CIS Benchmarks
The Center for Internet Security (CIS) Benchmarks are globally recognized security configuration standards. Cloudgeni automates CIS compliance assessment across your cloud infrastructure.
CIS Coverage
CIS 3.0 for Oracle Cloud - Full benchmark coverage
400+ automated checks across cloud services
Scored and unscored recommendations
Level 1 and Level 2 profiles supported
Understanding CIS Benchmarks
Benchmark Structure
CIS Benchmarks organize recommendations into:
Component Description Sections Major security domains (IAM, Logging, etc.) Recommendations Specific security configurations Profiles Level 1 (essential) or Level 2 (defense in depth) Scoring Scored (measurable) or Unscored (procedural)
Profile Levels
Level Description Use Case Level 1 Essential security, minimal performance impact All environments Level 2 Defense in depth, may impact usability High-security environments
CIS for Oracle Cloud Infrastructure (OCI)
Section 1: Identity and Access Management
Recommendation Level Scored Description 1.1 L1 Yes Ensure MFA is enabled for all users 1.2 L1 Yes Ensure API keys rotate within 90 days 1.3 L1 Yes Ensure all users have valid email 1.4 L1 Yes Ensure IAM password policy requires minimum length 1.5 L1 Yes Ensure IAM password policy requires uppercase 1.6 L1 Yes Ensure IAM password policy requires lowercase 1.7 L1 Yes Ensure IAM password policy requires symbols 1.8 L1 Yes Ensure IAM password policy requires numbers 1.9 L1 Yes Ensure IAM policies restrict tenancy admin 1.10 L2 Yes Ensure IAM administrators use dedicated admin accounts 1.11 L1 Yes Ensure service account keys rotate within 90 days 1.12 L1 Yes Ensure user groups don’t have direct IAM policy 1.13 L1 Yes Ensure policies don’t allow all resources in tenancy 1.14 L2 Yes Ensure MFA is enabled for Federation users
Section 2: Logging and Monitoring
Recommendation Level Scored Description 2.1 L1 Yes Ensure audit log retention is 365 days 2.2 L1 Yes Ensure default VCN logging is enabled 2.3 L1 Yes Ensure Object Storage bucket has logging enabled 2.4 L2 Yes Ensure Flow Logs capture rejected traffic 2.5 L1 Yes Ensure security notifications are enabled 2.6 L1 Yes Ensure Cloud Guard is enabled 2.7 L1 Yes Ensure Cloud Guard responders are enabled
Section 3: Networking
Recommendation Level Scored Description 3.1 L1 Yes Ensure security lists restrict SSH to specific IPs 3.2 L1 Yes Ensure security lists restrict RDP to specific IPs 3.3 L1 Yes Ensure no security list allows ingress 0.0.0.0/0 3.4 L2 Yes Ensure Network Security Groups are used 3.5 L1 Yes Ensure VCN has inbound security rules 3.6 L1 Yes Ensure no NSG allows ingress 0.0.0.0/0 3.7 L2 Yes Ensure FastConnect/VPN is used for on-prem
Section 4: Object Storage
Recommendation Level Scored Description 4.1 L1 Yes Ensure Object Storage buckets are not public 4.2 L1 Yes Ensure Object Storage uses customer-managed keys 4.3 L2 Yes Ensure Object Storage has versioning enabled 4.4 L1 Yes Ensure pre-authenticated requests are time-limited
Section 5: Block Volumes
Recommendation Level Scored Description 5.1 L1 Yes Ensure Block Volumes use customer-managed keys 5.2 L2 Yes Ensure Block Volume backups are encrypted 5.3 L1 Yes Ensure boot volumes use customer-managed keys
Section 6: Database
Recommendation Level Scored Description 6.1 L1 Yes Ensure Autonomous DB uses customer-managed keys 6.2 L1 Yes Ensure DB systems use customer-managed keys 6.3 L2 Yes Ensure DB backups use customer-managed keys 6.4 L1 Yes Ensure Database Management is enabled
Section 7: Compute
Recommendation Level Scored Description 7.1 L1 Yes Ensure compute instances don’t have public IPs 7.2 L1 Yes Ensure OS Management is enabled 7.3 L2 Yes Ensure Vulnerability Scanning is enabled 7.4 L1 Yes Ensure instance metadata v2 is used
Using CIS Benchmarks in Cloudgeni
Running Assessment
Go to Compliance in Cloudgeni
Select CIS 3.0 (for OCI accounts)
Click Run Assessment
Review findings by section
Filtering Results
Filter by:
Level - Show only Level 1 or Level 2
Scored - Show scored recommendations only
Status - Pass, Fail, or Manual review
Section - IAM, Networking, Storage, etc.
Compliance Score
CIS score calculation:
Score = (Passing Scored Recommendations / Total Scored) × 100
Score Status Interpretation 90-100% Excellent Meeting CIS best practices 75-89% Good Minor gaps to address 50-74% Fair Significant improvements needed Below 50% Poor Major security gaps
Implementation Guide
Level 1 Implementation
Start with Level 1 recommendations:
Identity & Access
Enable MFA for all users
Implement password policies
Restrict admin access
Logging
Enable audit logging
Configure 365-day retention
Set up security notifications
Networking
Review security list rules
Remove 0.0.0.0/0 ingress
Restrict SSH/RDP access
Storage
Make buckets private
Enable encryption
Use customer-managed keys
Level 2 Implementation
After achieving Level 1 compliance:
Advanced IAM
Dedicated admin accounts
Federation MFA
Regular access reviews
Enhanced Monitoring
Flow log analysis
Cloud Guard responders
Vulnerability scanning
Defense in Depth
Network Security Groups
VPN/FastConnect
Advanced encryption
Automated Fixes
Many CIS recommendations can be auto-remediated:
Recommendation Auto-Remediate Fix 1.1 MFA Manual Requires user action 2.1 Audit retention Yes Update audit policy 3.1 SSH restriction Yes Update security list 4.1 Bucket public Yes Update bucket policy 5.1 Volume encryption Yes Enable encryption
Some recommendations require manual action:
Category Examples User configuration MFA enrollment, password changes Architecture changes VPN setup, network redesign Process changes Access reviews, training
Reporting
CIS Report Generation
Go to Compliance → CIS 3.0
Click Generate Report
Select options:
Level (1, 2, or both)
Scored only or all
Date range
Download PDF
Report Contents
Section Contents Executive Summary Overall score, trends Section Breakdown Score by CIS section Recommendations Pass/fail for each Evidence Configuration details Remediation Plan Prioritized fixes
CIS for Other Clouds
While Cloudgeni currently provides full CIS 3.0 support for OCI, compliance for AWS, Azure, and GCP is covered through:
Framework AWS Azure GCP CIS-aligned checks Via SOC 2, ISO 27001 Via SOC 2, ISO 27001 Via SOC 2, ISO 27001 Direct CIS Coming soon Coming soon Coming soon
CIS Benchmarks for AWS, Azure, and GCP are on our roadmap. Many CIS controls are already covered through SOC 2 and ISO 27001 frameworks.