# CIS (Windows) Benkmarks

**URL:** <https://discourse.chef.io/t/cis-windows-benkmarks/6933>\
**Category:** Chef Infra (archive)\
**Created:** [September 28, 2015, 2:43pm UTC](https://discourse.chef.io/t/cis-windows-benkmarks/6933 "2015-09-28T14:43:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hippiehacker](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/hippiehacker/32/1469_2.png) [@hippiehacker](https://discourse.chef.io/u/hippiehacker)\
**Post date:** [September 28, 2015, 2:43pm UTC](https://discourse.chef.io/t/cis-windows-benkmarks/6933/1 "2015-09-28T14:43:02Z")

</div>

CIS puts out security benchmarks and guides to ensure compliance to a  
’hardened’ os from the base put out by the OS vendors. Is anyone seen  
any efforts within the chef community to create a security policy  
cookbook that checks for compliance against these (or similar)  
standards? I’m thinking of picking something like this up, but it’s a  
large undertaking and would interest from more than just one customer  
to fund it.

Windows Benchmarks:

[https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.os.windows](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.os.windows)

Linux Benchmarks:

> **[CIS Benchmarks Landing Page](https://learn.cisecurity.org/benchmarks?category=benchmarks.os.linux)**
>
> The CIS Benchmarks are secure configuration settings for over 100 technologies, available as a free PDF download.

Database Benchmarks:

> **[CIS Benchmarks Landing Page](https://learn.cisecurity.org/benchmarks?category=benchmarks.servers.database)**
>
> The CIS Benchmarks are secure configuration settings for over 100 technologies, available as a free PDF download.

MSSQL Benchmarks:

[https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.servers.database.mssql](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.servers.database.mssql)

(One of my current customers would benefit from Windows 2012r2 + MSSQL  
security policy cookbooks)

---

<div class="post-metadata">

**Author:** ![Galen\_Emery1](https://avatars.discourse-cdn.com/v4/letter/g/46a35a/32.png) [@Galen\_Emery1](https://discourse.chef.io/u/Galen_Emery1)\
**Post date:** [September 28, 2015, 3:01pm UTC](https://discourse.chef.io/t/cis-windows-benkmarks/6933/2 "2015-09-28T15:01:40Z")

</div>

Chris,

There's a bunch of work on the audit-cis cookbook. I'd recommend there as  
a starting point.

> **[GitHub - chef-boneyard/audit-cis: DEPRECATED: Recipes to perform chef audit...](https://github.com/chef-boneyard/audit-cis)**
>
> DEPRECATED: Recipes to perform chef audit mode check for CIS Benchmarks - GitHub - chef-boneyard/audit-cis: DEPRECATED: Recipes to perform chef audit mode check for CIS Benchmarks

On Mon, Sep 28, 2015 at 10:43 AM, Chris McClimans [chef@hippiehacker.org](mailto:chef@hippiehacker.org)  
wrote:

> CIS puts out security benchmarks and guides to ensure compliance to a  
> 'hardened' os from the base put out by the OS vendors. Is anyone seen  
> any efforts within the chef community to create a security policy  
> cookbook that checks for compliance against these (or similar)  
> standards? I'm thinking of picking something like this up, but it's a  
> large undertaking and would interest from more than just one customer  
> to fund it.
> 
> Windows Benchmarks:
> 
> [CIS Benchmarks](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.os.windows)
> 
> Linux Benchmarks:
> 
> [CIS Benchmarks](https://benchmarks.cisecurity.org/downloads/browse/index.cfm?category=benchmarks.os.linux)
> 
> Database Benchmarks:
> 
> [CIS Benchmarks](https://benchmarks.cisecurity.org/downloads/browse/index.cfm?category=benchmarks.servers.database)
> 
> MSSQL Benchmarks:
> 
> [CIS Benchmarks](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.servers.database.mssql)
> 
> (One of my current customers would benefit from Windows 2012r2 + MSSQL  
> security policy cookbooks)

---

<div class="post-metadata">

**Author:** ![hippiehacker](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/hippiehacker/32/1469_2.png) [@hippiehacker](https://discourse.chef.io/u/hippiehacker)\
**Post date:** [September 28, 2015, 3:03pm UTC](https://discourse.chef.io/t/cis-windows-benkmarks/6933/3 "2015-09-28T15:03:54Z")

</div>

Thanks Galen!

Access to the Audit-Tool would be useful during development

> **[CIS Benchmarks™](https://www.cisecurity.org/cis-benchmarks)**
>
> CIS Benchmarks help you safeguard systems, software, and networks against today's evolving cyber threats.

I'll reach out to CIS to see if I can get some assistance there.

On Mon, Sep 28, 2015 at 11:01 AM, Galen Emery [galen@chef.io](mailto:galen@chef.io) wrote:

> Chris,
> 
> There's a bunch of work on the audit-cis cookbook. I'd recommend there as a  
> starting point.
> 
> [GitHub - chef-boneyard/audit-cis: DEPRECATED: Recipes to perform chef audit mode check for CIS Benchmarks](https://github.com/chef-cookbooks/audit-cis)
> 
> On Mon, Sep 28, 2015 at 10:43 AM, Chris McClimans [chef@hippiehacker.org](mailto:chef@hippiehacker.org)  
> wrote:
> 
> > CIS puts out security benchmarks and guides to ensure compliance to a  
> > 'hardened' os from the base put out by the OS vendors. Is anyone seen  
> > any efforts within the chef community to create a security policy  
> > cookbook that checks for compliance against these (or similar)  
> > standards? I'm thinking of picking something like this up, but it's a  
> > large undertaking and would interest from more than just one customer  
> > to fund it.
> > 
> > Windows Benchmarks:
> > 
> > [CIS Benchmarks](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.os.windows)
> > 
> > Linux Benchmarks:
> > 
> > [CIS Benchmarks](https://benchmarks.cisecurity.org/downloads/browse/index.cfm?category=benchmarks.os.linux)
> > 
> > Database Benchmarks:
> > 
> > [CIS Benchmarks](https://benchmarks.cisecurity.org/downloads/browse/index.cfm?category=benchmarks.servers.database)
> > 
> > MSSQL Benchmarks:
> > 
> > [CIS Benchmarks](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.servers.database.mssql)
> > 
> > (One of my current customers would benefit from Windows 2012r2 + MSSQL  
> > security policy cookbooks)

---

<div class="post-metadata">

**Author:** ![stuartpreston](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/stuartpreston/32/1771_2.png) [@stuartpreston](https://discourse.chef.io/u/stuartpreston)\
**Post date:** [September 28, 2015, 3:12pm UTC](https://discourse.chef.io/t/cis-windows-benkmarks/6933/4 "2015-09-28T15:12:33Z")

</div>

Hi Chris,

The Chef community already has started down the path with CIS - you should check out the following for background:

[https://supermarket.chef.io/cookbooks/audit-cis](https://supermarket.chef.io/cookbooks/audit-cis)

> **[Chef Audit Mode: CIS Benchmarks - Chef Blog](https://blog.chef.io/2015/04/09/chef-audit-mode-cis-benchmarks/)**
>
> Today we’ve released an initial version of audit-cis. This is an “audit mode only” cookbook that runs on a node to check for compliance with The Center for Internet Security (CIS) benchmark for a specific platform. This release targets CentOS 7, CIS...

As far as I know there is no single community-maintained version of the Windows variant of CIS benchmarks yet.

Like you, we have spoken to a number of customers interested in creating something but the reality is that a decent compliance and auditing approach is something that needs to carefully designed with the customer’s own regulatory requirements and feedback mechanisms in mind. I would be interested in collaborating on a shared approach, the current mechanism uses Serverspec and Rspec as its approach, there may be alternative approaches that are more suitable depending on the type of test taking place.

Stuart

-----Original Message-----  
From: [chris@hippiehacker.org](mailto:chris@hippiehacker.org) [[mailto:chris@hippiehacker.org](mailto:chris@hippiehacker.org)] On Behalf Of Chris McClimans  
Sent: 28 September 2015 15:43  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] CIS (Windows) Benkmarks

CIS puts out security benchmarks and guides to ensure compliance to a ‘hardened’ os from the base put out by the OS vendors. Is anyone seen any efforts within the chef community to create a security policy cookbook that checks for compliance against these (or similar) standards? I’m thinking of picking something like this up, but it’s a large undertaking and would interest from more than just one customer to fund it.

Windows Benchmarks:

[https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.os.windows](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.os.windows)

Linux Benchmarks:

> **[CIS Benchmarks Landing Page](https://learn.cisecurity.org/benchmarks?category=benchmarks.os.linux)**
>
> The CIS Benchmarks are secure configuration settings for over 100 technologies, available as a free PDF download.

Database Benchmarks:

> **[CIS Benchmarks Landing Page](https://learn.cisecurity.org/benchmarks?category=benchmarks.servers.database)**
>
> The CIS Benchmarks are secure configuration settings for over 100 technologies, available as a free PDF download.

MSSQL Benchmarks:

[https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.servers.database.mssql](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.servers.database.mssql)

(One of my current customers would benefit from Windows 2012r2 + MSSQL security policy cookbooks)

---

<div class="post-metadata">

**Author:** ![Sean\_Farrow1](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@Sean\_Farrow1](https://discourse.chef.io/u/Sean_Farrow1)\
**Post date:** [September 28, 2015, 3:15pm UTC](https://discourse.chef.io/t/cis-windows-benkmarks/6933/5 "2015-09-28T15:15:33Z")

</div>

Hi,

Likewise, coming at it from a customer’s prospective, I['d be interested in collaborating as audition and compliance is a big part of our project.  
Cheers  
Sean.

-----Original Message-----  
From: Stuart Preston [[mailto:stuart@pendrica.com](mailto:stuart@pendrica.com)]  
Sent: 28 September 2015 16:13  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] RE: CIS (Windows) Benkmarks

Hi Chris,

The Chef community already has started down the path with CIS - you should check out the following for background:

[https://supermarket.chef.io/cookbooks/audit-cis](https://supermarket.chef.io/cookbooks/audit-cis)

> **[Chef Audit Mode: CIS Benchmarks - Chef Blog](https://blog.chef.io/2015/04/09/chef-audit-mode-cis-benchmarks/)**
>
> Today we’ve released an initial version of audit-cis. This is an “audit mode only” cookbook that runs on a node to check for compliance with The Center for Internet Security (CIS) benchmark for a specific platform. This release targets CentOS 7, CIS...

As far as I know there is no single community-maintained version of the Windows variant of CIS benchmarks yet.

Like you, we have spoken to a number of customers interested in creating something but the reality is that a decent compliance and auditing approach is something that needs to carefully designed with the customer’s own regulatory requirements and feedback mechanisms in mind. I would be interested in collaborating on a shared approach, the current mechanism uses Serverspec and Rspec as its approach, there may be alternative approaches that are more suitable depending on the type of test taking place.

Stuart

-----Original Message-----  
From: [chris@hippiehacker.org](mailto:chris@hippiehacker.org) [[mailto:chris@hippiehacker.org](mailto:chris@hippiehacker.org)] On Behalf Of Chris McClimans  
Sent: 28 September 2015 15:43  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] CIS (Windows) Benkmarks

CIS puts out security benchmarks and guides to ensure compliance to a ‘hardened’ os from the base put out by the OS vendors. Is anyone seen any efforts within the chef community to create a security policy cookbook that checks for compliance against these (or similar) standards? I’m thinking of picking something like this up, but it’s a large undertaking and would interest from more than just one customer to fund it.

Windows Benchmarks:

[https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.os.windows](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.os.windows)

Linux Benchmarks:

> **[CIS Benchmarks Landing Page](https://learn.cisecurity.org/benchmarks?category=benchmarks.os.linux)**
>
> The CIS Benchmarks are secure configuration settings for over 100 technologies, available as a free PDF download.

Database Benchmarks:

> **[CIS Benchmarks Landing Page](https://learn.cisecurity.org/benchmarks?category=benchmarks.servers.database)**
>
> The CIS Benchmarks are secure configuration settings for over 100 technologies, available as a free PDF download.

MSSQL Benchmarks:

[https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.servers.database.mssql](https://benchmarks.cisecurity.org/downloads/browse/?category=benchmarks.servers.database.mssql)

(One of my current customers would benefit from Windows 2012r2 + MSSQL security policy cookbooks)
