Maintained with ☕️ by
IcePanel logo
Microsoft Azure logo
Original post

Public Preview: Built-in CIS benchmarks for Azure endorsed Linux distros in Machine Config

Share

Services

Microsoft Azure now offers built-in Center for Internet Security (CIS) benchmarks in public preview for all [Azure endorsed Linux distributions](https://learn.microsoft.com/en-us/azure/virtual-machines/linux/endorsed-distros) through Azure Machine Configuration’s new customizable security benchmarks capability, powered by [azure-osconfig’s](https://github.com/Azure/azure-osconfig/tree/dev/src/modules/complianceengine/src) compliance engine. This capability allows organizations to easily customize and apply industry-standard security benchmarks which are in parity with the content published on [CIS website.](https://www.cisecurity.org/) It supports both Level 1(L1) and Level 2(L2) server profiles, enables exception and parameter customization, operates in audit-only mode at no additional cost, and extends compliance management to hybrid scenarios via Azure Arc. Using this new capability, you can introduce a flexible, compliance as code driven approach to your organization to maintain security and compliance across your hybrid infrastructure. The solution is officially certified by CIS for CIS benchmark assessment for all the supported benchmarks. Learn more: * Read our [blog](https://aka.ms/cisonazureblog) and refer to the [documentation](https://aka.ms/cisonazure). * For any questions or feedback fill out this short [form](https://aka.ms/cisonazurefeedback).