Microsoft 365

Secure configuration benchmarks for Microsoft 365 cloud productivity and collaboration services.

Microsoft 365 Foundations

v6.0.1February 2026

Comprehensive security configuration guidelines covering Microsoft Entra ID, Exchange Online, SharePoint, Teams, Defender, and Purview across E3/E5/F1/F3 license tiers.

7 Sections 194 Recommendations 2 Profile Levels

Microsoft SharePoint Server 2019

v1.0.0January 2025

Security configuration guidelines for SharePoint Server 2019 covering service accounts, authentication, SSL, logging, app management, backup, web application security, and Central Administration hardening.

8 Sections ~150 Recommendations 2 Profile Levels

Cloud Infrastructure

Benchmarks for cloud platform services including compute, storage, networking, and identity.

Microsoft Azure Foundations

v3.0.0February 2025

Security configuration guidelines for Microsoft Azure infrastructure services, IAM, networking, storage, logging, and monitoring.

9 Sections ~200 Recommendations 2 Profile Levels

Amazon Web Services Foundations

v4.0.1December 2024

Security configuration guidelines for AWS services including IAM, S3, EC2, CloudTrail, VPC, and RDS.

5 Sections ~250 Recommendations 2 Profile Levels

Google Cloud Platform Foundations

v4.0.0October 2024

Security configuration guidelines for Google Cloud including IAM, compute, storage, networking, and logging.

7 Sections ~200 Recommendations 2 Profile Levels

Oracle Cloud Infrastructure Foundations

v2.0.0December 2024

Security configuration guidelines for Oracle Cloud Infrastructure covering IAM, networking, compute, storage, database, and logging and monitoring.

6 Sections ~110 Recommendations 2 Profile Levels

Alibaba Cloud Foundations

v1.0.0September 2024

Security configuration guidelines for Alibaba Cloud (Aliyun) covering RAM identity management, VPC networking, ECS compute, OSS storage, database services, and logging and monitoring.

6 Sections ~100 Recommendations 2 Profile Levels

Google Workspace

v1.0.0May 2026

Security configuration guidelines for Google Workspace covering Admin Console settings, authentication, Gmail security, Drive sharing, mobile management, and audit logging.

6 Sections ~120 Recommendations 2 Profile Levels

Terraform Enterprise

v1.0.0May 2026

Security configuration guidelines for Terraform Enterprise covering organization settings, workspace security, VCS and run security, Sentinel policy enforcement, API token management, network isolation, and audit logging.

7 Sections ~100 Recommendations 2 Profile Levels

GitHub Enterprise

v1.0.0Jan 2025

Security configuration guidelines for GitHub Enterprise covering organization security, authentication with SAML SSO, repository protection, Actions security, supply chain security with Dependabot, code scanning, and audit log streaming.

7 Sections ~160 Recommendations 2 Profile Levels

DigitalOcean

v1.0.0Jan 2025

Security configuration guidelines for DigitalOcean cloud infrastructure covering VPC networking, firewall rules, Droplet hardening, Spaces object storage, managed databases, Kubernetes (DOKS), load balancers, and DNS security.

7 Sections ~160 Recommendations 2 Profile Levels

Operating Systems

Hardening benchmarks for server and desktop operating systems.

Windows Server 2022

v3.0.0March 2025

Security configuration guidelines for Microsoft Windows Server 2022 including account policies, audit settings, and security options.

6 Sections ~370 Recommendations 3 Profile Levels

Ubuntu Linux 24.04 LTS

v1.0.0May 2026

Security configuration guidelines for Ubuntu 24.04 LTS (Noble Numbat) covering filesystem, boot, services, network, logging, SSH/PAM, and system maintenance.

6 Sections ~300 Recommendations 2 Profile Levels

Ubuntu Linux 22.04 LTS

v2.0.0January 2024

Security configuration guidelines for Ubuntu Linux including filesystem, boot, networking, logging, and access control.

6 Sections ~300 Recommendations 2 Profile Levels

Red Hat Enterprise Linux 8

v1.0.0May 2026

Security configuration guidelines for RHEL 8 covering crypto policies, firewalld, auditd, authselect, SELinux, dnf package management, and SSH/PAM hardening.

6 Sections ~250 Recommendations 2 Profile Levels

Red Hat Enterprise Linux 9

v2.0.0March 2025

Security configuration guidelines for RHEL 9 including SELinux, firewalld, auditd, SSH hardening, and PAM policies.

6 Sections ~250 Recommendations 2 Profile Levels

macOS 15.0 Sequoia

v1.0.0January 2025

Security configuration guidelines for macOS Sequoia covering FileVault, Gatekeeper, SIP, firewall, and privacy controls.

5 Sections ~150 Recommendations 2 Profile Levels

Debian Linux 12

v1.1.0September 2024

Security configuration guidelines for Debian 12 (Bookworm) covering AppArmor, nftables, auditd, SSH, PAM, and system maintenance.

6 Sections ~280 Recommendations 2 Profile Levels

Windows 11 Enterprise

v3.0.0February 2025

Security configuration guidelines for Windows 11 Enterprise covering account policies, audit policy, Defender & Firewall, BitLocker, and Credential Guard.

6 Sections ~180 Recommendations 2 Profile Levels

Amazon Linux 2

v1.0.0May 2026

Security configuration guidelines for Amazon Linux 2 covering filesystem, yum package management, iptables firewall, auditd, SSH/PAM hardening, and system maintenance.

6 Sections ~200 Recommendations 2 Profile Levels

Amazon Linux 2023

v1.1.0March 2025

Security configuration guidelines for Amazon Linux 2023 covering filesystem hardening, services, network, logging, SSH/PAM, and user maintenance.

6 Sections ~150 Recommendations 2 Profile Levels

Rocky Linux 9

v2.0.0February 2025

Security configuration guidelines for Rocky Linux 9 covering filesystem partitioning, services, network configuration, auditd, SSH/PAM, and system maintenance.

6 Sections ~160 Recommendations 2 Profile Levels

Oracle Linux 9

v1.0.0December 2024

Security configuration guidelines for Oracle Linux 9 covering filesystem hardening, service management, network configuration, logging, SSH/PAM, and system maintenance.

6 Sections ~250 Recommendations 2 Profile Levels

AlmaLinux 9

v1.0.0November 2024

Security configuration guidelines for AlmaLinux 9 covering filesystem configuration, service hardening, network configuration, logging, SSH/PAM, and system maintenance.

6 Sections ~240 Recommendations 2 Profile Levels

SUSE Linux Enterprise 15

v1.1.0January 2025

Security configuration guidelines for SUSE Linux Enterprise 15 covering filesystem configuration, service management, network parameters, logging, SSH/PAM hardening, and system maintenance.

6 Sections ~260 Recommendations 2 Profile Levels

CentOS Linux 7

v3.1.0June 2024

Security configuration guidelines for CentOS Linux 7 covering filesystem configuration, services, network parameters, logging and auditing, SSH/PAM hardening, and system maintenance.

6 Sections ~250 Recommendations 2 Profile Levels

Windows 10 Enterprise

v3.0.0November 2024

Security configuration guidelines for Windows 10 Enterprise covering account policies, local policies, Windows Firewall, audit policy, Defender & Credential Guard, and BitLocker.

6 Sections ~180 Recommendations 2 Profile Levels

Windows Server 2019

v2.0.0September 2024

Security configuration guidelines for Windows Server 2019 covering account policies, local policies, Windows Firewall, audit policy, advanced security, and administrative templates.

6 Sections ~350 Recommendations 2 Profile Levels

Windows Server 2016

v2.0.0August 2024

Security configuration guidelines for Windows Server 2016 covering account policies, local policies, Windows Firewall, audit policy, advanced security, and administrative templates.

6 Sections ~330 Recommendations 2 Profile Levels

Debian Linux 11

v2.0.0March 2024

Security configuration guidelines for Debian Linux 11 (Bullseye) covering filesystem configuration, services, network parameters, logging, SSH/PAM hardening, and system maintenance.

6 Sections ~270 Recommendations 2 Profile Levels

Fedora 40

v1.0.0October 2024

Security configuration guidelines for Fedora Linux 40 covering filesystem configuration, services, network parameters, logging, SSH/PAM hardening, and system maintenance.

6 Sections ~280 Recommendations 2 Profile Levels

Oracle Solaris 11.4

v1.0.0May 2026

Security configuration guidelines for Oracle Solaris 11.4 covering IPS packaging, SMF services, ipadm networking, BSM auditing, IPFilter firewall, and ZFS security.

6 Sections ~180 Recommendations 2 Profile Levels

IBM AIX 7.3

v1.0.0May 2026

Security configuration guidelines for IBM AIX 7.3 covering system configuration, TCP/IP security, IPsec filtering, audit subsystem, user account hardening, and trusted computing.

6 Sections ~160 Recommendations 2 Profile Levels

FreeBSD 14

v1.0.0May 2026

Security configuration guidelines for FreeBSD 14 covering system access, services, PF firewall, filesystem permissions, BSM audit, network hardening, and update management using sysrc and sysctl.

7 Sections ~120 Recommendations 2 Profile Levels

OpenBSD 7

v1.0.0Jan 2025

Security configuration guidelines for OpenBSD 7 covering SSH hardening, access control with doas, PF firewall, filesystem security, kernel security levels, network hardening, and system maintenance with syspatch.

7 Sections ~160 Recommendations 2 Profile Levels

Container & Orchestration

Hardening benchmarks for container runtimes and orchestration platforms.

Kubernetes

v1.10.0October 2024

Security configuration guidelines for Kubernetes covering API server, controller manager, scheduler, etcd, kubelet, and network policies.

5 Sections ~250 Recommendations 2 Profile Levels

Docker

v1.7.0September 2024

Security configuration guidelines for Docker including daemon configuration, container images, runtime, and Docker Swarm.

5 Sections ~120 Recommendations 2 Profile Levels

Amazon EKS

v1.5.0January 2025

Security configuration guidelines for Amazon EKS covering control plane configuration, worker node security, network policies, IAM/RBAC, logging, and pod security.

6 Sections ~130 Recommendations 2 Profile Levels

Azure Kubernetes Service (AKS)

v1.5.0January 2025

Security configuration guidelines for Azure Kubernetes Service covering cluster configuration, identity and access management, networking, workload security, data protection, and logging.

6 Sections ~120 Recommendations 2 Profile Levels

Red Hat OpenShift Container Platform

v1.6.0February 2025

Security configuration guidelines for Red Hat OpenShift Container Platform 4 covering control plane, worker nodes, RBAC, networking, pod security, and logging.

6 Sections ~140 Recommendations 2 Profile Levels

Google Kubernetes Engine (GKE)

v1.0.0January 2025

Security configuration guidelines for GKE clusters covering identity and Workload Identity, RBAC, network security, node hardening, cluster management, and data protection using gcloud and kubectl.

6 Sections ~140 Recommendations 2 Profile Levels

Podman

v1.0.0May 2026

Security configuration guidelines for Podman covering rootless operation, image provenance, registry configuration, seccomp profiles, network isolation, Quadlet units, and resource governance.

7 Sections ~100 Recommendations 2 Profile Levels

Rancher

v1.0.0Jan 2025

Security configuration guidelines for Rancher Kubernetes management covering authentication, RBAC, CIS hardening profiles, network isolation, workload security, data protection, and monitoring with Fleet GitOps.

7 Sections ~160 Recommendations 2 Profile Levels

HashiCorp Nomad

v1.0.0Jan 2025

Security configuration guidelines for HashiCorp Nomad covering ACL bootstrapping, mTLS encryption, gossip security, namespace isolation, Vault integration, Sentinel policies, Consul Connect mesh, and snapshot automation.

7 Sections ~160 Recommendations 2 Profile Levels

Istio

v1.0.0Jan 2025

Security configuration guidelines for Istio service mesh covering mutual TLS enforcement, authorization policies, peer authentication, gateway hardening, egress control, rate limiting, Envoy access logging, and control plane security.

7 Sections ~160 Recommendations 2 Profile Levels

ArgoCD

v1.0.0Jan 2025

Security configuration guidelines for ArgoCD covering SSO integration, RBAC policies, repository credential management, TLS enforcement, application sync policies, resource whitelisting, audit logging, and HA Redis clustering.

7 Sections ~160 Recommendations 2 Profile Levels

Harbor

v1.0.0Jan 2025

Security configuration guidelines for Harbor container registry covering OIDC authentication, RBAC project policies, TLS enforcement, vulnerability scanning, content trust with Cosign, garbage collection, replication, and audit logging.

7 Sections ~160 Recommendations 2 Profile Levels

Cilium

v1.0.0Mar 2025

Security configuration guidelines for Cilium eBPF networking covering RBAC, CiliumNetworkPolicy enforcement, WireGuard transparent encryption, Hubble observability, host firewall, L7 policy controls, and identity-aware access management.

7 Sections ~160 Recommendations 2 Profile Levels

Linkerd

v1.0.0Mar 2025

Security configuration guidelines for Linkerd service mesh covering trust anchor management, mutual TLS enforcement, authorization policies, dashboard RBAC, observability, traffic management, proxy hardening, and certificate rotation.

7 Sections ~160 Recommendations 2 Profile Levels

K3s

v1.0.0Mar 2025

Security configuration guidelines for K3s lightweight Kubernetes covering API server authentication, RBAC least privilege, secrets encryption at rest, TLS certificate management, audit logging, network policies, Pod Security Standards, and etcd snapshot backups.

7 Sections ~160 Recommendations 2 Profile Levels

Containerd

v1.0.0Mar 2025

Security configuration guidelines for Containerd container runtime covering systemd cgroup driver, seccomp profiles, registry TLS, gRPC socket permissions, namespace isolation, storage drivers, file permissions, and image source restrictions.

7 Sections ~160 Recommendations 2 Profile Levels

Databases

Hardening benchmarks for relational and NoSQL database management systems.

PostgreSQL 16

v1.0.0August 2024

Security configuration guidelines for PostgreSQL 16 including installation, file permissions, logging, user access, SSL/TLS, and replication.

6 Sections ~100 Recommendations 2 Profile Levels

MySQL 8.0

v1.1.0October 2024

Security configuration guidelines for MySQL 8.0 covering installation, file permissions, authentication, network, auditing, and replication.

6 Sections ~150 Recommendations 2 Profile Levels

MongoDB 8.0

v1.0.0November 2024

Security configuration guidelines for MongoDB 8.0 covering authentication, access control, auditing, encryption, network, and replica set security.

6 Sections ~80 Recommendations 2 Profile Levels

Microsoft SQL Server 2022

v1.1.0September 2024

Security configuration guidelines for MS SQL Server 2022 covering installation, authentication, auditing, encryption, and database engine settings.

6 Sections ~90 Recommendations 2 Profile Levels

Oracle Database 19c

v1.2.0January 2025

Security configuration guidelines for Oracle Database 19c covering installation, instance configuration, user accounts, privileges, auditing, and encryption.

6 Sections ~170 Recommendations 2 Profile Levels

Redis 7

v1.1.0November 2024

Security configuration guidelines for Redis 7 covering authentication, ACL management, TLS, dangerous command restrictions, persistence, and monitoring.

6 Sections ~80 Recommendations 2 Profile Levels

MariaDB 10.11

v1.0.0December 2024

Security configuration guidelines for MariaDB 10.11 covering installation, authentication, network security, auditing, privilege management, and replication encryption.

6 Sections ~110 Recommendations 2 Profile Levels

Apache CouchDB 3

v1.0.0October 2024

Security configuration guidelines for Apache CouchDB 3 covering installation hardening, authentication, network security, TLS encryption, logging, and replication/cluster security.

6 Sections ~70 Recommendations 2 Profile Levels

Elasticsearch 8

v1.1.0December 2024

Security configuration guidelines for Elasticsearch 8 covering installation, authentication, network security, TLS encryption, cluster management, and audit logging.

6 Sections ~80 Recommendations 2 Profile Levels

IBM Db2

v1.1.0October 2024

Security configuration guidelines for IBM Db2 covering installation, authentication, authorization, network security, auditing, and data protection.

6 Sections ~85 Recommendations 2 Profile Levels

Apache Cassandra 4.1

v1.0.0November 2024

Security configuration guidelines for Apache Cassandra 4.1 covering installation, authentication, authorization, encryption, audit logging, and operational security.

6 Sections ~75 Recommendations 2 Profile Levels

SAP HANA 2.0

v1.0.0May 2026

Security configuration guidelines for SAP HANA 2.0 covering SSL/TLS, password policies, authorization, auditing, data-at-rest encryption, key management, and operational security.

5 Sections ~150 Recommendations 2 Profile Levels

Snowflake

v1.0.0January 2025

Security configuration guidelines for Snowflake cloud data platform covering account configuration, IAM, data protection, monitoring, warehouse security, and data masking policies using SQL commands.

6 Sections ~130 Recommendations 2 Profile Levels

Neo4j 5

v1.0.0January 2025

Security configuration guidelines for Neo4j 5 graph database covering authentication, password policies, RBAC, SSL/TLS, Bolt encryption, procedure restrictions, logging, and JMX security.

6 Sections ~110 Recommendations 2 Profile Levels

InfluxDB 2

v1.0.0May 2026

Security configuration guidelines for InfluxDB 2 covering authentication, API token management, TLS transport, bucket retention, Flux query restrictions, backup encryption, and audit logging.

7 Sections ~100 Recommendations 2 Profile Levels

Couchbase 7

v1.0.0Jan 2025

Security configuration guidelines for Couchbase Server 7 covering LDAP authentication, RBAC, encryption in transit and at rest, XDCR security, audit logging, cluster management, and query service security.

7 Sections ~160 Recommendations 2 Profile Levels

TimescaleDB

v1.0.0Jan 2025

Security configuration guidelines for TimescaleDB covering SCRAM-SHA-256 authentication, TLS 1.3 encryption, hypertable access control, retention policies, compression, pgAudit logging, row-level security, and replication.

7 Sections ~160 Recommendations 2 Profile Levels

CockroachDB

v1.0.0Jan 2025

Security configuration guidelines for CockroachDB covering SCRAM-SHA-256 authentication, mutual TLS, AES-256 encryption at rest, multi-region replication, automated backups, SQL audit logging, admission control, and CA rotation.

7 Sections ~160 Recommendations 2 Profile Levels

etcd

v1.0.0Mar 2025

Security configuration guidelines for etcd covering client/peer mutual TLS, RBAC authentication, snapshot backups, auto-compaction, peer URL restrictions, cluster health monitoring, defragmentation, and version management.

7 Sections ~160 Recommendations 2 Profile Levels

Memcached

v1.0.0Mar 2025

Security configuration guidelines for Memcached covering network binding restrictions, SASL and TLS authentication, connection logging, resource limits, memory management, network security, and maintenance procedures.

7 Sections ~160 Recommendations 2 Profile Levels

Apache Solr

v1.0.0Mar 2025

Security configuration guidelines for Apache Solr covering authentication plugins, role-based authorization, TLS encryption, ZooKeeper security, audit logging, network binding, data directory permissions, Config API restriction, and feature hardening.

7 Sections ~160 Recommendations 2 Profile Levels

OpenSearch

v1.0.0Mar 2025

Security configuration guidelines for OpenSearch covering Security plugin activation, internal user authentication, RBAC, transport and REST layer TLS, audit logging, network binding, JVM heap limits, index state management, and snapshot backup encryption.

7 Sections ~160 Recommendations 2 Profile Levels

ClickHouse

v1.0.0Mar 2025

Security configuration guidelines for ClickHouse columnar database covering SHA256 authentication, RBAC, client and inter-server TLS, query and server logging, network binding, resource limits, encryption at rest, backup procedures, and TTL retention policies.

7 Sections ~160 Recommendations 2 Profile Levels

Server Software

Benchmarks for web servers, application servers, and reverse proxies.

Nginx

v2.1.0June 2024

Security configuration guidelines for Nginx web server and reverse proxy covering TLS, security headers, rate limiting, and information disclosure.

6 Sections ~60 Recommendations 2 Profile Levels

Apache HTTP Server 2.4

v2.2.0August 2024

Security configuration guidelines for Apache HTTP Server 2.4 covering modules, directory permissions, logging, SSL/TLS, and request limits.

6 Sections ~80 Recommendations 2 Profile Levels

Apache Tomcat 10

v1.1.0August 2024

Security configuration guidelines for Apache Tomcat 10 covering installation, connectors, TLS, logging, account management, and session security.

5 Sections ~75 Recommendations 2 Profile Levels

Microsoft IIS 10

v1.2.1March 2025

Security configuration guidelines for Microsoft IIS 10 covering authentication, request filtering, TLS/HSTS, application pools, and security headers.

7 Sections ~90 Recommendations 2 Profile Levels

HAProxy 2.8

v1.0.0January 2025

Security configuration guidelines for HAProxy 2.8 LTS covering TLS termination, access control, rate limiting, security headers, logging, and health checks.

6 Sections ~100 Recommendations 2 Profile Levels

Splunk Enterprise

v1.1.0November 2024

Security configuration guidelines for Splunk Enterprise covering deployment, authentication, data security, search configuration, TLS, and audit logging.

6 Sections ~90 Recommendations 2 Profile Levels

HashiCorp Vault

v1.0.0October 2024

Security configuration guidelines for HashiCorp Vault covering storage backend, authentication methods, secrets engines, audit logging, TLS/API hardening, and operational security.

6 Sections ~80 Recommendations 2 Profile Levels

Apache Kafka

v1.0.0October 2024

Security configuration guidelines for Apache Kafka covering installation hardening, authentication and authorization, network security, encryption, topic and cluster management, and monitoring.

6 Sections ~80 Recommendations 2 Profile Levels

BIND 9 DNS Server

v1.0.0May 2026

Security configuration guidelines for ISC BIND 9 covering zone transfer restrictions, DNSSEC, recursion controls, response rate limiting, TSIG authentication, and file permissions.

5 Sections ~120 Recommendations 2 Profile Levels

Microsoft Exchange Server 2019

v2.0.0January 2025

Security configuration guidelines for Microsoft Exchange Server 2019 covering transport, client access, mailbox security, RBAC permissions, logging, and server hardening.

6 Sections ~130 Recommendations 2 Profile Levels

GitLab

v1.0.0January 2025

Security configuration guidelines for self-managed GitLab instances covering authentication, token management, TLS, repository protection, CI/CD hardening, audit logging, backups, and container registry security.

7 Sections ~120 Recommendations 2 Profile Levels

RabbitMQ 3.13

v1.0.0January 2025

Security configuration guidelines for RabbitMQ 3.13 message broker covering authentication, vhost isolation, TLS transport, resource limits, cluster security, and logging using rabbitmqctl and rabbitmq.conf.

6 Sections ~100 Recommendations 2 Profile Levels

Ansible Automation Platform

v1.0.0May 2026

Security configuration guidelines for Ansible Automation Platform covering controller authentication, RBAC, credential encryption with ansible-vault, playbook linting, execution environment isolation, and audit logging.

7 Sections ~100 Recommendations 2 Profile Levels

Postfix

v1.0.0May 2026

Security configuration guidelines for Postfix MTA covering SASL authentication, TLS transport, relay restrictions, SPF/DKIM verification, chroot isolation, rate limiting, and postconf hardening.

7 Sections ~110 Recommendations 2 Profile Levels

Jenkins

v1.0.0Jan 2025

Security configuration guidelines for Jenkins CI/CD covering authentication, controller hardening, credential management, plugin governance, build agent security, audit logging, and web security.

7 Sections ~160 Recommendations 2 Profile Levels

Grafana

v1.0.0Jan 2025

Security configuration guidelines for Grafana covering authentication, access control, data source security, plugin governance, alerting configuration, audit logging, and web security with HTTPS and CSP.

7 Sections ~160 Recommendations 2 Profile Levels

Keycloak

v1.0.0Jan 2025

Security configuration guidelines for Keycloak IAM covering realm security, authentication flows, client configuration, token management, admin console security, event logging, and transport security.

7 Sections ~160 Recommendations 2 Profile Levels

HashiCorp Consul

v1.0.0Jan 2025

Security configuration guidelines for HashiCorp Consul covering ACL deny-default policies, TLS encryption, gossip key management, Connect service mesh, intention security, KV store access, audit logging, and snapshot recovery.

7 Sections ~160 Recommendations 2 Profile Levels

Traefik

v1.0.0Jan 2025

Security configuration guidelines for Traefik covering HTTPS entrypoints, TLS options, dashboard authentication, rate limiting, security headers, Let's Encrypt ACME, circuit breakers, Docker provider security, and systemd hardening.

7 Sections ~160 Recommendations 2 Profile Levels

SonarQube

v1.0.0Jan 2025

Security configuration guidelines for SonarQube covering authentication enforcement, LDAP/SAML integration, permission templates, quality gate policies, security hotspot review, plugin management, database SSL, and token security.

7 Sections ~160 Recommendations 2 Profile Levels

FreeIPA

v1.0.0Jan 2025

Security configuration guidelines for FreeIPA covering password and Kerberos policies, OTP two-factor authentication, HBAC rules, sudo delegation, certificate authority, replication topology, DNSSEC validation, and audit logging.

7 Sections ~160 Recommendations 2 Profile Levels

MinIO

v1.0.0Jan 2025

Security configuration guidelines for MinIO covering IAM policy-based access, TLS enforcement, server-side encryption with KMS, bucket policies, object locking, versioning, audit webhook logging, erasure coding, and site replication.

7 Sections ~160 Recommendations 2 Profile Levels

Prometheus

v1.0.0Jan 2025

Security configuration guidelines for Prometheus covering basic authentication, TLS encryption, scrape target authorization, recording rules, Alertmanager routing, remote write/read, TSDB retention, WAL configuration, and federation.

7 Sections ~160 Recommendations 2 Profile Levels

Grafana Loki

v1.0.0Jan 2025

Security configuration guidelines for Grafana Loki covering multi-tenancy, reverse proxy authentication, TLS encryption, encrypted storage backends, retention policies, rate limiting, Promtail pipelines, alerting rules, and clustering.

7 Sections ~160 Recommendations 2 Profile Levels

Teleport

v1.0.0Jan 2025

Security configuration guidelines for Teleport covering SSO with WebAuthn MFA, least-privilege RBAC, enhanced session recording, trusted cluster federation, database and application proxying, audit event storage, HA backends, and CA rotation.

7 Sections ~160 Recommendations 2 Profile Levels

Envoy Proxy

v1.0.0Mar 2025

Security configuration guidelines for Envoy Proxy covering TLS enforcement, admin interface lockdown, access logging, rate limiting, CORS policy, circuit breakers, health check endpoints, and hot restart configuration.

7 Sections ~160 Recommendations 2 Profile Levels

OpenLDAP

v1.0.0Mar 2025

Security configuration guidelines for OpenLDAP covering StartTLS/LDAPS enforcement, ACL-based access control, password policy overlay, audit logging, size/time limits, database tuning, and backup procedures.

7 Sections ~160 Recommendations 2 Profile Levels

Squid Proxy

v1.0.0Mar 2025

Security configuration guidelines for Squid caching proxy covering ACL-based access control, NCSA authentication, HTTPS interception, access logging, cache management, header stripping, URL filtering, and log rotation.

7 Sections ~160 Recommendations 2 Profile Levels

Nagios Core

v1.0.0Mar 2025

Security configuration guidelines for Nagios Core covering HTTPS web interface, authentication hardening, NRPE SSL, file permissions, notification configuration, CGI authorization, resource file protection, and config verification.

7 Sections ~160 Recommendations 2 Profile Levels

HashiCorp Boundary

v1.0.0Mar 2025

Security configuration guidelines for HashiCorp Boundary covering controller TLS, OIDC authentication, RBAC roles, worker authentication, KMS seals, audit event logging, session recording, credential brokering, and scope organization.

7 Sections ~160 Recommendations 2 Profile Levels

Apache Airflow

v1.0.0Mar 2025

Security configuration guidelines for Apache Airflow covering authentication backends, RBAC, HTTPS enforcement, Fernet encryption, remote logging, production database backend, executor configuration, API authentication, and secrets backend integration.

7 Sections ~160 Recommendations 2 Profile Levels

Zabbix

v1.0.0Mar 2025

Security configuration guidelines for Zabbix monitoring platform covering web frontend HTTPS, database and agent TLS encryption, audit logging, API security, alerting configuration, proxy hardening, and maintenance procedures.

7 Sections ~160 Recommendations 2 Profile Levels

Caddy

v1.0.0Mar 2025

Security configuration guidelines for Caddy web server covering automatic HTTPS, TLS configuration, HTTP security headers, access logging, reverse proxy authentication, admin API restriction, file server hardening, and certificate management.

7 Sections ~160 Recommendations 2 Profile Levels

Fluentd

v1.0.0Mar 2025

Security configuration guidelines for Fluentd log aggregation covering input/output TLS encryption, data filtering, internal logging, resource management, error handling, plugin security, secrets management, and buffer configuration.

7 Sections ~160 Recommendations 2 Profile Levels

Kong Gateway

v1.0.0Mar 2025

Security configuration guidelines for Kong API Gateway covering Admin API restriction, RBAC enforcement, proxy and upstream TLS, access logging, rate limiting, authentication plugins, IP restriction, CORS policies, and database TLS hardening.

7 Sections ~160 Recommendations 2 Profile Levels

Ceph

v1.0.0Mar 2025

Security configuration guidelines for Ceph distributed storage covering CephX authentication, keyring management, messenger v2 encryption, RGW TLS, network separation, dashboard security, OSD encryption at rest, and CRUSH rule configuration.

7 Sections ~160 Recommendations 2 Profile Levels

Dovecot

v1.0.0Mar 2025

Security configuration guidelines for Dovecot IMAP/POP3 mail server covering TLS enforcement, plaintext authentication disabling, protocol restriction, connection limits, mail event logging, quota management, Sieve filtering, and authentication backend hardening.

7 Sections ~160 Recommendations 2 Profile Levels

Logstash

v1.0.0Mar 2025

Security configuration guidelines for Logstash data processing pipeline covering API authentication, keystore secrets management, TLS on inputs and outputs, logging and slowlog configuration, binding restrictions, persistent queue settings, and JVM security hardening.

7 Sections ~160 Recommendations 2 Profile Levels

Kibana

v1.0.0Mar 2025

Security configuration guidelines for Kibana visualization platform covering authentication providers, session management, spaces-based RBAC, HTTPS/TLS, audit logging, CSP headers, saved objects encryption, keystore management, and feature disablement.

7 Sections ~160 Recommendations 2 Profile Levels

Graylog

v1.0.0Mar 2025

Security configuration guidelines for Graylog log management covering root password hardening, LDAP/AD authentication, HTTPS/TLS, Elasticsearch TLS, audit logging, network binding, input security, file permissions, JVM hardening, and plugin management.

7 Sections ~160 Recommendations 2 Profile Levels

Varnish Cache

v1.0.0Mar 2025

Security configuration guidelines for Varnish Cache HTTP accelerator covering VCL ACL configuration, management interface security, backend health checks, NCSA logging, security headers, request filtering, cache policy, and resource limits.

7 Sections ~160 Recommendations 2 Profile Levels

Network Devices

Hardening benchmarks for routers, switches, and network infrastructure devices.

Cisco IOS 17

v2.1.0January 2025

Security configuration guidelines for Cisco IOS 17 covering management plane, control plane, data plane, access lists, services, and IOS hardening.

6 Sections ~160 Recommendations 2 Profile Levels

Palo Alto Firewall PAN-OS 11

v1.2.0February 2025

Security configuration guidelines for Palo Alto PAN-OS 11 covering device management, network security, security policies, SSL decryption, logging, and HA.

6 Sections ~140 Recommendations 2 Profile Levels

Juniper JunOS

v2.1.0February 2025

Security configuration guidelines for Juniper JunOS covering management plane, authentication, system services, routing protocol hardening, logging, and network resilience.

6 Sections ~140 Recommendations 2 Profile Levels

F5 BIG-IP

v1.1.0November 2024

Security configuration guidelines for F5 BIG-IP covering system configuration, authentication, network security, SSL/TLS profiles, logging, and high availability hardening.

6 Sections ~110 Recommendations 2 Profile Levels

Fortinet FortiGate

v1.3.0December 2024

Security configuration guidelines for Fortinet FortiGate covering system administration, authentication, firewall policies, VPN configuration, logging, and intrusion prevention.

6 Sections ~130 Recommendations 2 Profile Levels

Cisco Meraki

v1.0.0January 2025

Security configuration guidelines for Cisco Meraki cloud-managed infrastructure covering dashboard administration, network configuration, wireless security, content filtering, VPN, and monitoring.

6 Sections ~90 Recommendations 2 Profile Levels

Check Point Firewall

v1.1.0November 2024

Security configuration guidelines for Check Point Security Gateways covering system configuration, authentication, security policy, VPN, logging and monitoring, and high availability.

6 Sections ~100 Recommendations 2 Profile Levels

Arista EOS

v1.0.0November 2024

Security configuration guidelines for Arista EOS network devices covering management plane, authentication, control plane, data plane, logging, and system hardening.

6 Sections ~95 Recommendations 2 Profile Levels

Sophos Firewall

v1.0.0December 2024

Security configuration guidelines for Sophos Firewall (SFOS) covering system configuration, authentication, firewall rules, VPN, web protection, and logging and monitoring.

6 Sections ~90 Recommendations 2 Profile Levels

Cisco NX-OS

v1.0.0January 2025

Security configuration guidelines for Cisco Nexus switches running NX-OS covering management plane, SSH/transport, CoPP, routing authentication, logging, NTP, SNMP, port security, and ACLs.

8 Sections ~120 Recommendations 2 Profile Levels

pfSense

v1.0.0January 2025

Security configuration guidelines for pfSense firewall/router covering system updates, authentication, WebGUI hardening, firewall rules, VPN security, DNS over TLS, and OS-level hardening using pfctl and sysctl.

7 Sections ~110 Recommendations 2 Profile Levels

Ubiquiti UniFi

v1.0.0May 2026

Security configuration guidelines for Ubiquiti UniFi covering controller security, VLAN segmentation, WPA3 wireless, IPS/IDS, firewall rules, DPI configuration, and device firmware management via UniFi API.

7 Sections ~100 Recommendations 2 Profile Levels

MikroTik RouterOS

v1.0.0Jan 2025

Security configuration guidelines for MikroTik RouterOS covering user management, firewall hardening, network services, service hardening, logging, cryptography, and system maintenance.

7 Sections ~160 Recommendations 2 Profile Levels

Cumulus Linux

v1.0.0Jan 2025

Security configuration guidelines for Cumulus Linux covering NVUE ACLs, control plane policing, management VRF, SNMPv3, syslog forwarding, NTP authentication, STP hardening, storm control, BGP/OSPF MD5 authentication, and route filtering.

7 Sections ~160 Recommendations 2 Profile Levels

WireGuard

v1.0.0Jan 2025

Security configuration guidelines for WireGuard VPN covering key management, AllowedIPs restrictions, firewall integration, DNS leak prevention, preshared keys, logging, peer rotation, and kill switch configuration.

7 Sections ~160 Recommendations 2 Profile Levels

OPNsense

v1.0.0Jan 2025

Security configuration guidelines for OPNsense firewall covering admin authentication, TLS enforcement, firewall rule hardening, Suricata IDS/IPS, VPN gateway security, DNS filtering, CARP high availability, and syslog audit forwarding.

7 Sections ~160 Recommendations 2 Profile Levels

Suricata

v1.0.0Mar 2025

Security configuration guidelines for Suricata IDS/IPS covering IPS mode configuration, rule management, EVE JSON logging, protocol analysis, network variable tuning, stream engine optimization, and rule update automation.

7 Sections ~160 Recommendations 2 Profile Levels

Cisco ASA

v1.0.0Mar 2025

Security configuration guidelines for Cisco ASA covering password encryption, AAA authentication, management access restriction, TLS hardening, syslog logging, NTP authentication, threat detection, IKEv2 VPN, and protocol hardening.

7 Sections ~160 Recommendations 2 Profile Levels

Pi-hole

v1.0.0Mar 2025

Security configuration guidelines for Pi-hole DNS filtering covering admin interface HTTPS, upstream DNS-over-HTTPS, DNSSEC validation, query logging privacy, interface restriction, rate limiting, blocklist management, regex filtering, and backup procedures.

7 Sections ~160 Recommendations 2 Profile Levels

Calico

v1.0.0Mar 2025

Security configuration guidelines for Calico network policy engine covering default-deny global policies, WireGuard encryption, Typha TLS, flow logging, IP pool configuration, BGP peering security, Felix settings, host endpoint protection, and policy tier management.

7 Sections ~160 Recommendations 2 Profile Levels

Tailscale

v1.0.0Mar 2025

Security configuration guidelines for Tailscale mesh VPN covering ACL policy configuration, device authorization, MagicDNS, key expiry management, network flow logging, subnet route restrictions, exit node security, Tailscale SSH hardening, and Funnel/Serve controls.

7 Sections ~160 Recommendations 2 Profile Levels

Virtualization

Hardening benchmarks for hypervisors and virtual infrastructure platforms.

VMware ESXi 8

v1.1.0November 2024

Security configuration guidelines for VMware ESXi 8 covering installation, communication, logging, access control, VM hardening, and storage security.

6 Sections ~130 Recommendations 2 Profile Levels

Citrix Hypervisor

v1.0.0August 2024

Security configuration guidelines for Citrix Hypervisor (XenServer) covering installation hardening, authentication, network configuration, storage security, VM management, and logging.

6 Sections ~90 Recommendations 2 Profile Levels

Microsoft Hyper-V

v1.0.0September 2024

Security configuration guidelines for Microsoft Hyper-V covering host configuration, virtual machine settings, networking, storage, access control, and monitoring.

6 Sections ~85 Recommendations 2 Profile Levels

VMware vCenter 8

v1.0.0May 2026

Security configuration guidelines for VMware vCenter Server 8 covering SSO policies, role-based access, network security, VM isolation, syslog, TLS, and service hardening.

5 Sections ~170 Recommendations 2 Profile Levels

Proxmox VE 8

v1.0.0January 2025

Security configuration guidelines for Proxmox VE 8 covering authentication, RBAC, network security, storage encryption, VM/container hardening, cluster security, and host hardening using pvesh, pveum, qm, and pct.

7 Sections ~100 Recommendations 2 Profile Levels

Nutanix AHV

v1.0.0May 2026

Security configuration guidelines for Nutanix AHV covering Prism authentication, RBAC, Flow microsegmentation, VM hardening, cluster encryption, SCMA compliance, and CVM security using ncli and acli.

7 Sections ~100 Recommendations 2 Profile Levels

KVM / libvirt

v1.0.0Jan 2025

Security configuration guidelines for KVM/libvirt covering host access control, mandatory access controls, network security, storage encryption, migration TLS, resource management, and audit logging.

7 Sections ~160 Recommendations 2 Profile Levels

XCP-ng

v1.0.0Jan 2025

Security configuration guidelines for XCP-ng covering RBAC and SSH hardening, VLAN network isolation, host firewall, iSCSI CHAP storage authentication, VM resource limits, backup automation, centralized logging, and TLS certificate deployment.

7 Sections ~160 Recommendations 2 Profile Levels

Desktop Software

Security benchmarks for desktop applications and end-user software.

Google Chrome

v3.0.0January 2025

Security configuration guidelines for Google Chrome enterprise covering extensions, privacy, network security, content settings, authentication, and update policies.

6 Sections ~120 Recommendations 2 Profile Levels

Microsoft Edge

v3.0.0January 2025

Security configuration guidelines for Microsoft Edge enterprise covering extensions, privacy, SmartScreen, content filtering, authentication, and update policies.

6 Sections ~120 Recommendations 2 Profile Levels

Mozilla Firefox

v2.0.0October 2024

Security configuration guidelines for Mozilla Firefox enterprise covering extensions, tracking protection, network security, certificates, and enterprise policies.

6 Sections ~100 Recommendations 2 Profile Levels

Apple Safari 18

v1.0.0May 2026

Security configuration guidelines for Apple Safari 18 covering privacy, autofill, extensions, HTTPS enforcement, developer tools, and data protection via macOS defaults.

6 Sections ~100 Recommendations 2 Profile Levels

Zoom Workplace

v1.0.0January 2025

Security configuration guidelines for Zoom Workplace covering account security, encryption, data protection, meeting controls, chat restrictions, authentication, and client management via admin portal and GPO/MDM policies.

6 Sections ~100 Recommendations 2 Profile Levels

Slack Enterprise

v1.0.0May 2026

Security configuration guidelines for Slack Enterprise covering SSO authentication, session management, DLP policies, external sharing controls, app governance, audit log forwarding, and eDiscovery compliance.

7 Sections ~100 Recommendations 2 Profile Levels

Microsoft Teams

v1.0.0Jan 2025

Security configuration guidelines for Microsoft Teams covering external access, meeting policies, messaging controls, app governance, data loss prevention, identity management, and audit compliance.

7 Sections ~160 Recommendations 2 Profile Levels

Brave Browser

v1.0.0Jan 2025

Security and privacy configuration guidelines for Brave Browser covering Shields defaults, cookie policies, WebRTC leak prevention, fingerprint blocking, extension governance, HTTPS-Only mode, DNS-over-HTTPS, telemetry controls, and Tor window usage.

7 Sections ~160 Recommendations 2 Profile Levels

Mobile Devices

Security benchmarks for mobile operating systems and enterprise device management.

Apple iOS 18

v1.0.0March 2025

Security configuration guidelines for Apple iOS 18 covering passcode policies, network settings, app management, privacy, iCloud, and enterprise MDM configuration.

6 Sections ~120 Recommendations 2 Profile Levels

Android 14 Enterprise

v1.0.0February 2025

Security configuration guidelines for Android 14 enterprise covering device lock, network configuration, app management, data protection, EMM policies, and developer settings.

6 Sections ~110 Recommendations 2 Profile Levels

Microsoft Intune

v2.0.0March 2025

Security configuration guidelines for Microsoft Intune covering device enrollment, compliance policies, configuration profiles, app protection, conditional access, and monitoring.

6 Sections ~95 Recommendations 2 Profile Levels

Samsung Knox

v1.0.0May 2026

Security configuration guidelines for Samsung Knox covering Knox Manage enrollment, KPE policy enforcement, containerization, E-FOTA firmware control, network protection, and enterprise device attestation.

7 Sections ~100 Recommendations 2 Profile Levels