CIS Benchmarks Compliance Mapping Matrix

This document maps the CIS Benchmarks sections for Windows Server (2016, 2019, 2022) and Windows 10/11 Client systems to the technical security controls present in this guidebook.

Mapped CIS Benchmark Sections

CIS Section Section Title / Scope Benchmark Category Status Mapped Technical Control(s)
1.1 Password Policy (Complexity, Length, Age, History) Account Policies Covered REQ-ID-001, REQ-PAW-013, REQ-END-018
1.2 Account Lockout Policy (Threshold, Duration) Account Policies Covered REQ-PAW-013, REQ-END-018
1.3 Kerberos Policy (Ticket Lifetimes, Clock Tolerance) Account Policies Covered REQ-END-018
2.2 User Rights Assignment (Deny logons, Allow logons, DC Operator Restrictions) Local Policies Covered REQ-ARCH-001, REQ-ID-007, REQ-DC-023, REQ-PAW-009, REQ-END-016
2.3 Security Options (LSA, LAN Manager, LDAP Signing, SMB Signing) Local Policies Covered REQ-DC-003, REQ-DC-004, REQ-DC-005, REQ-DC-006, REQ-DC-009, REQ-DC-010, REQ-DC-011, REQ-DC-014, REQ-DC-024, REQ-DC-025
9.1 Windows Defender Firewall Profiles (Domain, Private, Public) Firewall Covered REQ-NET-001, REQ-NET-008, REQ-END-022
18.2 Local Administrator Password Solution (LAPS) settings Administrative Templates Covered REQ-ID-002
18.3 AutoPlay and AutoRun settings Administrative Templates Covered REQ-END-003
18.5 Network parameters (KeepAliveTime, perform router discovery, TCP retransmissions) Administrative Templates Covered REQ-DC-026, REQ-END-001
18.6 DNS Client, Fonts, LLTD, Peer-to-Peer, WCN settings Administrative Templates Covered REQ-DC-002, REQ-DC-026, REQ-END-001
18.8 PowerShell Logging, Device Guard, and Virtualization-Based Security Administrative Templates Covered REQ-LOG-002, REQ-PAW-006, REQ-PAW-010, REQ-END-010
18.9 System Services (Print Spooler), AppLocker, WDAC, and GP Refresh settings Administrative Templates Covered REQ-ARCH-005, REQ-DC-001, REQ-DC-008, REQ-DC-021, REQ-PAW-001, REQ-END-011, REQ-END-024, REQ-END-025, REQ-END-027
18.10 Windows Components (Defender, RDP Session Limits, Search, KMS Client, WinRS) Administrative Templates Covered REQ-DC-019, REQ-DC-020, REQ-DC-027, REQ-NET-010, REQ-END-005, REQ-END-007, REQ-END-026
19.1 Windows Defender Firewall port configurations and isolation rules Firewall Advanced Security Covered REQ-NET-001, REQ-NET-003, REQ-NET-008, REQ-END-022
19.6 / 19.7 User configuration (Help Experience, Cloud Content, spotlight, WMP playback) Administrative Templates Covered REQ-DC-027, REQ-END-019
Public Key Encrypting File System (EFS) Settings Public Key Policies Covered REQ-ARCH-005

CIS Benchmark Sections Outside Active Directory Scope

The following CIS Benchmark sections are not covered by this guidebook because they concern standalone workstation settings, user-level privacy options, or non-security features:

Section Title / Scope Category Status Notes
18.8.2 Toast Notifications / Cortana Settings User Experience Not Covered Operational/productivity settings, low security impact.
18.9.1 Background Intelligent Transfer Service System Services Not Covered General operating system background task tuning.

Explicit Hardening Exclusions

The following specific CIS Level 2 controls have been explicitly excluded from this guidebook based on operational safety and environment compatibility constraints:

  1. Disable IPv6 Components (CIS 18.6.19.2.1): Excluded to prevent network malfunctions on loopback, DNS resolution, and domain replication dependencies.
  2. Disable WinRM Server Automatic Listener (CIS 18.10.89.2.2): Excluded to preserve automatic listener provisioning for remote management.

results matching ""

    No results matching ""