at rest — evidence the data-security baseline. |
| Network exposure | Networking recommendations — restricted default security groups and NSGs, no 0.0.0.0/0 on management ports, and enabled flow logs — evidence the network baseline. |
| Logging & monitoring | Logging & monitoring recommendations — CloudTrail, Azure diagnostic settings, GCP Cloud Audit Logs, and metric-based alerting — map to the logging baseline. |
| Framework mapping | CIS crosswalks let a single benchmark finding show where you also satisfy — or miss — the SOC 2, PCI-DSS, or NIST control that recommendation underpins. |
What you get
A CIS-mapped posture report that scores every account, subscription, and project against the relevant Foundations Benchmark for its provider. Findings are grouped by benchmark section, assessed against CIS Level 1 by default with Level 2 flagged where your risk warrants the added friction, and ranked so your team closes the settings that matter most first — not just the longest list. The assessment is read-only readiness evidence: it measures your environment and hands you the ranked gaps, and nothing is changed in production.
Most relevant to: FinTech, Healthcare, Commercial real estate
Questions
Which CIS level do you assess against?
We assess against CIS Level 1 by default — the broadly applicable hardening that rarely breaks functionality — and flag Level 2 recommendations where a workload's sensitivity justifies the added restriction. You decide how far to take Level 2.
Are CIS Benchmarks the same as the CIS Controls?
No. The Benchmarks are per-technology configuration checklists — the AWS, Azure, and GCP Foundations Benchmarks we assess. The CIS Controls are 18 higher-level, program-wide security controls. This assessment measures your cloud against the Benchmarks; the Controls are a broader program conversation.
Do you certify our CIS conformance?
No — CIS Benchmarks carry no certification, and conformance is self-attested. We measure your environment against the benchmark, hand you the ranked gaps with a remediation order, and give you evidence you can show auditors and insurers. The assessment is read-only — nothing is changed in production.
Framework work in practice
Evidence rooms and compliance tables
Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.





