Microsoft 365
Secure configuration benchmarks for Microsoft 365 cloud productivity and collaboration services.
Microsoft 365 Foundations
v6.0.1February 2026Comprehensive security configuration guidelines covering Microsoft Entra ID, Exchange Online, SharePoint, Teams, Defender, and Purview across E3/E5/F1/F3 license tiers.
Microsoft SharePoint Server 2019
v1.0.0January 2025Security configuration guidelines for SharePoint Server 2019 covering service accounts, authentication, SSL, logging, app management, backup, web application security, and Central Administration hardening.
Cloud Infrastructure
Benchmarks for cloud platform services including compute, storage, networking, and identity.
Microsoft Azure Foundations
v3.0.0February 2025Security configuration guidelines for Microsoft Azure infrastructure services, IAM, networking, storage, logging, and monitoring.
Amazon Web Services Foundations
v4.0.1December 2024Security configuration guidelines for AWS services including IAM, S3, EC2, CloudTrail, VPC, and RDS.
Google Cloud Platform Foundations
v4.0.0October 2024Security configuration guidelines for Google Cloud including IAM, compute, storage, networking, and logging.
Oracle Cloud Infrastructure Foundations
v2.0.0December 2024Security configuration guidelines for Oracle Cloud Infrastructure covering IAM, networking, compute, storage, database, and logging and monitoring.
Alibaba Cloud Foundations
v1.0.0September 2024Security configuration guidelines for Alibaba Cloud (Aliyun) covering RAM identity management, VPC networking, ECS compute, OSS storage, database services, and logging and monitoring.
Google Workspace
v1.0.0May 2026Security configuration guidelines for Google Workspace covering Admin Console settings, authentication, Gmail security, Drive sharing, mobile management, and audit logging.
Terraform Enterprise
v1.0.0May 2026Security configuration guidelines for Terraform Enterprise covering organization settings, workspace security, VCS and run security, Sentinel policy enforcement, API token management, network isolation, and audit logging.
GitHub Enterprise
v1.0.0Jan 2025Security configuration guidelines for GitHub Enterprise covering organization security, authentication with SAML SSO, repository protection, Actions security, supply chain security with Dependabot, code scanning, and audit log streaming.
DigitalOcean
v1.0.0Jan 2025Security configuration guidelines for DigitalOcean cloud infrastructure covering VPC networking, firewall rules, Droplet hardening, Spaces object storage, managed databases, Kubernetes (DOKS), load balancers, and DNS security.
Operating Systems
Hardening benchmarks for server and desktop operating systems.
Windows Server 2022
v3.0.0March 2025Security configuration guidelines for Microsoft Windows Server 2022 including account policies, audit settings, and security options.
Ubuntu Linux 24.04 LTS
v1.0.0May 2026Security configuration guidelines for Ubuntu 24.04 LTS (Noble Numbat) covering filesystem, boot, services, network, logging, SSH/PAM, and system maintenance.
Ubuntu Linux 22.04 LTS
v2.0.0January 2024Security configuration guidelines for Ubuntu Linux including filesystem, boot, networking, logging, and access control.
Red Hat Enterprise Linux 8
v1.0.0May 2026Security configuration guidelines for RHEL 8 covering crypto policies, firewalld, auditd, authselect, SELinux, dnf package management, and SSH/PAM hardening.
Red Hat Enterprise Linux 9
v2.0.0March 2025Security configuration guidelines for RHEL 9 including SELinux, firewalld, auditd, SSH hardening, and PAM policies.
macOS 15.0 Sequoia
v1.0.0January 2025Security configuration guidelines for macOS Sequoia covering FileVault, Gatekeeper, SIP, firewall, and privacy controls.
Debian Linux 12
v1.1.0September 2024Security configuration guidelines for Debian 12 (Bookworm) covering AppArmor, nftables, auditd, SSH, PAM, and system maintenance.
Windows 11 Enterprise
v3.0.0February 2025Security configuration guidelines for Windows 11 Enterprise covering account policies, audit policy, Defender & Firewall, BitLocker, and Credential Guard.
Amazon Linux 2
v1.0.0May 2026Security configuration guidelines for Amazon Linux 2 covering filesystem, yum package management, iptables firewall, auditd, SSH/PAM hardening, and system maintenance.
Amazon Linux 2023
v1.1.0March 2025Security configuration guidelines for Amazon Linux 2023 covering filesystem hardening, services, network, logging, SSH/PAM, and user maintenance.
Rocky Linux 9
v2.0.0February 2025Security configuration guidelines for Rocky Linux 9 covering filesystem partitioning, services, network configuration, auditd, SSH/PAM, and system maintenance.
Oracle Linux 9
v1.0.0December 2024Security configuration guidelines for Oracle Linux 9 covering filesystem hardening, service management, network configuration, logging, SSH/PAM, and system maintenance.
AlmaLinux 9
v1.0.0November 2024Security configuration guidelines for AlmaLinux 9 covering filesystem configuration, service hardening, network configuration, logging, SSH/PAM, and system maintenance.
SUSE Linux Enterprise 15
v1.1.0January 2025Security configuration guidelines for SUSE Linux Enterprise 15 covering filesystem configuration, service management, network parameters, logging, SSH/PAM hardening, and system maintenance.
CentOS Linux 7
v3.1.0June 2024Security configuration guidelines for CentOS Linux 7 covering filesystem configuration, services, network parameters, logging and auditing, SSH/PAM hardening, and system maintenance.
Windows 10 Enterprise
v3.0.0November 2024Security configuration guidelines for Windows 10 Enterprise covering account policies, local policies, Windows Firewall, audit policy, Defender & Credential Guard, and BitLocker.
Windows Server 2019
v2.0.0September 2024Security configuration guidelines for Windows Server 2019 covering account policies, local policies, Windows Firewall, audit policy, advanced security, and administrative templates.
Windows Server 2016
v2.0.0August 2024Security configuration guidelines for Windows Server 2016 covering account policies, local policies, Windows Firewall, audit policy, advanced security, and administrative templates.
Debian Linux 11
v2.0.0March 2024Security configuration guidelines for Debian Linux 11 (Bullseye) covering filesystem configuration, services, network parameters, logging, SSH/PAM hardening, and system maintenance.
Fedora 40
v1.0.0October 2024Security configuration guidelines for Fedora Linux 40 covering filesystem configuration, services, network parameters, logging, SSH/PAM hardening, and system maintenance.
Oracle Solaris 11.4
v1.0.0May 2026Security configuration guidelines for Oracle Solaris 11.4 covering IPS packaging, SMF services, ipadm networking, BSM auditing, IPFilter firewall, and ZFS security.
IBM AIX 7.3
v1.0.0May 2026Security configuration guidelines for IBM AIX 7.3 covering system configuration, TCP/IP security, IPsec filtering, audit subsystem, user account hardening, and trusted computing.
FreeBSD 14
v1.0.0May 2026Security configuration guidelines for FreeBSD 14 covering system access, services, PF firewall, filesystem permissions, BSM audit, network hardening, and update management using sysrc and sysctl.
OpenBSD 7
v1.0.0Jan 2025Security configuration guidelines for OpenBSD 7 covering SSH hardening, access control with doas, PF firewall, filesystem security, kernel security levels, network hardening, and system maintenance with syspatch.
Container & Orchestration
Hardening benchmarks for container runtimes and orchestration platforms.
Kubernetes
v1.10.0October 2024Security configuration guidelines for Kubernetes covering API server, controller manager, scheduler, etcd, kubelet, and network policies.
Docker
v1.7.0September 2024Security configuration guidelines for Docker including daemon configuration, container images, runtime, and Docker Swarm.
Amazon EKS
v1.5.0January 2025Security configuration guidelines for Amazon EKS covering control plane configuration, worker node security, network policies, IAM/RBAC, logging, and pod security.
Azure Kubernetes Service (AKS)
v1.5.0January 2025Security configuration guidelines for Azure Kubernetes Service covering cluster configuration, identity and access management, networking, workload security, data protection, and logging.
Red Hat OpenShift Container Platform
v1.6.0February 2025Security configuration guidelines for Red Hat OpenShift Container Platform 4 covering control plane, worker nodes, RBAC, networking, pod security, and logging.
Google Kubernetes Engine (GKE)
v1.0.0January 2025Security configuration guidelines for GKE clusters covering identity and Workload Identity, RBAC, network security, node hardening, cluster management, and data protection using gcloud and kubectl.
Podman
v1.0.0May 2026Security configuration guidelines for Podman covering rootless operation, image provenance, registry configuration, seccomp profiles, network isolation, Quadlet units, and resource governance.
Rancher
v1.0.0Jan 2025Security configuration guidelines for Rancher Kubernetes management covering authentication, RBAC, CIS hardening profiles, network isolation, workload security, data protection, and monitoring with Fleet GitOps.
HashiCorp Nomad
v1.0.0Jan 2025Security configuration guidelines for HashiCorp Nomad covering ACL bootstrapping, mTLS encryption, gossip security, namespace isolation, Vault integration, Sentinel policies, Consul Connect mesh, and snapshot automation.
Istio
v1.0.0Jan 2025Security configuration guidelines for Istio service mesh covering mutual TLS enforcement, authorization policies, peer authentication, gateway hardening, egress control, rate limiting, Envoy access logging, and control plane security.
ArgoCD
v1.0.0Jan 2025Security configuration guidelines for ArgoCD covering SSO integration, RBAC policies, repository credential management, TLS enforcement, application sync policies, resource whitelisting, audit logging, and HA Redis clustering.
Harbor
v1.0.0Jan 2025Security configuration guidelines for Harbor container registry covering OIDC authentication, RBAC project policies, TLS enforcement, vulnerability scanning, content trust with Cosign, garbage collection, replication, and audit logging.
Cilium
v1.0.0Mar 2025Security configuration guidelines for Cilium eBPF networking covering RBAC, CiliumNetworkPolicy enforcement, WireGuard transparent encryption, Hubble observability, host firewall, L7 policy controls, and identity-aware access management.
Linkerd
v1.0.0Mar 2025Security configuration guidelines for Linkerd service mesh covering trust anchor management, mutual TLS enforcement, authorization policies, dashboard RBAC, observability, traffic management, proxy hardening, and certificate rotation.
K3s
v1.0.0Mar 2025Security configuration guidelines for K3s lightweight Kubernetes covering API server authentication, RBAC least privilege, secrets encryption at rest, TLS certificate management, audit logging, network policies, Pod Security Standards, and etcd snapshot backups.
Containerd
v1.0.0Mar 2025Security configuration guidelines for Containerd container runtime covering systemd cgroup driver, seccomp profiles, registry TLS, gRPC socket permissions, namespace isolation, storage drivers, file permissions, and image source restrictions.
Databases
Hardening benchmarks for relational and NoSQL database management systems.
PostgreSQL 16
v1.0.0August 2024Security configuration guidelines for PostgreSQL 16 including installation, file permissions, logging, user access, SSL/TLS, and replication.
MySQL 8.0
v1.1.0October 2024Security configuration guidelines for MySQL 8.0 covering installation, file permissions, authentication, network, auditing, and replication.
MongoDB 8.0
v1.0.0November 2024Security configuration guidelines for MongoDB 8.0 covering authentication, access control, auditing, encryption, network, and replica set security.
Microsoft SQL Server 2022
v1.1.0September 2024Security configuration guidelines for MS SQL Server 2022 covering installation, authentication, auditing, encryption, and database engine settings.
Oracle Database 19c
v1.2.0January 2025Security configuration guidelines for Oracle Database 19c covering installation, instance configuration, user accounts, privileges, auditing, and encryption.
Redis 7
v1.1.0November 2024Security configuration guidelines for Redis 7 covering authentication, ACL management, TLS, dangerous command restrictions, persistence, and monitoring.
MariaDB 10.11
v1.0.0December 2024Security configuration guidelines for MariaDB 10.11 covering installation, authentication, network security, auditing, privilege management, and replication encryption.
Apache CouchDB 3
v1.0.0October 2024Security configuration guidelines for Apache CouchDB 3 covering installation hardening, authentication, network security, TLS encryption, logging, and replication/cluster security.
Elasticsearch 8
v1.1.0December 2024Security configuration guidelines for Elasticsearch 8 covering installation, authentication, network security, TLS encryption, cluster management, and audit logging.
IBM Db2
v1.1.0October 2024Security configuration guidelines for IBM Db2 covering installation, authentication, authorization, network security, auditing, and data protection.
Apache Cassandra 4.1
v1.0.0November 2024Security configuration guidelines for Apache Cassandra 4.1 covering installation, authentication, authorization, encryption, audit logging, and operational security.
SAP HANA 2.0
v1.0.0May 2026Security configuration guidelines for SAP HANA 2.0 covering SSL/TLS, password policies, authorization, auditing, data-at-rest encryption, key management, and operational security.
Snowflake
v1.0.0January 2025Security configuration guidelines for Snowflake cloud data platform covering account configuration, IAM, data protection, monitoring, warehouse security, and data masking policies using SQL commands.
Neo4j 5
v1.0.0January 2025Security configuration guidelines for Neo4j 5 graph database covering authentication, password policies, RBAC, SSL/TLS, Bolt encryption, procedure restrictions, logging, and JMX security.
InfluxDB 2
v1.0.0May 2026Security configuration guidelines for InfluxDB 2 covering authentication, API token management, TLS transport, bucket retention, Flux query restrictions, backup encryption, and audit logging.
Couchbase 7
v1.0.0Jan 2025Security configuration guidelines for Couchbase Server 7 covering LDAP authentication, RBAC, encryption in transit and at rest, XDCR security, audit logging, cluster management, and query service security.
TimescaleDB
v1.0.0Jan 2025Security configuration guidelines for TimescaleDB covering SCRAM-SHA-256 authentication, TLS 1.3 encryption, hypertable access control, retention policies, compression, pgAudit logging, row-level security, and replication.
CockroachDB
v1.0.0Jan 2025Security configuration guidelines for CockroachDB covering SCRAM-SHA-256 authentication, mutual TLS, AES-256 encryption at rest, multi-region replication, automated backups, SQL audit logging, admission control, and CA rotation.
etcd
v1.0.0Mar 2025Security configuration guidelines for etcd covering client/peer mutual TLS, RBAC authentication, snapshot backups, auto-compaction, peer URL restrictions, cluster health monitoring, defragmentation, and version management.
Memcached
v1.0.0Mar 2025Security configuration guidelines for Memcached covering network binding restrictions, SASL and TLS authentication, connection logging, resource limits, memory management, network security, and maintenance procedures.
Apache Solr
v1.0.0Mar 2025Security configuration guidelines for Apache Solr covering authentication plugins, role-based authorization, TLS encryption, ZooKeeper security, audit logging, network binding, data directory permissions, Config API restriction, and feature hardening.
OpenSearch
v1.0.0Mar 2025Security configuration guidelines for OpenSearch covering Security plugin activation, internal user authentication, RBAC, transport and REST layer TLS, audit logging, network binding, JVM heap limits, index state management, and snapshot backup encryption.
ClickHouse
v1.0.0Mar 2025Security configuration guidelines for ClickHouse columnar database covering SHA256 authentication, RBAC, client and inter-server TLS, query and server logging, network binding, resource limits, encryption at rest, backup procedures, and TTL retention policies.
Server Software
Benchmarks for web servers, application servers, and reverse proxies.
Nginx
v2.1.0June 2024Security configuration guidelines for Nginx web server and reverse proxy covering TLS, security headers, rate limiting, and information disclosure.
Apache HTTP Server 2.4
v2.2.0August 2024Security configuration guidelines for Apache HTTP Server 2.4 covering modules, directory permissions, logging, SSL/TLS, and request limits.
Apache Tomcat 10
v1.1.0August 2024Security configuration guidelines for Apache Tomcat 10 covering installation, connectors, TLS, logging, account management, and session security.
Microsoft IIS 10
v1.2.1March 2025Security configuration guidelines for Microsoft IIS 10 covering authentication, request filtering, TLS/HSTS, application pools, and security headers.
HAProxy 2.8
v1.0.0January 2025Security configuration guidelines for HAProxy 2.8 LTS covering TLS termination, access control, rate limiting, security headers, logging, and health checks.
Splunk Enterprise
v1.1.0November 2024Security configuration guidelines for Splunk Enterprise covering deployment, authentication, data security, search configuration, TLS, and audit logging.
HashiCorp Vault
v1.0.0October 2024Security configuration guidelines for HashiCorp Vault covering storage backend, authentication methods, secrets engines, audit logging, TLS/API hardening, and operational security.
Apache Kafka
v1.0.0October 2024Security configuration guidelines for Apache Kafka covering installation hardening, authentication and authorization, network security, encryption, topic and cluster management, and monitoring.
BIND 9 DNS Server
v1.0.0May 2026Security configuration guidelines for ISC BIND 9 covering zone transfer restrictions, DNSSEC, recursion controls, response rate limiting, TSIG authentication, and file permissions.
Microsoft Exchange Server 2019
v2.0.0January 2025Security configuration guidelines for Microsoft Exchange Server 2019 covering transport, client access, mailbox security, RBAC permissions, logging, and server hardening.
GitLab
v1.0.0January 2025Security configuration guidelines for self-managed GitLab instances covering authentication, token management, TLS, repository protection, CI/CD hardening, audit logging, backups, and container registry security.
RabbitMQ 3.13
v1.0.0January 2025Security configuration guidelines for RabbitMQ 3.13 message broker covering authentication, vhost isolation, TLS transport, resource limits, cluster security, and logging using rabbitmqctl and rabbitmq.conf.
Ansible Automation Platform
v1.0.0May 2026Security configuration guidelines for Ansible Automation Platform covering controller authentication, RBAC, credential encryption with ansible-vault, playbook linting, execution environment isolation, and audit logging.
Postfix
v1.0.0May 2026Security configuration guidelines for Postfix MTA covering SASL authentication, TLS transport, relay restrictions, SPF/DKIM verification, chroot isolation, rate limiting, and postconf hardening.
Jenkins
v1.0.0Jan 2025Security configuration guidelines for Jenkins CI/CD covering authentication, controller hardening, credential management, plugin governance, build agent security, audit logging, and web security.
Grafana
v1.0.0Jan 2025Security configuration guidelines for Grafana covering authentication, access control, data source security, plugin governance, alerting configuration, audit logging, and web security with HTTPS and CSP.
Keycloak
v1.0.0Jan 2025Security configuration guidelines for Keycloak IAM covering realm security, authentication flows, client configuration, token management, admin console security, event logging, and transport security.
HashiCorp Consul
v1.0.0Jan 2025Security configuration guidelines for HashiCorp Consul covering ACL deny-default policies, TLS encryption, gossip key management, Connect service mesh, intention security, KV store access, audit logging, and snapshot recovery.
Traefik
v1.0.0Jan 2025Security configuration guidelines for Traefik covering HTTPS entrypoints, TLS options, dashboard authentication, rate limiting, security headers, Let's Encrypt ACME, circuit breakers, Docker provider security, and systemd hardening.
SonarQube
v1.0.0Jan 2025Security configuration guidelines for SonarQube covering authentication enforcement, LDAP/SAML integration, permission templates, quality gate policies, security hotspot review, plugin management, database SSL, and token security.
FreeIPA
v1.0.0Jan 2025Security configuration guidelines for FreeIPA covering password and Kerberos policies, OTP two-factor authentication, HBAC rules, sudo delegation, certificate authority, replication topology, DNSSEC validation, and audit logging.
MinIO
v1.0.0Jan 2025Security configuration guidelines for MinIO covering IAM policy-based access, TLS enforcement, server-side encryption with KMS, bucket policies, object locking, versioning, audit webhook logging, erasure coding, and site replication.
Prometheus
v1.0.0Jan 2025Security configuration guidelines for Prometheus covering basic authentication, TLS encryption, scrape target authorization, recording rules, Alertmanager routing, remote write/read, TSDB retention, WAL configuration, and federation.
Grafana Loki
v1.0.0Jan 2025Security configuration guidelines for Grafana Loki covering multi-tenancy, reverse proxy authentication, TLS encryption, encrypted storage backends, retention policies, rate limiting, Promtail pipelines, alerting rules, and clustering.
Teleport
v1.0.0Jan 2025Security configuration guidelines for Teleport covering SSO with WebAuthn MFA, least-privilege RBAC, enhanced session recording, trusted cluster federation, database and application proxying, audit event storage, HA backends, and CA rotation.
Envoy Proxy
v1.0.0Mar 2025Security configuration guidelines for Envoy Proxy covering TLS enforcement, admin interface lockdown, access logging, rate limiting, CORS policy, circuit breakers, health check endpoints, and hot restart configuration.
OpenLDAP
v1.0.0Mar 2025Security configuration guidelines for OpenLDAP covering StartTLS/LDAPS enforcement, ACL-based access control, password policy overlay, audit logging, size/time limits, database tuning, and backup procedures.
Squid Proxy
v1.0.0Mar 2025Security configuration guidelines for Squid caching proxy covering ACL-based access control, NCSA authentication, HTTPS interception, access logging, cache management, header stripping, URL filtering, and log rotation.
Nagios Core
v1.0.0Mar 2025Security configuration guidelines for Nagios Core covering HTTPS web interface, authentication hardening, NRPE SSL, file permissions, notification configuration, CGI authorization, resource file protection, and config verification.
HashiCorp Boundary
v1.0.0Mar 2025Security configuration guidelines for HashiCorp Boundary covering controller TLS, OIDC authentication, RBAC roles, worker authentication, KMS seals, audit event logging, session recording, credential brokering, and scope organization.
Apache Airflow
v1.0.0Mar 2025Security configuration guidelines for Apache Airflow covering authentication backends, RBAC, HTTPS enforcement, Fernet encryption, remote logging, production database backend, executor configuration, API authentication, and secrets backend integration.
Zabbix
v1.0.0Mar 2025Security configuration guidelines for Zabbix monitoring platform covering web frontend HTTPS, database and agent TLS encryption, audit logging, API security, alerting configuration, proxy hardening, and maintenance procedures.
Caddy
v1.0.0Mar 2025Security configuration guidelines for Caddy web server covering automatic HTTPS, TLS configuration, HTTP security headers, access logging, reverse proxy authentication, admin API restriction, file server hardening, and certificate management.
Fluentd
v1.0.0Mar 2025Security configuration guidelines for Fluentd log aggregation covering input/output TLS encryption, data filtering, internal logging, resource management, error handling, plugin security, secrets management, and buffer configuration.
Kong Gateway
v1.0.0Mar 2025Security configuration guidelines for Kong API Gateway covering Admin API restriction, RBAC enforcement, proxy and upstream TLS, access logging, rate limiting, authentication plugins, IP restriction, CORS policies, and database TLS hardening.
Ceph
v1.0.0Mar 2025Security configuration guidelines for Ceph distributed storage covering CephX authentication, keyring management, messenger v2 encryption, RGW TLS, network separation, dashboard security, OSD encryption at rest, and CRUSH rule configuration.
Dovecot
v1.0.0Mar 2025Security configuration guidelines for Dovecot IMAP/POP3 mail server covering TLS enforcement, plaintext authentication disabling, protocol restriction, connection limits, mail event logging, quota management, Sieve filtering, and authentication backend hardening.
Logstash
v1.0.0Mar 2025Security configuration guidelines for Logstash data processing pipeline covering API authentication, keystore secrets management, TLS on inputs and outputs, logging and slowlog configuration, binding restrictions, persistent queue settings, and JVM security hardening.
Kibana
v1.0.0Mar 2025Security configuration guidelines for Kibana visualization platform covering authentication providers, session management, spaces-based RBAC, HTTPS/TLS, audit logging, CSP headers, saved objects encryption, keystore management, and feature disablement.
Graylog
v1.0.0Mar 2025Security configuration guidelines for Graylog log management covering root password hardening, LDAP/AD authentication, HTTPS/TLS, Elasticsearch TLS, audit logging, network binding, input security, file permissions, JVM hardening, and plugin management.
Varnish Cache
v1.0.0Mar 2025Security configuration guidelines for Varnish Cache HTTP accelerator covering VCL ACL configuration, management interface security, backend health checks, NCSA logging, security headers, request filtering, cache policy, and resource limits.
Network Devices
Hardening benchmarks for routers, switches, and network infrastructure devices.
Cisco IOS 17
v2.1.0January 2025Security configuration guidelines for Cisco IOS 17 covering management plane, control plane, data plane, access lists, services, and IOS hardening.
Palo Alto Firewall PAN-OS 11
v1.2.0February 2025Security configuration guidelines for Palo Alto PAN-OS 11 covering device management, network security, security policies, SSL decryption, logging, and HA.
Juniper JunOS
v2.1.0February 2025Security configuration guidelines for Juniper JunOS covering management plane, authentication, system services, routing protocol hardening, logging, and network resilience.
F5 BIG-IP
v1.1.0November 2024Security configuration guidelines for F5 BIG-IP covering system configuration, authentication, network security, SSL/TLS profiles, logging, and high availability hardening.
Fortinet FortiGate
v1.3.0December 2024Security configuration guidelines for Fortinet FortiGate covering system administration, authentication, firewall policies, VPN configuration, logging, and intrusion prevention.
Cisco Meraki
v1.0.0January 2025Security configuration guidelines for Cisco Meraki cloud-managed infrastructure covering dashboard administration, network configuration, wireless security, content filtering, VPN, and monitoring.
Check Point Firewall
v1.1.0November 2024Security configuration guidelines for Check Point Security Gateways covering system configuration, authentication, security policy, VPN, logging and monitoring, and high availability.
Arista EOS
v1.0.0November 2024Security configuration guidelines for Arista EOS network devices covering management plane, authentication, control plane, data plane, logging, and system hardening.
Sophos Firewall
v1.0.0December 2024Security configuration guidelines for Sophos Firewall (SFOS) covering system configuration, authentication, firewall rules, VPN, web protection, and logging and monitoring.
Cisco NX-OS
v1.0.0January 2025Security configuration guidelines for Cisco Nexus switches running NX-OS covering management plane, SSH/transport, CoPP, routing authentication, logging, NTP, SNMP, port security, and ACLs.
pfSense
v1.0.0January 2025Security configuration guidelines for pfSense firewall/router covering system updates, authentication, WebGUI hardening, firewall rules, VPN security, DNS over TLS, and OS-level hardening using pfctl and sysctl.
Ubiquiti UniFi
v1.0.0May 2026Security configuration guidelines for Ubiquiti UniFi covering controller security, VLAN segmentation, WPA3 wireless, IPS/IDS, firewall rules, DPI configuration, and device firmware management via UniFi API.
MikroTik RouterOS
v1.0.0Jan 2025Security configuration guidelines for MikroTik RouterOS covering user management, firewall hardening, network services, service hardening, logging, cryptography, and system maintenance.
Cumulus Linux
v1.0.0Jan 2025Security configuration guidelines for Cumulus Linux covering NVUE ACLs, control plane policing, management VRF, SNMPv3, syslog forwarding, NTP authentication, STP hardening, storm control, BGP/OSPF MD5 authentication, and route filtering.
WireGuard
v1.0.0Jan 2025Security configuration guidelines for WireGuard VPN covering key management, AllowedIPs restrictions, firewall integration, DNS leak prevention, preshared keys, logging, peer rotation, and kill switch configuration.
OPNsense
v1.0.0Jan 2025Security configuration guidelines for OPNsense firewall covering admin authentication, TLS enforcement, firewall rule hardening, Suricata IDS/IPS, VPN gateway security, DNS filtering, CARP high availability, and syslog audit forwarding.
Suricata
v1.0.0Mar 2025Security configuration guidelines for Suricata IDS/IPS covering IPS mode configuration, rule management, EVE JSON logging, protocol analysis, network variable tuning, stream engine optimization, and rule update automation.
Cisco ASA
v1.0.0Mar 2025Security configuration guidelines for Cisco ASA covering password encryption, AAA authentication, management access restriction, TLS hardening, syslog logging, NTP authentication, threat detection, IKEv2 VPN, and protocol hardening.
Pi-hole
v1.0.0Mar 2025Security configuration guidelines for Pi-hole DNS filtering covering admin interface HTTPS, upstream DNS-over-HTTPS, DNSSEC validation, query logging privacy, interface restriction, rate limiting, blocklist management, regex filtering, and backup procedures.
Calico
v1.0.0Mar 2025Security configuration guidelines for Calico network policy engine covering default-deny global policies, WireGuard encryption, Typha TLS, flow logging, IP pool configuration, BGP peering security, Felix settings, host endpoint protection, and policy tier management.
Tailscale
v1.0.0Mar 2025Security configuration guidelines for Tailscale mesh VPN covering ACL policy configuration, device authorization, MagicDNS, key expiry management, network flow logging, subnet route restrictions, exit node security, Tailscale SSH hardening, and Funnel/Serve controls.
Virtualization
Hardening benchmarks for hypervisors and virtual infrastructure platforms.
VMware ESXi 8
v1.1.0November 2024Security configuration guidelines for VMware ESXi 8 covering installation, communication, logging, access control, VM hardening, and storage security.
Citrix Hypervisor
v1.0.0August 2024Security configuration guidelines for Citrix Hypervisor (XenServer) covering installation hardening, authentication, network configuration, storage security, VM management, and logging.
Microsoft Hyper-V
v1.0.0September 2024Security configuration guidelines for Microsoft Hyper-V covering host configuration, virtual machine settings, networking, storage, access control, and monitoring.
VMware vCenter 8
v1.0.0May 2026Security configuration guidelines for VMware vCenter Server 8 covering SSO policies, role-based access, network security, VM isolation, syslog, TLS, and service hardening.
Proxmox VE 8
v1.0.0January 2025Security configuration guidelines for Proxmox VE 8 covering authentication, RBAC, network security, storage encryption, VM/container hardening, cluster security, and host hardening using pvesh, pveum, qm, and pct.
Nutanix AHV
v1.0.0May 2026Security configuration guidelines for Nutanix AHV covering Prism authentication, RBAC, Flow microsegmentation, VM hardening, cluster encryption, SCMA compliance, and CVM security using ncli and acli.
KVM / libvirt
v1.0.0Jan 2025Security configuration guidelines for KVM/libvirt covering host access control, mandatory access controls, network security, storage encryption, migration TLS, resource management, and audit logging.
XCP-ng
v1.0.0Jan 2025Security configuration guidelines for XCP-ng covering RBAC and SSH hardening, VLAN network isolation, host firewall, iSCSI CHAP storage authentication, VM resource limits, backup automation, centralized logging, and TLS certificate deployment.
Desktop Software
Security benchmarks for desktop applications and end-user software.
Google Chrome
v3.0.0January 2025Security configuration guidelines for Google Chrome enterprise covering extensions, privacy, network security, content settings, authentication, and update policies.
Microsoft Edge
v3.0.0January 2025Security configuration guidelines for Microsoft Edge enterprise covering extensions, privacy, SmartScreen, content filtering, authentication, and update policies.
Mozilla Firefox
v2.0.0October 2024Security configuration guidelines for Mozilla Firefox enterprise covering extensions, tracking protection, network security, certificates, and enterprise policies.
Apple Safari 18
v1.0.0May 2026Security configuration guidelines for Apple Safari 18 covering privacy, autofill, extensions, HTTPS enforcement, developer tools, and data protection via macOS defaults.
Zoom Workplace
v1.0.0January 2025Security configuration guidelines for Zoom Workplace covering account security, encryption, data protection, meeting controls, chat restrictions, authentication, and client management via admin portal and GPO/MDM policies.
Slack Enterprise
v1.0.0May 2026Security configuration guidelines for Slack Enterprise covering SSO authentication, session management, DLP policies, external sharing controls, app governance, audit log forwarding, and eDiscovery compliance.
Microsoft Teams
v1.0.0Jan 2025Security configuration guidelines for Microsoft Teams covering external access, meeting policies, messaging controls, app governance, data loss prevention, identity management, and audit compliance.
Brave Browser
v1.0.0Jan 2025Security and privacy configuration guidelines for Brave Browser covering Shields defaults, cookie policies, WebRTC leak prevention, fingerprint blocking, extension governance, HTTPS-Only mode, DNS-over-HTTPS, telemetry controls, and Tor window usage.
Mobile Devices
Security benchmarks for mobile operating systems and enterprise device management.
Apple iOS 18
v1.0.0March 2025Security configuration guidelines for Apple iOS 18 covering passcode policies, network settings, app management, privacy, iCloud, and enterprise MDM configuration.
Android 14 Enterprise
v1.0.0February 2025Security configuration guidelines for Android 14 enterprise covering device lock, network configuration, app management, data protection, EMM policies, and developer settings.
Microsoft Intune
v2.0.0March 2025Security configuration guidelines for Microsoft Intune covering device enrollment, compliance policies, configuration profiles, app protection, conditional access, and monitoring.
Samsung Knox
v1.0.0May 2026Security configuration guidelines for Samsung Knox covering Knox Manage enrollment, KPE policy enforcement, containerization, E-FOTA firmware control, network protection, and enterprise device attestation.