CIS Benchmarks Compliance Mapping Matrix
This document maps the CIS Benchmarks sections for Windows Server (2016, 2019, 2022) and Windows 10/11 Client systems to the technical security controls present in this guidebook.
Mapped CIS Benchmark Sections
| CIS Section | Section Title / Scope | Benchmark Category | Status | Mapped Technical Control(s) |
|---|---|---|---|---|
| 1.1 | Password Policy (Complexity, Length, Age, History) | Account Policies | Covered | REQ-ID-001, REQ-PAW-013, REQ-END-018 |
| 1.2 | Account Lockout Policy (Threshold, Duration) | Account Policies | Covered | REQ-PAW-013, REQ-END-018 |
| 1.3 | Kerberos Policy (Ticket Lifetimes, Clock Tolerance) | Account Policies | Covered | REQ-END-018 |
| 2.2 | User Rights Assignment (Deny logons, Allow logons, DC Operator Restrictions) | Local Policies | Covered | REQ-ARCH-001, REQ-ID-007, REQ-DC-023, REQ-PAW-009, REQ-END-016 |
| 2.3 | Security Options (LSA, LAN Manager, LDAP Signing, SMB Signing) | Local Policies | Covered | REQ-DC-003, REQ-DC-004, REQ-DC-005, REQ-DC-006, REQ-DC-009, REQ-DC-010, REQ-DC-011, REQ-DC-014, REQ-DC-024, REQ-DC-025 |
| 9.1 | Windows Defender Firewall Profiles (Domain, Private, Public) | Firewall | Covered | REQ-NET-001, REQ-NET-008, REQ-END-022 |
| 18.2 | Local Administrator Password Solution (LAPS) settings | Administrative Templates | Covered | REQ-ID-002 |
| 18.3 | AutoPlay and AutoRun settings | Administrative Templates | Covered | REQ-END-003 |
| 18.5 | Network parameters (KeepAliveTime, perform router discovery, TCP retransmissions) | Administrative Templates | Covered | REQ-DC-026, REQ-END-001 |
| 18.6 | DNS Client, Fonts, LLTD, Peer-to-Peer, WCN settings | Administrative Templates | Covered | REQ-DC-002, REQ-DC-026, REQ-END-001 |
| 18.8 | PowerShell Logging, Device Guard, and Virtualization-Based Security | Administrative Templates | Covered | REQ-LOG-002, REQ-PAW-006, REQ-PAW-010, REQ-END-010 |
| 18.9 | System Services (Print Spooler), AppLocker, WDAC, and GP Refresh settings | Administrative Templates | Covered | REQ-ARCH-005, REQ-DC-001, REQ-DC-008, REQ-DC-021, REQ-PAW-001, REQ-END-011, REQ-END-024, REQ-END-025, REQ-END-027 |
| 18.10 | Windows Components (Defender, RDP Session Limits, Search, KMS Client, WinRS) | Administrative Templates | Covered | REQ-DC-019, REQ-DC-020, REQ-DC-027, REQ-NET-010, REQ-END-005, REQ-END-007, REQ-END-026 |
| 19.1 | Windows Defender Firewall port configurations and isolation rules | Firewall Advanced Security | Covered | REQ-NET-001, REQ-NET-003, REQ-NET-008, REQ-END-022 |
| 19.6 / 19.7 | User configuration (Help Experience, Cloud Content, spotlight, WMP playback) | Administrative Templates | Covered | REQ-DC-027, REQ-END-019 |
| Public Key | Encrypting File System (EFS) Settings | Public Key Policies | Covered | REQ-ARCH-005 |
CIS Benchmark Sections Outside Active Directory Scope
The following CIS Benchmark sections are not covered by this guidebook because they concern standalone workstation settings, user-level privacy options, or non-security features:
| Section | Title / Scope | Category | Status | Notes |
|---|---|---|---|---|
| 18.8.2 | Toast Notifications / Cortana Settings | User Experience | Not Covered | Operational/productivity settings, low security impact. |
| 18.9.1 | Background Intelligent Transfer Service | System Services | Not Covered | General operating system background task tuning. |
Explicit Hardening Exclusions
The following specific CIS Level 2 controls have been explicitly excluded from this guidebook based on operational safety and environment compatibility constraints:
- Disable IPv6 Components (CIS 18.6.19.2.1): Excluded to prevent network malfunctions on loopback, DNS resolution, and domain replication dependencies.
- Disable WinRM Server Automatic Listener (CIS 18.10.89.2.2): Excluded to preserve automatic listener provisioning for remote management.