CIS Benchmark
Also known as CIS hardening guide, CIS configuration baseline
A CIS Benchmark is a consensus-based, prescriptive configuration guideline published by the Center for Internet Security that defines secure-by-default settings for an operating system, cloud service, or application.
CIS Benchmarks are developed by global cybersecurity practitioners and refined through community review. Each benchmark contains hundreds of individual controls covering authentication, audit logging, network configuration, services, and registry or filesystem hardening. Benchmarks are versioned (for example Windows 11 v5.0.0) and published with two profile levels: Level 1 for general-purpose systems and Level 2 for sensitive environments. CISGuard supports 22 CIS Benchmarks covering Windows, Linux, cloud, container, browser, database and web platforms, with a total of 3,933 security controls.
CIS ControlsHardening BaselineConfiguration Drift
CIS Controls
CIS Controls are a set of 18 prioritized cybersecurity safeguards published by the Center for Internet Security to help organizations defend against the most common attack patterns.
CIS Controls v8 organize 153 safeguards across 18 control categories, from inventory of enterprise assets to penetration testing, and are mapped to NIST CSF, ISO 27001 and other frameworks. CIS Benchmarks operationalize many CIS Controls at the configuration level, and CISGuard’s continuous benchmark scans provide the configuration evidence that sits behind them.
CIS BenchmarkNIST CSFISO 27001
Configuration Drift
Also known as Config drift, Baseline drift
Configuration drift is the gradual divergence of a system’s actual configuration from its intended secure baseline, caused by patches, deployments, troubleshooting changes, or scaling.
Drift is the dominant reason "compliant" systems become non-compliant between audits. Common drivers include patch deployments that reset audit policies, application installs that open firewall ports, troubleshooting sessions where security controls are disabled and not re-enabled, and new instances spun from outdated templates. Organizations typically see meaningful drift within weeks of any hardening exercise. Continuous compliance monitoring exists specifically to detect drift as it happens rather than at the next audit.
Drift DetectionHardening BaselineContinuous Compliance Monitoring
Drift Detection
Drift detection is the process of continuously comparing a system’s current configuration against its hardened baseline and alerting when controls regress.
Effective drift detection categorizes changes as regressions (a previously passing control now fails), improvements (a previously failing control now passes), or new controls (added to the benchmark in a newer version). CISGuard performs drift detection by comparing every scan against the previous baseline scan and dispatching alerts by email, to your SIEM, or to a signed webhook within minutes of a regression.
Configuration DriftContinuous Compliance MonitoringHardening Baseline
Continuous Compliance Monitoring
Continuous compliance monitoring replaces point-in-time audits with automated, scheduled scans that maintain real-time visibility of an organization’s compliance posture.
Continuous monitoring is required for SOC 2 Type II (controls operating over a period), DORA Article 10 (ICT-related incident detection), and is strongly recommended by NIST SP 800-137. Implementations typically combine scheduled benchmark scanning, drift detection between scans, real-time dashboards, alert fan-out to SIEM and notification channels, and historical trend retention. CISGuard implements all of these with on-premises deployment and air-gapped support.
Drift DetectionSOC 2 Type IINIST SP 800-137
Hardening Baseline
A hardening baseline is the documented set of secure configuration values an organization commits to maintaining across its systems, typically derived from a CIS Benchmark.
A baseline is more than a one-time snapshot. It is the contract every system is measured against. Mature programs version their baseline to match the underlying CIS Benchmark version, document approved exceptions with compensating controls and expiry dates, and review it quarterly. CISGuard takes its baseline from the CIS Benchmark, tracks per-system deviation, and automatically recalculates compliance posture when exceptions expire.
CIS BenchmarkConfiguration DriftException Management
Compliance Automation
Compliance automation is the use of software to continuously evaluate, evidence, and report on technical controls required by regulatory frameworks, replacing manual checklists, screenshots, and spreadsheet reviews.
Compliance automation typically targets the technical-control layer of a GRC program: secure configuration, audit logging, access reviews and change tracking. It does not replace policy, procedure or training controls. CISGuard automates the technical-control layer specifically for CIS Benchmark compliance, with mappings to NIST 800-53, ISO 27001 and SOC 2, and the same evidence supports the sector regulations built on those frameworks.
CIS BenchmarkGRCMulti-Framework Mapping
Air-Gapped Deployment
Also known as Air-gap, Offline deployment, Disconnected deployment
Air-gapped deployment is installation of a software system inside a network that has no direct or indirect connection to the public internet.
Air-gapped environments are common in defence, government, financial services, energy and healthcare. Software intended for air-gapped use must support offline installation, offline benchmark and signature updates (typically via portable media), no telemetry callbacks, and full functionality without DNS or NTP to the public internet. CISGuard is designed for air-gapped deployment: a single offline installer covers all platforms, benchmark updates can be sideloaded, and no scan data leaves the customer’s network.
On-Premises DeploymentData Sovereignty
Multi-Framework Mapping
Multi-framework mapping is the practice of producing compliance evidence for multiple frameworks (for example NIST 800-53, ISO 27001 and SOC 2) from a single underlying configuration scan.
Most organizations need to evidence the same control (say, audit logging) against several frameworks simultaneously. Multi-framework mapping eliminates duplicate scanning by tagging each CIS control with the corresponding NIST, ISO and SOC 2 references, then generating per-framework reports from one underlying dataset. CISGuard maps to three frameworks from one scan: 50 NIST 800-53 controls across 13 control families, 36 ISO 27001:2022 Annex A controls, and 25 SOC 2 Trust Services Criteria.
NIST 800-53ISO 27001SOC 2
Exception Management
Also known as Waiver management, Risk acceptance workflow
Exception management is the formal workflow used to document, approve, and time-bound deviations from a security baseline that cannot be remediated immediately.
Exceptions exist because real environments occasionally need to deviate from policy: a legacy application that requires TLS 1.0, a server that cannot be patched until a vendor update ships. Mature exception management requires documented business justification, approved compensating controls, a designated approver, an expiry date and a tamper-evident audit trail. CISGuard implements all five: requesters submit justification, approvers review and decide, exceptions auto-expire on a set date, the compliance score recalculates automatically, and every action is logged with user, IP address and timestamp.
Hardening BaselineAudit Trail