Cis benchmark windows 10

Attribution-NonCommercial-ShareAlike 4.0 International

=======================================================================

Creative Commons Corporation ("Creative Commons") is not a law firm and
does not provide legal services or legal advice. Distribution of
Creative Commons public licenses does not create a lawyer-client or
other relationship. Creative Commons makes its licenses and related
information available on an "as-is" basis. Creative Commons gives no
warranties regarding its licenses, any material licensed under their
terms and conditions, or any related information. Creative Commons
disclaims all liability for damages resulting from their use to the
fullest extent possible.

Using Creative Commons Public Licenses

Creative Commons public licenses provide a standard set of terms and
conditions that creators and other rights holders may use to share
original works of authorship and other material subject to copyright
and certain other rights specified in the public license below. The
following considerations are for informational purposes only, are not
exhaustive, and do not form part of our licenses.

     Considerations for licensors: Our public licenses are
     intended for use by those authorized to give the public
     permission to use material in ways otherwise restricted by
     copyright and certain other rights. Our licenses are
     irrevocable. Licensors should read and understand the terms
     and conditions of the license they choose before applying it.
     Licensors should also secure all rights necessary before
     applying our licenses so that the public can reuse the
     material as expected. Licensors should clearly mark any
     material not subject to the license. This includes other CC-
     licensed material, or material used under an exception or
     limitation to copyright. More considerations for licensors:
    wiki.creativecommons.org/Considerations_for_licensors

     Considerations for the public: By using one of our public
     licenses, a licensor grants the public permission to use the
     licensed material under specified terms and conditions. If
     the licensor's permission is not necessary for any reason--for
     example, because of any applicable exception or limitation to
     copyright--then that use is not regulated by the license. Our
     licenses grant only permissions under copyright and certain
     other rights that a licensor has authority to grant. Use of
     the licensed material may still be restricted for other
     reasons, including because others have copyright or other
     rights in the material. A licensor may make special requests,
     such as asking that all changes be marked or described.
     Although not required by our licenses, you are encouraged to
     respect those requests where reasonable. More considerations
     for the public:
    wiki.creativecommons.org/Considerations_for_licensees

=======================================================================

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International
Public License

By exercising the Licensed Rights (defined below), You accept and agree
to be bound by the terms and conditions of this Creative Commons
Attribution-NonCommercial-ShareAlike 4.0 International Public License
("Public License"). To the extent this Public License may be
interpreted as a contract, You are granted the Licensed Rights in
consideration of Your acceptance of these terms and conditions, and the
Licensor grants You such rights in consideration of benefits the
Licensor receives from making the Licensed Material available under
these terms and conditions.


Section 1 -- Definitions.

  a. Adapted Material means material subject to Copyright and Similar
     Rights that is derived from or based upon the Licensed Material
     and in which the Licensed Material is translated, altered,
     arranged, transformed, or otherwise modified in a manner requiring
     permission under the Copyright and Similar Rights held by the
     Licensor. For purposes of this Public License, where the Licensed
     Material is a musical work, performance, or sound recording,
     Adapted Material is always produced where the Licensed Material is
     synched in timed relation with a moving image.

  b. Adapter's License means the license You apply to Your Copyright
     and Similar Rights in Your contributions to Adapted Material in
     accordance with the terms and conditions of this Public License.

  c. BY-NC-SA Compatible License means a license listed at
     creativecommons.org/compatiblelicenses, approved by Creative
     Commons as essentially the equivalent of this Public License.

  d. Copyright and Similar Rights means copyright and/or similar rights
     closely related to copyright including, without limitation,
     performance, broadcast, sound recording, and Sui Generis Database
     Rights, without regard to how the rights are labeled or
     categorized. For purposes of this Public License, the rights
     specified in Section 2(b)(1)-(2) are not Copyright and Similar
     Rights.

  e. Effective Technological Measures means those measures that, in the
     absence of proper authority, may not be circumvented under laws
     fulfilling obligations under Article 11 of the WIPO Copyright
     Treaty adopted on December 20, 1996, and/or similar international
     agreements.

  f. Exceptions and Limitations means fair use, fair dealing, and/or
     any other exception or limitation to Copyright and Similar Rights
     that applies to Your use of the Licensed Material.

  g. License Elements means the license attributes listed in the name
     of a Creative Commons Public License. The License Elements of this
     Public License are Attribution, NonCommercial, and ShareAlike.

  h. Licensed Material means the artistic or literary work, database,
     or other material to which the Licensor applied this Public
     License.

  i. Licensed Rights means the rights granted to You subject to the
     terms and conditions of this Public License, which are limited to
     all Copyright and Similar Rights that apply to Your use of the
     Licensed Material and that the Licensor has authority to license.

  j. Licensor means the individual(s) or entity(ies) granting rights
     under this Public License.

  k. NonCommercial means not primarily intended for or directed towards
     commercial advantage or monetary compensation. For purposes of
     this Public License, the exchange of the Licensed Material for
     other material subject to Copyright and Similar Rights by digital
     file-sharing or similar means is NonCommercial provided there is
     no payment of monetary compensation in connection with the
     exchange.

  l. Share means to provide material to the public by any means or
     process that requires permission under the Licensed Rights, such
     as reproduction, public display, public performance, distribution,
     dissemination, communication, or importation, and to make material
     available to the public including in ways that members of the
     public may access the material from a place and at a time
     individually chosen by them.

  m. Sui Generis Database Rights means rights other than copyright
     resulting from Directive 96/9/EC of the European Parliament and of
     the Council of 11 March 1996 on the legal protection of databases,
     as amended and/or succeeded, as well as other essentially
     equivalent rights anywhere in the world.

  n. You means the individual or entity exercising the Licensed Rights
     under this Public License. Your has a corresponding meaning.


Section 2 -- Scope.

  a. License grant.

       1. Subject to the terms and conditions of this Public License,
          the Licensor hereby grants You a worldwide, royalty-free,
          non-sublicensable, non-exclusive, irrevocable license to
          exercise the Licensed Rights in the Licensed Material to:

            a. reproduce and Share the Licensed Material, in whole or
               in part, for NonCommercial purposes only; and

            b. produce, reproduce, and Share Adapted Material for
               NonCommercial purposes only.

       2. Exceptions and Limitations. For the avoidance of doubt, where
          Exceptions and Limitations apply to Your use, this Public
          License does not apply, and You do not need to comply with
          its terms and conditions.

       3. Term. The term of this Public License is specified in Section
          6(a).

       4. Media and formats; technical modifications allowed. The
          Licensor authorizes You to exercise the Licensed Rights in
          all media and formats whether now known or hereafter created,
          and to make technical modifications necessary to do so. The
          Licensor waives and/or agrees not to assert any right or
          authority to forbid You from making technical modifications
          necessary to exercise the Licensed Rights, including
          technical modifications necessary to circumvent Effective
          Technological Measures. For purposes of this Public License,
          simply making modifications authorized by this Section 2(a)
          (4) never produces Adapted Material.

       5. Downstream recipients.

            a. Offer from the Licensor -- Licensed Material. Every
               recipient of the Licensed Material automatically
               receives an offer from the Licensor to exercise the
               Licensed Rights under the terms and conditions of this
               Public License.

            b. Additional offer from the Licensor -- Adapted Material.
               Every recipient of Adapted Material from You
               automatically receives an offer from the Licensor to
               exercise the Licensed Rights in the Adapted Material
               under the conditions of the Adapter's License You apply.

            c. No downstream restrictions. You may not offer or impose
               any additional or different terms or conditions on, or
               apply any Effective Technological Measures to, the
               Licensed Material if doing so restricts exercise of the
               Licensed Rights by any recipient of the Licensed
               Material.

       6. No endorsement. Nothing in this Public License constitutes or
          may be construed as permission to assert or imply that You
          are, or that Your use of the Licensed Material is, connected
          with, or sponsored, endorsed, or granted official status by,
          the Licensor or others designated to receive attribution as
          provided in Section 3(a)(1)(A)(i).

  b. Other rights.

       1. Moral rights, such as the right of integrity, are not
          licensed under this Public License, nor are publicity,
          privacy, and/or other similar personality rights; however, to
          the extent possible, the Licensor waives and/or agrees not to
          assert any such rights held by the Licensor to the limited
          extent necessary to allow You to exercise the Licensed
          Rights, but not otherwise.

       2. Patent and trademark rights are not licensed under this
          Public License.

       3. To the extent possible, the Licensor waives any right to
          collect royalties from You for the exercise of the Licensed
          Rights, whether directly or through a collecting society
          under any voluntary or waivable statutory or compulsory
          licensing scheme. In all other cases the Licensor expressly
          reserves any right to collect such royalties, including when
          the Licensed Material is used other than for NonCommercial
          purposes.


Section 3 -- License Conditions.

Your exercise of the Licensed Rights is expressly made subject to the
following conditions.

  a. Attribution.

       1. If You Share the Licensed Material (including in modified
          form), You must:

            a. retain the following if it is supplied by the Licensor
               with the Licensed Material:

                 i. identification of the creator(s) of the Licensed
                    Material and any others designated to receive
                    attribution, in any reasonable manner requested by
                    the Licensor (including by pseudonym if
                    designated);

                ii. a copyright notice;

               iii. a notice that refers to this Public License;

                iv. a notice that refers to the disclaimer of
                    warranties;

                 v. a URI or hyperlink to the Licensed Material to the
                    extent reasonably practicable;

            b. indicate if You modified the Licensed Material and
               retain an indication of any previous modifications; and

            c. indicate the Licensed Material is licensed under this
               Public License, and include the text of, or the URI or
               hyperlink to, this Public License.

       2. You may satisfy the conditions in Section 3(a)(1) in any
          reasonable manner based on the medium, means, and context in
          which You Share the Licensed Material. For example, it may be
          reasonable to satisfy the conditions by providing a URI or
          hyperlink to a resource that includes the required
          information.
       3. If requested by the Licensor, You must remove any of the
          information required by Section 3(a)(1)(A) to the extent
          reasonably practicable.

  b. ShareAlike.

     In addition to the conditions in Section 3(a), if You Share
     Adapted Material You produce, the following conditions also apply.

       1. The Adapter's License You apply must be a Creative Commons
          license with the same License Elements, this version or
          later, or a BY-NC-SA Compatible License.

       2. You must include the text of, or the URI or hyperlink to, the
          Adapter's License You apply. You may satisfy this condition
          in any reasonable manner based on the medium, means, and
          context in which You Share Adapted Material.

       3. You may not offer or impose any additional or different terms
          or conditions on, or apply any Effective Technological
          Measures to, Adapted Material that restrict exercise of the
          rights granted under the Adapter's License You apply.


Section 4 -- Sui Generis Database Rights.

Where the Licensed Rights include Sui Generis Database Rights that
apply to Your use of the Licensed Material:

  a. for the avoidance of doubt, Section 2(a)(1) grants You the right
     to extract, reuse, reproduce, and Share all or a substantial
     portion of the contents of the database for NonCommercial purposes
     only;

  b. if You include all or a substantial portion of the database
     contents in a database in which You have Sui Generis Database
     Rights, then the database in which You have Sui Generis Database
     Rights (but not its individual contents) is Adapted Material,
     including for purposes of Section 3(b); and

  c. You must comply with the conditions in Section 3(a) if You Share
     all or a substantial portion of the contents of the database.

For the avoidance of doubt, this Section 4 supplements and does not
replace Your obligations under this Public License where the Licensed
Rights include other Copyright and Similar Rights.


Section 5 -- Disclaimer of Warranties and Limitation of Liability.

  a. UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE
     EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS
     AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF
     ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS,
     IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION,
     WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR
     PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS,
     ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT
     KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT
     ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU.

  b. TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE
     TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION,
     NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT,
     INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES,
     COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR
     USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN
     ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR
     DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR
     IN PART, THIS LIMITATION MAY NOT APPLY TO YOU.

  c. The disclaimer of warranties and limitation of liability provided
     above shall be interpreted in a manner that, to the extent
     possible, most closely approximates an absolute disclaimer and
     waiver of all liability.


Section 6 -- Term and Termination.

  a. This Public License applies for the term of the Copyright and
     Similar Rights licensed here. However, if You fail to comply with
     this Public License, then Your rights under this Public License
     terminate automatically.

  b. Where Your right to use the Licensed Material has terminated under
     Section 6(a), it reinstates:

       1. automatically as of the date the violation is cured, provided
          it is cured within 30 days of Your discovery of the
          violation; or

       2. upon express reinstatement by the Licensor.

     For the avoidance of doubt, this Section 6(b) does not affect any
     right the Licensor may have to seek remedies for Your violations
     of this Public License.

  c. For the avoidance of doubt, the Licensor may also offer the
     Licensed Material under separate terms or conditions or stop
     distributing the Licensed Material at any time; however, doing so
     will not terminate this Public License.

  d. Sections 1, 5, 6, 7, and 8 survive termination of this Public
     License.


Section 7 -- Other Terms and Conditions.

  a. The Licensor shall not be bound by any additional or different
     terms or conditions communicated by You unless expressly agreed.

  b. Any arrangements, understandings, or agreements regarding the
     Licensed Material not stated herein are separate from and
     independent of the terms and conditions of this Public License.


Section 8 -- Interpretation.

  a. For the avoidance of doubt, this Public License does not, and
     shall not be interpreted to, reduce, limit, restrict, or impose
     conditions on any use of the Licensed Material that could lawfully
     be made without permission under this Public License.

  b. To the extent possible, if any provision of this Public License is
     deemed unenforceable, it shall be automatically reformed to the
     minimum extent necessary to make it enforceable. If the provision
     cannot be reformed, it shall be severed from this Public License
     without affecting the enforceability of the remaining terms and
     conditions.

  c. No term or condition of this Public License will be waived and no
     failure to comply consented to unless expressly agreed to by the
     Licensor.

  d. Nothing in this Public License constitutes or may be interpreted
     as a limitation upon, or waiver of, any privileges and immunities
     that apply to the Licensor or You, including from the legal
     processes of any jurisdiction or authority.

=======================================================================

Creative Commons is not a party to its public
licenses. Notwithstanding, Creative Commons may elect to apply one of
its public licenses to material it publishes and in those instances
will be considered the “Licensor.” The text of the Creative Commons
public licenses is dedicated to the public domain under the CC0 Public
Domain Dedication. Except for the limited purpose of indicating that
material is shared under a Creative Commons public license or as
otherwise permitted by the Creative Commons policies published at
creativecommons.org/policies, Creative Commons does not authorize the
use of the trademark "Creative Commons" or any other trademark or logo
of Creative Commons without its prior written consent including,
without limitation, in connection with any unauthorized modifications
to any of its public licenses or any other arrangements,
understandings, or agreements concerning use of licensed material. For
the avoidance of doubt, this paragraph does not form part of the
public licenses.

Creative Commons may be contacted at creativecommons.org.


Microsoft Windows and Windows Server Benchmarks



Problem

I’m having difficulty understanding which Microsoft Windows Benchmark my organization needs.

Solution

All published CIS Microsoft Windows Benchmarks can be found at the CIS Microsoft Windows Benchmarks community in CIS WorkBench. The following tables list each type of Microsoft Windows Benchmark and their intended use:

Windows Server Benchmarks

Intended For

CIS Microsoft Windows Server 2022 Benchmark

This secure configuration guide is based on Microsoft Windows Server 2022 (Release 21H2) and is intended for all versions of Microsoft Windows Server 2022 operating system, including older versions.

CIS Azure Compute Microsoft Windows Server 2022 Benchmark

This secure configuration guide is based on Server 2022 settings available via built in Microsoft profiles in Azure and is intended for all versions of the Server 2022 operating system, including older versions.

CIS Microsoft Windows Server 2019 Benchmark

This document provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows Server. This guide was tested against Microsoft Windows Server 2019 Datacenter.

CIS Microsoft Windows Server 2019 STIG Benchmark

This secure configuration guide is based on Microsoft Windows Server 2019 Security Technical Implementation Guide (STIG) and is intended for all versions of the Server 2019 operating system, including older versions.

CIS Azure Compute Microsoft Windows Server 2019 Benchmark

This secure configuration guide is based on Server 2019 settings available via built in Microsoft profiles in Azure, and is intended for all versions of the Server 2019 operating system, including older versions.

CIS Microsoft Windows Server 2016 Benchmark

This secure configuration guide is based on Microsoft Windows Server 2016 and is intended for all versions of the Server 2016 operating system, including older versions.

CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark

This document provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows Server. This guide was tested against Microsoft Windows Server 2016 Datacenter.

CIS Microsoft Windows Server 2016 STIG Benchmark

This secure configuration guide is based on Microsoft Windows Server 2016 (ADMX/ADML Template Release for 21H2) and is intended for all versions of the Server 2016 operating system, including older versions.

CIS Microsoft Windows Server 2012 R2 Benchmark

This secure configuration guide is based on Windows Server 2012 R2 and is intended for all versions of the Server 2012 R2 operating system, including older versions.

CIS Microsoft Windows Server 2012 (non-R2) Benchmark

This secure configuration guide is based on Windows Server 2012 and is intended for all versions of the Server 2012 operating system, including older versions.

CIS Microsoft Windows Server 2008 R2 Benchmark

This secure configuration guide is based on Microsoft Windows Server 2008 R2 and is intended for all versions of Server 2008 R2 operating system.

CIS Microsoft Windows Server 2008 (non-R2) Benchmark

This document provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows Server 2008 (non-R2).

Windows Benchmarks

Intended For

CIS Microsoft Windows 11 Stand-alone Benchmark

This secure configuration guide is based on Microsoft Windows 11 Enterprise Release 21H2 and is intended for all versions of Windows 11 operating system, including older versions.

CIS Microsoft Windows 11 Enterprise Benchmark

This secure configuration guide is based on the Microsoft Windows 11 Enterprise Release 21H2 and is intended for all versions of the Windows 11 operating system, including older versions.

CIS Microsoft Intune for Windows 11 Benchmark

This secure configuration guide is based on Windows 11 and is intended for all versions of the Windows 11 operating system, including older versions.

CIS Microsoft Windows 10 Stand-alone Benchmark

This secure configuration guide is based on Microsoft Windows 10 Enterprise Release 21H2 and is intended for all versions of Windows 10 operating system, including older versions.

CIS Microsoft Windows 10 EMS Gateway Benchmark

This document provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows 10 installed on an Elections Management System (EMS) Gateway.

CIS Microsoft Windows 10 Enterprise Benchmark | other releases: 21H1, 20H2, 2004, 1909, 1903, 1809, 1803, 1709, 1703, 1607, 1511, 1507

This secure configuration guide is based on Windows 10 and is intended for all versions of the Windows 10 operating system, including older versions.

CIS Microsoft Windows 8.1 Workstation Benchmark

This document provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows 8.1.

CIS Microsoft Windows 7 Workstation Benchmark

This document provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows 7. This guide was tested against Microsoft Windows 7 Enterprise Edition (SP1).

CIS Microsoft Windows XP Benchmark

This document, CIS Microsoft Windows XP Benchmark v3.1.0, provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows XP.

To ensure all new and updated group policy objects (GPOs) are installed on the system, please download the newest version of the ADMX/ADML templates. Unfortunately, Microsoft doesn’t provide a central location to download ADMX/ADML templates, so please search the web for the latest download pages.

The Windows CIS Benchmarks are written for Active Directory domain-joined systems using Group Policy, not stand-alone/workgroup systems. Adjustments/tailoring to some recommendations will be needed to maintain functionality if attempting to implement CIS hardening on stand-alone systems or a system running in the cloud.

Keywords; Microsoft Windows Server 7 10 11 2008 2012 2016 2019 2022

Content by Label


Center for Internet Security®


Securing the Windows 10 operating system is paramount to safeguarding sensitive data and protecting against emerging cyber threats. To establish a robust security baseline, it is essential to leverage industry-recognized standards and best practices. In this blog post, we will explore the latest CIS Benchmark and STIG (Security Technical Implementation Guide) as authoritative references for creating a comprehensive security baseline for Windows 10. By implementing the recommendations outlined in these benchmarks, organizations can enhance their Windows 10 security posture effectively.

  1. Understand the CIS Benchmark and STIG

The CIS Benchmark and STIG are guidelines developed by the Center for Internet Security and the Defense Information Systems Agency, respectively. These benchmarks provide detailed configuration recommendations for securing Windows 10 systems based on industry expertise and practical experience.

Source: CIS Security Benchmarks

  1. User Account Control (UAC) Configuration

Configure User Account Control (UAC) to the highest level (Always notify) to ensure that administrative actions require user consent. This helps prevent unauthorized changes to system settings and enhances the overall security posture of Windows 10.

  1. Windows Updates and Patch Management

Regularly apply Windows updates to ensure the operating system is equipped with the latest security patches and fixes. Establish a robust patch management process to automate and streamline the deployment of updates.

  1. Account Security Measures

Enforce strong password policies, including complexity requirements, minimum password length, and regular password expiration. Implement multi-factor authentication (MFA) for user accounts, particularly for privileged accounts, to provide an additional layer of security.

  1. Audit Logging and Monitoring

Enable auditing of security events to monitor potential security incidents effectively. Configure an appropriate audit policy to log relevant events, such as failed logon attempts, privilege escalation, and changes to critical system files. Implement a robust monitoring system or leverage a Security Information and Event Management (SIEM) solution to detect and respond to security events in real-time.

  1. Network Security Controls

Enable and configure Windows Firewall to control incoming and outgoing network traffic. Implement appropriate rules and restrictions to allow only necessary network communication. Disable unnecessary network services and protocols to reduce the attack surface and limit potential vulnerabilities.

  1. Secure Configuration Settings

Harden Windows 10 by implementing recommended security configurations. Disable unnecessary features, secure network protocols, and configure access controls to minimize the risk of exploitation.

  1. Application Whitelisting and Execution Policies

Implement application whitelisting to allow only authorized and trusted applications to run on Windows 10 systems. Define and enforce execution policies to prevent the execution of malicious scripts and unauthorized code.

  1. Device and Data Encryption

Enable full disk encryption using BitLocker or similar encryption solutions to protect sensitive data stored on Windows 10 devices. Additionally, encrypt removable media to ensure data confidentiality and integrity.

  1. Incident Response Planning

Develop a comprehensive incident response plan that outlines the steps to be taken in the event of a security incident. This plan should include incident identification, containment, eradication, recovery, and lessons learned.

Conclusion

Creating a security baseline for Windows 10 based on the latest CIS Benchmark and STIG is a proactive step towards strengthening the security posture of your organization. By following these guidelines and implementing the recommended security measures, you can significantly reduce the risk of security breaches, protect sensitive data, and stay one step ahead of emerging threats in the dynamic cybersecurity landscape.

Remember to regularly review and update your security baseline to align with new releases and emerging best practices to ensure ongoing protection.

Sources:

  • Center for Internet Security (CIS): https://www.cisecurity.org/
  • Defense Information Systems Agency (DISA): https://www.disa.mil/

Let’s check the options to download Intune CIS Benchmark for Windows 10 or Windows 11. CIS benchmarks are produced and maintained by the Center for Internet Security (a.k.a CIS).

They have developed CIS Benchmarks for more than 100 configuration guidelines across 25+ vendor product families. I have seen most of the security teams are happy to implement CIS benchmarks. The security community widely accepts the CIS benchmark.

The CIS helps to safeguard systems against today’s evolving cyber threats. Windows 10 and Windows 11 group policy-related CIS benchmark configurations are available for many years.

I have seen many organizations moving to modern management using Intune. Until recently, there was NO CIS benchmark released for Intune-managed Windows devices. Recently, Mark Thomas kindly shared the details about Intune CIS Benchmark for Windows 10 or Windows 11.

Patch My PC

Video – Intune Windows 11 CIS Benchmark Security Policy Settings

In this video, you will learn more about Intune Windows 11 CIS Benchmark and Security Policy Settings Design Decisions – Intune Design Decisions Part 10.

Intune Windows 11 CIS Benchmark and Security Policy Settings

Who Develops the CIS Benchmark for Windows 10/11 Azure AD Joined Systems

As per CIS –  ‘Benchmarks are developed through the generous volunteer efforts of subject matter experts, technology vendors, public and private CIS Benchmark community members, and the CIS Benchmark Development team.’

NOTE! – This CIS Benchmark guide was tested against Microsoft Windows 10 Release 2004 Enterprise edition. Please note that Intune is continually updating to support settings that are backed by group policy. This benchmark is based on settings that were available natively within Intune at the time of publication.

Frequency of CIS Benchmark Update for Windows 11

I don’t think there is any regular or fixed schedule to update the CIS benchmark. I have seen these benchmarks getting updated regularly. It’s worth checking monthly reports that announce new benchmarks and updates to existing benchmarks.

The release of revised CIS Benchmarks changes depending on the IT community who developed it and on the release schedule of the technology the benchmark supports.

Download Intune CIS Benchmark for Windows 10 or Windows 11 1

Download Intune CIS Benchmark for Windows 10 or Windows 11 1

Let’s download the Intune CIS Benchmark for Windows 10 or Windows 11 from the following URL -> CIS Microsoft Windows Desktop Benchmarks (cisecurity.org).

You need to signup with all the details to get the FREE PDF version of the CIS Benchmark. Securing Microsoft Windows Desktop. An objective, consensus-driven security guideline for the Microsoft Windows Desktop Operating Systems. A step-by-step checklist to secure Microsoft Windows Desktop.

Download Intune CIS Benchmark for Windows 10 or Windows 11 4

Download Intune CIS Benchmark for Windows 10 or Windows 11 4

Intune CIS Benchmark for Windows 10 or Windows 11

Recently CIS released the latest version (1.0.1) of Intune CIS benchmark for Windows 10. This is the CIS benchmark for Azure AD, and Hybrid Azure AD joined Intune managed Windows 10 devices. You can download the Intune CIS benchmark for free now.

This latest CIS Benchmark for Microsoft Intune for Windows 10 is for version 2004. I do think there should be an update to this CIS benchmark version soon. Microsoft has released the latest version of Windows 10 21H2 and Windows 11 in insider preview.

Download Intune CIS Benchmark for Windows 10 or Windows 11 2

Download Intune CIS Benchmark for Windows 10 or Windows 11 2

I hope CIS will release Windows 11 security benchmark as well when it’s released in production. As per CIS, there are over 12,000 professionals in the CIS Benchmarks communities. This community does great work to create CIS Benchmark recommendations wide accepted by the security community.

CIS provides JSON another format to configure the policies on the fly so that IT or System Admins can implement these recommended policy settings without going through a lot of struggle for Windows 10 or Windows 11 devices.

NOTE! – You have an option to download the CIS benchmark for Windows 10 domain-joined PCs.

Download Intune CIS Benchmark for Windows 10

Download Intune CIS Benchmark for Windows 10 and Windows 11

Create CIS Benchmark Security policies using Intune

The following are the best approach as per Microsoft’s recommendation. Also, Microsoft enabled over 1400 new mobile device management (MDM) policies with the latest version of Windows (coming soon version) announced by Mike Danoski.

  • Settings Catalog – The best option to create security policies using Intune.
  • Security Baseline – the Microsoft product group recommended security policies (easiest way to deploy security policies).
  • Administrative Templates – Settings catalog has administrative templates as well. So better to use the Settings catalog wherever possible. Isn’t it?
  • Device Restriction/Custom policies – Use this security setting if the security settings you are looking for are not available in any other types of options mentioned above.

Create Security policies using Intune

Let’s first understand what the options to create security policies using Intune are. You have many options to create Windows security policies using Intune. It’s important to understand the best option(s) to build security policies using Intune.

Download Intune CIS Benchmark for Windows 10 or Windows 11 3

Download Intune CIS Benchmark for Windows 10 or Windows 11 3

Intune modern management security policies

I have presented Intune modern management security policies session at India Cloud Security Summit 2021 (ICSS). You can watch the video below to get more details below.

Intune Security policies 1-hour free training Download Intune CIS Benchmark for Windows 10 or Windows 11

Free Intune Training

HTMD Community provided 63 Episodes of free Intune Training for IT Administrators. You can get more details about free Intune training from 63 Episodes Of Free Intune Training For Device Management Admins HTMD Blog (anoopcnair.com).

Author

Anoop is Microsoft MVP! He is a Solution Architect in enterprise client management with over 17 years of experience (calculation done in 2018). He is Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc…..…

Checklist Summary:

This document provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows.

Checklist Role:

  • Desktop Operating System

Known Issues:

Not provided.

Target Audience:

The Windows CIS Benchmarks are written for Active Directory domain-joined systems using Group Policy, not standalone/workgroup systems. Adjustments/tailoring to some recommendations will be needed to maintain functionality if attempting to implement CIS hardening on standalone systems or a system running in the cloud.

Target
Operational Environment:

  • Managed

Testing Information:

This guide was tested against a system running Windows 10 Enterprise Release 1809.

Regulatory
Compliance:

Not provided.

Comments/Warnings/Miscellaneous:

Not provided.

Disclaimer:

https://www.cisecurity.org/cis-securesuite/cis-securesuite-membership-terms-of-use/

Product Support:

support@cisecurity.org

Point of Contact:

support@cisecurity.org

Sponsor:

Not provided.

Licensing:

https://www.cisecurity.org/cis-securesuite/cis-securesuite-membership-terms-of-use/

Change History:

updated to FINAL - 9/30/19
updated benchmark per CIS - 2/22/24

Dependency/Requirements:

URL Description

References:

Reference URL Description

NIST checklist record last modified on 02/22/2024

Понравилась статья? Поделить с друзьями:
0 0 голоса
Рейтинг статьи
Подписаться
Уведомить о
guest

0 комментариев
Старые
Новые Популярные
Межтекстовые Отзывы
Посмотреть все комментарии
  • Как создать ini файл на windows 10
  • Как на рабочем столе увеличить ярлыки на рабочем столе windows
  • Shadowsocks windows v2ray plugin
  • Как восстановить spool windows 10
  • Webdav windows server 2012 настройка