Compliance Benchmarks Template Reference

Compliance Benchmarks Configuration Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Center for Internet Security (CIS) Templates

The CIS benchmarks are available in the following security levels to match your organization's needs:

CIS Level 1
Establishes essential cybersecurity safeguards for organizations with limited IT resources, focusing on foundational controls to protect against common threats with minimal technical complexity.
CIS Level 2
Provides enhanced cybersecurity safeguards for organizations managing sensitive information or facing increased risk exposure, implementing intermediate controls that balance security effectiveness with operational scalability.
CIS v8
Establishes prioritized safeguards to mitigate common cyber attack vectors, providing actionable security controls organized by implementation groups for organizations of varying resources and risk profiles.

National Institute of Standards and Technology (NIST) Templates

NIST 800-53 Rev 5 Low
Provides baseline security controls for information systems and organizations with low-impact data, focusing on fundamental protections with minimal operational complexity.
NIST 800-53 Rev 5 Moderate
Establishes enhanced security controls for information systems handling moderate-impact data, balancing security requirements with operational efficiency.
NIST 800-53 Rev 5 High
Defines comprehensive security controls for information systems processing high-impact data, implementing the most stringent protections for critical assets.
NIST 800-171
Provides security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations, focusing on practical controls for contractors and partners handling sensitive government data.

Committee on National Security Systems Instruction (CNSSI) Templates

CNSSI 1253 Low
Defines baseline security controls for national security systems and organizations with low-impact data, establishing fundamental protections tailored to classified and sensitive government information.
CNSSI 1253 Moderate
Establishes enhanced security controls for national security systems handling moderate-impact data, balancing mission requirements with robust protections for classified information.
CNSSI 1253 High
Provides comprehensive security controls for national security systems processing high-impact data, implementing the most stringent safeguards for critical national security operations.

Cybersecurity Maturity Model Certification (CMMC) Templates

US CMMC 2.0 Level 1
Establishes foundational cybersecurity practices for Department of Defense contractors, focusing on basic safeguarding of Federal Contract Information through essential security controls.
US CMMC 2.0 Level 2
Defines advanced cybersecurity practices for Department of Defense contractors handling Controlled Unclassified Information, implementing comprehensive protections aligned with NIST 800-171 requirements.

Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)

DISA STIG
Provides technical configuration standards for hardening information systems and software, establishing prescriptive security settings to reduce vulnerabilities in Department of Defense environments.

Government Information Security Baseline 2 (BIO2)

NLMAPGOV Base
Establishes foundational security controls for Apple devices in Dutch government organizations, implementing essential protections aligned with the Government Information Security Baseline 2 (BIO2) requirements.
NLMAPGOV Plus
Provides enhanced security controls for Apple devices in Dutch government environments, building upon the base protections with additional safeguards to meet elevated BIO2 compliance requirements and risk profiles.