33 questions,answered directly.
Plain-English answers to common questions about CIS benchmarks, compliance frameworks, sovereign deployment and audit evidence. Every answer opens with the direct answer, then the context.
- Fundamentals
- 6 answers
- Tools
- 1 answer
- CISGuard
- 5 answers
- Framework Mapping
- 3 answers
- Frameworks
- 10 answers
- Regions
- 1 answer
- Deployment
- 2 answers
- Comparisons
- 3 answers
- Implementation
- 1 answer
- Integration
- 1 answer
Fundamentals: 6 answers.
What is a CIS benchmark?
A CIS benchmark is a configuration baseline published by the Center for Internet Security defining secure-by-default settings for a specific technology: Windows, Linux, AWS, Kubernetes, databases, browsers. Each benchmark contains hundreds of individually-rated controls grouped by Level 1 (essential security) and Level 2 (defense-in-depth). They are the most widely-referenced configuration security baselines globally.
Read the answerWhat is the difference between CIS Level 1 and Level 2?
CIS Level 1 (L1) controls are essential security settings that can be applied without significant operational impact, the baseline every organization should meet. CIS Level 2 (L2) controls provide defense-in-depth for sensitive environments but may affect functionality or performance. Most organizations target L1 across all systems and L2 selectively on systems handling sensitive data.
Read the answerWhat is configuration drift?
Configuration drift is the accumulation of unauthorized or undocumented configuration changes between formal baselines: small modifications that erode compliance posture between audit cycles. Common causes: troubleshooting changes that don't get reverted, firefighting under operational pressure, and legitimate administrative actions that bypass change-management. Continuous monitoring with drift detection catches these in minutes, not at the next quarterly audit.
Read the answerWhat is a compliance exception?
A compliance exception is a documented deviation from a required control, with a formally approved compensating control documenting equivalent risk reduction. Exceptions exist because no control set perfectly fits every environment: legacy systems, vendor constraints, and operational realities sometimes require deviation. Auditors expect exception registers with approval chains, supporting evidence, and auto-expiry to prevent stale waivers.
Read the answerWho uses CIS benchmarks?
CIS benchmarks are used globally by enterprises, governments, financial services, healthcare, and critical infrastructure operators as the de facto configuration security baseline. Major audit firms reference them. US federal agencies cite them through NIST. The Center for Internet Security reports thousands of member organizations across the public and private sectors. Adoption is broadest in regulated industries where audit evidence quality matters.
Read the answerHow many CIS benchmarks exist?
The Center for Internet Security publishes over 100 CIS benchmarks covering operating systems (Windows, Linux distros, macOS), cloud platforms (AWS, Azure, GCP, OCI), container orchestration (Kubernetes, Docker), databases (Oracle, SQL Server, PostgreSQL, MySQL, MongoDB), web servers, browsers, mobile devices, and applications. New benchmarks are added regularly; existing benchmarks update with major-version releases of underlying technology.
Read the answer
CISGuard: 5 answers.
What is CISGuard?
CISGuard is a CIS benchmark compliance platform built for sovereign, on-premises, and air-gapped deployment. It continuously assesses your infrastructure against 22 CIS benchmarks (3,933 controls), applies 2,032 signed, reversible fixes, and maps every result to NIST 800-53, ISO 27001 and SOC 2 from a single scan.
Read the answerWhat makes CISGuard different from other compliance tools?
CISGuard is purpose-built for CIS benchmark compliance, not a vulnerability scanner with compliance bolted on. Three structural differences: sovereign-deployable architecture (on-premises and air-gapped as first-class configurations), auditor-ready Framework Coverage Reports for NIST 800-53, ISO 27001 and SOC 2 from one scan, and managed onboarding by our own compliance engineers.
Read the answerHow much does CISGuard cost?
CISGuard pricing is "talk to sales" because environments vary materially across endpoint count, framework scope, deployment model (cloud / on-premises / air-gapped), regional support requirements, and case-specific contractual constraints. Our compliance engineers scope your environment and quote within one business day. The model is designed to be predictable and not penalize cloud-native or ephemeral infrastructure.
Read the answerHow long does CISGuard deployment take?
Onboarding is managed: our compliance engineers deploy the server, configure benchmarks and schedules, integrate identity, and train your team, so deployment is seamless from the first day. Air-gapped deployments add a media-transfer step; the long path is usually customer-side change approval rather than installation. Your first scan runs as soon as agents register, and framework evidence builds from the first scheduled cycle.
Read the answerIs CISGuard affiliated with the Center for Internet Security?
No. CISGuard is an independent product. CISGuard interoperates with CIS benchmark standards (which are published by the Center for Internet Security), but is not affiliated with, endorsed by, or certified by CIS. CIS Benchmarks and CIS Controls are trademarks of the Center for Internet Security, Inc.
Read the answer
Framework Mapping: 3 answers.
How do CIS benchmarks map to NIST 800-53?
CISGuard maps CIS benchmark results to 50 NIST 800-53 Rev. 5 controls. Primary coverage spans Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), System and Communications Protection (SC), and System and Information Integrity (SI). CISGuard tags each CIS control with its corresponding NIST 800-53 control IDs for one-scan multi-framework reporting.
Read the answerHow do CIS benchmarks map to ISO 27001?
CISGuard maps CIS benchmark results to 36 of the 93 ISO/IEC 27001:2022 Annex A controls. Coverage concentrates on the technological controls that a configuration scan can evidence; people controls (A.6) are process-oriented and not automatable through scanning. CISGuard generates an ISO 27001 Framework Coverage Report you can attach to your Statement of Applicability as configuration evidence.
Read the answerHow do CIS benchmarks map to SOC 2 Type II?
CIS benchmarks map to 25 SOC 2 Trust Services Criteria across the Security (Common Criteria), Availability, Confidentiality, and Privacy categories. Primary coverage spans CC6 (Logical and Physical Access), CC7 (System Operations) and CC8 (Change Management). CISGuard's continuous monitoring produces the period-spanning evidence a SOC 2 Type II operating-effectiveness review asks for.
Read the answer
Frameworks: 10 answers.
Why does SOC 2 Type II require continuous evidence?
SOC 2 Type II evaluates whether controls operated effectively over a sustained period (typically 6 to 12 months), not just at a point in time. Auditors need evidence of consistent operation across the full period, not snapshots. Quarterly or monthly point-in-time scans leave evidence gaps. Continuous scanning produces the complete operational record auditors require without manual collection.
Read the answerWhat is the difference between SOC 2 Type I and Type II?
SOC 2 Type I evaluates whether controls are designed correctly at a single point in time. SOC 2 Type II evaluates whether those controls operated effectively over a sustained period (typically 6-12 months). Type II is significantly more demanding because it requires evidence of consistent operation, not just appropriate design. Enterprise customers typically require Type II.
Read the answerWhat is NIST 800-53 CA-7 Continuous Monitoring?
NIST 800-53 CA-7 (Continuous Monitoring) requires organizations to maintain ongoing situational awareness of information security and privacy posture across the system boundary. For configuration-based controls, this means continuous benchmark scanning rather than annual or quarterly point-in-time assessments. Tools that only produce annual or quarterly assessments cannot evidence it.
Read the answerWhat is FedRAMP ConMon?
FedRAMP ConMon (Continuous Monitoring) is the post-authorization monitoring program required of all FedRAMP-authorized cloud services. It implements NIST 800-53 CA-7 for federal cloud workloads. ConMon requires monthly vulnerability and configuration scan submissions, with annual control-set reassessment. Continuous CIS benchmark scanning is a core ConMon deliverable for configuration-based controls.
Read the answerCan CISGuard support FedRAMP authorization?
CISGuard supports the configuration-evidence part of a FedRAMP effort. It maps CIS benchmark results to 50 NIST 800-53 Rev. 5 controls and produces the continuous monitoring record that CA-7 asks for. It does not map the full Moderate or High baselines and does not grant authorization; the remaining controls in your package are evidenced elsewhere. Air-gapped deployment is available for environments where outbound connectivity is prohibited.
Read the answerWhat is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is the automotive sector's information-security passport, managed by the ENX Association. Tier-1 and Tier-2 suppliers undergo TISAX assessments at Assessment Levels (AL1, AL2, AL3) corresponding to data-sensitivity tiers. The technical-controls layer derives from ISO 27001 Annex A. OEMs require TISAX assessment evidence from every supplier.
Read the answerWhat is NIS2?
NIS2 is the EU Network and Information Security Directive 2, which member states had to transpose by 17 October 2024 and apply from 18 October 2024. It expands cybersecurity obligations to approximately 160,000 entities across essential and important sectors: energy, transport, banking, healthcare, water, digital infrastructure. NIS2 requires risk-management measures (Article 21), incident notification within 24 hours (Article 23), and management-body accountability.
Read the answerWhat is DORA?
DORA (Digital Operational Resilience Act) is the EU regulation for financial-sector ICT risk management, fully applicable since January 17, 2025. It mandates ICT risk management (Articles 5-16), incident reporting, operational resilience testing, and third-party ICT risk management for EU financial entities. CIS benchmarks satisfy the technical-controls layer underpinning DORA Articles 9-11.
Read the answerWhat is NCA ECC?
NCA ECC (Essential Cybersecurity Controls) is the Saudi Arabian National Cybersecurity Authority's framework for government, critical national infrastructure, and many private-sector organizations. The current edition, ECC-2:2024, replaced ECC-1:2018 in October 2024 and organizes 108 main controls across four domains and 28 subdomains. Compliance is mandatory for in-scope entities. CIS benchmarks satisfy the technical configuration controls within ECC; process-only controls require organizational evidence.
Read the answerWhat is ADHICS?
ADHICS (Abu Dhabi Healthcare Information and Cyber Security) is the Department of Health Abu Dhabi's mandatory cybersecurity standard for healthcare entities operating in Abu Dhabi. It elevates Abu Dhabi healthcare to one of the most regulated medical environments globally. The technical-controls layer aligns with ISO 27001, so hardened and continuously evidenced systems address much of its scope.
Read the answer
Deployment: 2 answers.
Does CISGuard deploy on air-gapped networks?
Yes. Air-gapped deployment is a first-class supported configuration, not a workaround. Benchmark definition updates are RSA-signed by the server and verified by every agent before use; software updates ship as offline media with published SHA-256 checksums. Agent-based scanning needs no outbound connectivity; only cloud-account scanning (Azure, AWS, Microsoft 365) reaches the provider APIs. Built for classified and isolated environments where outbound connectivity is prohibited.
Read the answerCan CISGuard scan Kubernetes?
Yes. CISGuard implements the CIS Kubernetes Benchmark with coverage at the cluster (kube-apiserver, etcd, kubelet, scheduler), namespace (RBAC, network policies), and pod (security context, capabilities) levels. CISGuard ships the CIS Kubernetes, Azure AKS, Amazon EKS and Red Hat OpenShift benchmarks, plus Docker for the container runtime. Cloud-native workloads scan with the same tooling as traditional infrastructure.
Read the answer
Comparisons: 3 answers.
How does CISGuard compare to Tenable?
CISGuard is purpose-built for CIS benchmark compliance and audit evidence; Tenable is a vulnerability management platform with CIS coverage as one feature. For audit-led compliance teams in sovereign jurisdictions (UAE, KSA, EU), CISGuard's on-premises architecture and auditor-ready Framework Coverage Reports often justify the choice. For CVE-based vulnerability operations, Tenable retains technical depth most customers continue to use.
Read the answerHow does CISGuard compare to Qualys?
CISGuard is built on-premises first, with air-gapped operation as a first-class configuration; Qualys is a cloud platform first, and while an on-premises appliance exists, the product is designed around the SaaS model. That difference matters in UAE, KSA and EU sovereign-residency jurisdictions. CISGuard's Framework Coverage Reports are formatted for auditor consumption rather than translated from a blended vulnerability + compliance product.
Read the answerHow does CISGuard compare to CIS-CAT Pro?
CIS-CAT Pro is the official CIS benchmark scanner. CISGuard extends that scanning with the operations layer CIS-CAT Pro doesn't provide: scheduled continuous assessment, mapping to NIST 800-53, ISO 27001 and SOC 2, drift alerting, signed reversible remediation, and an exception register with expiry. For production audit-evidence use, CISGuard replaces CIS-CAT Pro.
Read the answer
Still have a question we have not answered?
Request an executive briefing scoped to your environment and get answers specific to your compliance program.