You can use pre-built compliance templates based on existing frameworks created by organizations such as Center for Internet Security (CIS) and National Institute of Standards and Technology (NIST).
- In Elevate, click Compliance in the sidebar.
- Select a benchmark template from the available templates.
- Use the General pane to configure basic settings for the benchmark, including the display name, description, and enforcement type.
Best Practice:
Jamf recommends beginning your compliance benchmarks implementation with a Monitor only enforcement type.
- Click Next.
- Configure the scope of the compliance benchmark configuration.
Note:
Compliance benchmarks supports scoping with smart computer groups for targeted benchmark deployment, enabling you to phase your implementation or maintain different security standards for various device groups.
- Click Next.
- (Optional) Customize individual compliance rules for the configuration.
You can customize the benchmark by choosing which rules to include in your deployment. All rules are selected by default, but any rule can be deselected to create a customized configuration. You can also view specific details associated with each rule. Certain rules contain organization-defined values (ODVs) that can be defined during this step.
- Click Next.
- Review the deployment.
When reviewing the deployment, you can view the collection of management settings that will be created. For configuration profiles, extension attributes, and scripts, you can view specific contents of the settings prior to deployment.
- Click Save and deploy.
The new compliance benchmark configuration is created and deployed to the specified devices. The generation of management settings can take up to 15 minutes. You can navigate away from compliance benchmarks during the generation process if necessary. The benchmark card will display "In Progress" during this process. After all settings have been generated, the card will display "Deployed".