CIS benchmarks
CIS Benchmarks are consensus configuration baselines, published by the Center for Internet Security, for hardening operating systems, cloud services, containers and applications. Each benchmark is a numbered list of settings with a rationale, an audit procedure and a remediation step, grouped into profiles by how much operational disruption they cause.
The profile split is the part people skip. A Level 1 profile is intended to be applied broadly with limited effect on function; a Level 2 profile assumes a higher security requirement and expects things to break. Applying a Level 2 recommendation to a general purpose estate because it scored badly is the standard way to cause an outage in the name of hardening.
For a Spanish organisation there is a second reference that is often not optional. The CCN-STIC guides published by Spain’s Centro Criptológico Nacional are the baselines an ENS audit works from, and where the two disagree the national guide is the one that has to be met. Passing a benchmark scan is not evidence of compliance with the national scheme, and presenting it as such is a finding in itself.
What a benchmark score is genuinely useful for is triage before an engagement: it tells you which settings were considered, not which are enforced. We treat a high score as a hypothesis and verify the settings that carry attack value directly on the host, because scanners routinely read a policy that is defined and not applied. That verification is part of the Microsoft 365 hardening work where these baselines are the starting point.