Hardening checklists based on CIS Benchmarks (Center for Internet Security) and NIST SP 800-123. Check items as you complete them — progress saves locally in your browser. Always test in a non-production environment first.
0% COMPLETE (0/0)
0% COMPLETE (0/0)
0% COMPLETE (0/0)
FRAMEWORKS & STANDARDS
// KEY REFERENCES FOR SYSTEM HARDENING
CIS BENCHMARKS
Gold standard for system hardening. 100+ benchmarks for OS, cloud, and apps. Free PDF for non-commercial use. Level 1 = basic hygiene. Level 2 = high security (may impact usability).
→ DOWNLOAD
NIST SP 800-123
Guide to General Server Security. OS hardening, application security, patch management, security testing. Federal baseline referenced by FedRAMP and FISMA.
→ PDF
NIST SP 800-53 Rev 5
Comprehensive catalog of security and privacy controls for federal information systems. Maps to ISO 27001, CIS Controls, COBIT. Current standard for government systems.
→ NIST
CIS CRITICAL SECURITY CONTROLS v8
18 prioritized controls mapped to real attack patterns. IG1/IG2/IG3 implementation groups scale to organization size. Free download. The practical companion to CIS Benchmarks.
→ CONTROLS
DISA STIGs
DoD-level configuration requirements — more stringent than CIS Level 2. Free via DISA STIG Viewer. Covers Windows, Linux, network gear, databases, applications.
→ STIGs
MITRE ATT&CK
Maps real-world attacker behavior (tactics, techniques, procedures) to defensive controls. Use to understand what attackers do at each phase and where your gaps are.
→ ATT&CK
LYNIS — LINUX AUDIT
Open-source security auditing tool for Unix/Linux. Scores your system against CIS controls, shows exactly what to fix. Run after hardening to verify changes.
→ LYNIS → ANSIBLE
OPENSCAP — AUTOMATED SCANNING
Automated compliance scanning against CIS/STIG benchmarks. Free, open source. Generates detailed reports showing pass/fail for each control. Available for RHEL, Ubuntu, and more.
→ OPENSCAP