Hi folks,<\/p>\n
I have been assigned an task for hardening of windows server based on CIS benchmark.<\/p>\n
fyi - existing production environment running on AWS.<\/p>\n
As per my understanding CIS benchmark have levels i.e 1 and 2. Depending on your environment and how much your can restrict your environment.<\/p>\n
Steps should be :<\/p>\n
Run CIS benchmark auditing tool or script against one or 2 production server.<\/p>\n<\/li>\n
Identify gaps and what is missing.<\/p>\n<\/li>\n
Apply gpo that follows CIS benchmark. to Test server or clone of existing production server. See the impact on production envrionment operations and share with business.?<\/p>\n<\/li>\n<\/ul>\n
ref: Windows Server 2016 Hardening Checklist | UT Austin Information Security Office<\/a><\/p>\n https://www.powershellgallery.com/packages?q=Tags%3A\"cis\"<\/a><\/p>\n If anyone has done this before, please share some pointers or links.<\/p>\n Thanks<\/p>\n Atul<\/p>","upvoteCount":10,"answerCount":4,"datePublished":"2019-09-26T09:06:37.000Z","author":{"@type":"Person","name":"atuldogra0008","url":"https://community.spiceworks.com/u/atuldogra0008"},"suggestedAnswer":[{"@type":"Answer","text":" Hi folks,<\/p>\n I have been assigned an task for hardening of windows server based on CIS benchmark.<\/p>\n fyi - existing production environment running on AWS.<\/p>\n As per my understanding CIS benchmark have levels i.e 1 and 2. Depending on your environment and how much your can restrict your environment.<\/p>\n Steps should be :<\/p>\n Run CIS benchmark auditing tool or script against one or 2 production server.<\/p>\n<\/li>\n Identify gaps and what is missing.<\/p>\n<\/li>\n Apply gpo that follows CIS benchmark. to Test server or clone of existing production server. See the impact on production envrionment operations and share with business.?<\/p>\n<\/li>\n<\/ul>\n ref: Windows Server 2016 Hardening Checklist | UT Austin Information Security Office<\/a><\/p>\n\n