CIS (Center for Internet Security, Inc.)

https://www.cisecurity.org/about-us

우리는 IT 시스템 및 데이터 보안에 대한 세계적으로 인정받는 모범 사례인 CIS Controls ® 및 CIS Benchmarks 를 담당하는 커뮤니티 주도 비영리 단체 입니다

 

https://www.cisecurity.org/cis-benchmarks/

OS, Server Software, Cloud Providers, Mobile devices, Network devices, Desktop Software 등에 대한 benchmarks 제공

Desktops & Web Browsers:

  • Apple Desktop OSX 

  • Apple Safari Browser 

  • Google Chrome 

  • Microsoft Internet Explorer 

  • Microsoft Windows Desktop XP/NT

  • Mozilla Firefox Browser 

  • Opera Browser

Mobile Devices

  • Apple Mobile Platform iOS

  • Google Mobile Platform

Network Devices

  • Agnostic Print Devices

  • Checkpoint Firewall

  • Cisco Firewall Devices

  • Cisco Routers/Switches IOS

  • Cisco Wireless LAN Controller

  • Juniper Routers/Switches JunOS

Security Metrics

  • Quick Start Guide

  • Security Metrics

Servers – Operating Systems

  • Amazon Linux 

  • CentOS 

  • Debian Linux Server

  • IBM AIX Server 

  • Microsoft Windows Server 

  • Novell Netware

  • Oracle Linux 

  • Oracle Solaris Server 

  • Red Hat Linux Server 

  • Slackware Linux Server 

  • SUSE Linux Enterprise Server

  • Ubuntu LTS Server

Servers – Other

  • Apache HTTP Server 

  • Apache Tomcat Server

  • BIND DNS Server 

  • FreeRADIUS 

  • Microsoft IIS Server 

  • IBM DB2 Server 

  • Microsoft Exchange 

  • Microsoft SharePoint Server 

  • Microsoft SQL Server  

  • MIT Kerberos 

  • MySQL Database Server 

  • Novell eDirectory 

  • OpenLDAP Server 

  • Oracle Database Server 

  • Sybase Database Server

Virtualization Platforms & Cloud

  • Agnostic VM Server

  • AWS Foundations

  • AWS Three-Tier Web Architecture

  • Docker

  • Kubernetes

  • VMware Server 

  • Xen Server 

Other

  • Microsoft Access

  • Microsoft Excel

  • Microsoft Office 

  • Microsoft Outlook 

  • Microsoft PowerPoint

  • Microsoft Word

 

예제 : CIS Ubuntu Linux 20.04 LTS Benchmark v1.1.0

 

CIS Benchmarks 에 따라 구성된 클라우드 이미지를 제공함 (추가 비용 있음)

https://www.cisecurity.org/cis-hardened-images

https://www.cisecurity.org/cis-hardened-image-list/

 

내부 참고자료

AWS Compliance Scanning Tool

The CIS Amazon Web Services Foundations Benchmark (CIS v1.4.0)