Suggestions for improving CIS WorkBench

Create browser benchmarks for macOS

The current Google Chrome and Microsoft Edge CIS benchmarks are created for Windows devices. Since the majority of the keys are similar for macOS devices, why not ...
Suggested by: Mattias (09 Apr, '25) Upvoted: 06 Dec, '25 Comments: 0
Under consideration

2FA on CIS WorkBench

I was just auditing all of my online accounts and making sure to enable 2FA everywhere it is possible and was surprised that this site does not seem to have that ...
Suggested by: JVF (16 Jul, '24) Upvoted: 06 Dec, '25 Comments: 3
Under consideration

Easier way to download .docx or .xlsx versions of the .pdf files which document the controls.

I want to download the .docx or .xlsx version of a Linux (CIS_Ubuntu_Linux_20.04_LTS_Benchmark_v2.0.1) document but cannot find it. This is the same for a number of ...
Suggested by: BB (05 Jul, '24) Upvoted: 15 May Comments: 1
Done

Dark Mode

I would like to see a dark mode for the site. This could be a valuable accessibility feature for many users.
Suggested by: Charles Pierce (03 May, '24) Upvoted: 14 Oct, '25 Comments: 0
Under consideration

CIS-CAT Pro Combined Assessment Report of Entire Organization

Create a report that combines the assessments into one report for a complete overview of the entire environment
Suggested by: Kevin Garnier (16 Jan, '25) Upvoted: 03 Jun, '25 Comments: 1
Gathering user feedback

Drop the workbench account expiration and password reset

It baffles me that an organisation focused on IT security forces a password reset every 60 days, a security practice outdated since many years. Also, the email sent ...
Suggested by: Simon C. Tremblay (03 Jun, '24) Upvoted: 08 Jan Comments: 2
Under consideration

Improve search filtering in CIS workbench

I was trying to search for build kits under the downloads section. If I typed in "build kits" it gave me many results. If I added additional words such as "windows", ...
Suggested by: Michael (26 Aug, '25) Upvoted: 15 May Comments: 0
Under consideration

404 Error for "see what's changed"

When downloading the assessor tool, your "see what's changed" button leads to a 404 page not found. I'm just trying to see if I need the latest version but I'm not ...
Suggested by: Amy Raymond (01 Apr, '25) Upvoted: 02 Oct, '25 Comments: 0
Done

Ability to change email

Hello. It seems that I cannot change my email in my profile.
Suggested by: Olivier Debré (01 Feb, '25) Upvoted: 18 Jul, '25 Comments: 0
Under consideration

Hardened images for download

ISO or prebuilt virtual images for those of us on prem. I saw this requested in the forum, but didn't see a request in the suggestions: I know we have the ability to ...
Suggested by: Riley (09 Dec, '24) Upvoted: 29 Jan, '25 Comments: 0
Gathering user feedback

Provide link to CIS-CAT downloads

Just need a simple direct link to download CIS-CAT, but the email confirmation just directs to Workbench, and within Workbench it's not obvious to me.
Suggested by: Mark M (27 Jun, '25) Upvoted: 02 Sep, '25 Comments: 3
Done

CIS_Controlsv8.1 : Newcomer w/comments seeking the proper forum to share back w/ originating authors

As a consumer of CIS controls to assist customers, I finally am at the point to get involved to a degree where viewed as helpful. Initially perusing Control 3: DATA ...
Suggested by: Rich L (06 Aug, '24) Upvoted: 29 Aug, '24 Comments: 3

Add a tag for "Policy templates"

I was looking for Policy templates in the Downloads section and found that the templates did not have a specific tag associated with them. Pleas consider adding a ...
Suggested by: Brad Beckenhauer (25 Apr, '24) Upvoted: 03 May, '24 Comments: 2
Done

"Sorting" error

in CIS Workbench Downloads, sorting by "updated" field is not working correctly.
Suggested by: Simone Gennaioli (22 Sep, '25) Upvoted: 08 Dec, '25 Comments: 1
Gathering user feedback

make downloading docs easier

Unless I am missing something - selecting and downloading more than one document is not (easy|possible). Seems like after searching for a type / name that we should ...
Suggested by: Jim Hendrick (13 Aug, '24) Upvoted: 15 May Comments: 1
Gathering user feedback

Allow community feedback to show a post has traction

Make the ticketing system like Reddit, give us upvote and downvote buttons on posts.
Suggested by: Bryan Prather-Huff (22 Jul, '24) Upvoted: 04 Apr, '25 Comments: 1
Done

Workbench Profile Additional Fields

I'd love to add a profile picture and a link to social like LinkedIn
Suggested by: Tobias Fiebeler (20 Jun, '24) Upvoted: 27 Sep, '24 Comments: 1
Gathering user feedback

search within benchmark

why is there no search function within a benchmark? For example, I need to find all the controls that relate to PIN complexity in the "CIS Microsoft Windows 11 ...
Suggested by: Laurent (14 Aug, '25) Upvoted: 30 Sep, '25 Comments: 0
Under consideration

MS Edge v135 ScareWare Setting

I just downloaded the latest ADMX files from MS for Edge and noticed a new setting for Scareware Blocker which is supposed to detect and block those fake antivirus ...
Suggested by: Sebastian Sundell (10 Apr, '25) Upvoted: 18 Apr, '25 Comments: 0
Under consideration

Server2022v5.0.0 Build Kit Missing GPO

Within the Windows Server 2022 Benchmark v5.0.0 Build Kit, there is a callout in the PDF documentation to import GPOs for L1 Domain Controllers. Those CIS Group ...
Suggested by: Patrick Mullen (23 Apr) Upvoted: 23 Apr Comments: 3

Assessor 4.5.1 contains vulnerable jackson-databind component (CVSS v3: Score: 8.1)

Hello, with all respect for your great and hard work, this is to let you know, that the latest (as well as previous releases) Assessor contains vulnerable component ...
Suggested by: Michał Wawer (11 Mar, '25) Upvoted: 11 Mar, '25 Comments: 2
Done

Server 2025

When can we expect Windows Server 2025 (released 11/1/24) benchmarks?
Suggested by: Joe Bruns (05 Nov, '24) Upvoted: 05 Nov, '24 Comments: 2

Update Red Hat Enterprise Linux 9 Benchmark Section 1.6.2

CIS Red Hat Enterprise Linux 9 Benchmark Section 1.6.2 (Ensure system wide crypto policy is not set in sshd configuration) is wrong. On RHEL9 system wide crypto ...
Suggested by: Mihajlo (12 May) Upvoted: 12 May Comments: 1

Audit Procedure incorrect

For GitLab "1.1.5 Ensure there are restrictions on who can dismiss code change reviews" I think the audit procedure is not complete what happens after I ...
Suggested by: Julian (30 Apr) Upvoted: 30 Apr Comments: 1

Email change?

Can’t figure out how to change my account email. Please advise.
Suggested by: Eric Feign (26 Apr) Upvoted: 26 Apr Comments: 1

Detailed benchmark information

I have reviewed several benchmarks, particularly those related to Windows Workstation and Windows Server. Overall, I found that most controls are well-defined and ...
Suggested by: dawood (10 Apr) Upvoted: 10 Apr Comments: 1

xml (-cpe-dictionary, cpe-oval, oval, xccdf) file for F5 Networks

There is no XML file available for F5, and the only version of F5 currently listed is archived. Could you upload a newer version or make the XML file available?
Suggested by: Jamie (19 Mar) Upvoted: 19 Mar Comments: 1
Gathering user feedback

CIS Microsoft Windows 11 Stand-alone v4.0.0 L1 - 2.2.23 (L1) - Include printspoolerservice

2.2.23 (L1) Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE' FAILED due to: Output 'printspoolerservice' && 'network service' && ...
Suggested by: N M (10 Mar) Upvoted: 10 Mar Comments: 1

CIS CAT Pro: Windows Server Benchmarks for Windows OS that use 3rd party Virusscanner/Firewall etc.

Hi, I would be very helpfull to have a set of Benchmarks for CIS CAT Pro for instances of Windows Server where the customer uses a 3rd party Virusscanner/Firewall. ...
Suggested by: H.Y. (07 Mar) Upvoted: 07 Mar Comments: 1

CIS-CAT Pro Assessor Download (See what's changed.) - Dead link

From this page. (https://workbench.cisecurity.org/download/cis-cat/assessor). 404-Dead link - (https://workbench.cisecurity.org/community/30/discussions/12709)
Suggested by: C (20 Feb) Upvoted: 20 Feb Comments: 1
Done

Oracle19c-benchmark

Since new CISCAT 4.58/9 the regular Oracle19c Benchmark for unified auditing has been removed/disappeared. This was available until CISCAT 4.56/7. Please add this ...
Suggested by: Peter Verschoor (20 Feb) Upvoted: 20 Feb Comments: 1

Update to Linux Mint 22.3 "Zena?"

Currently using the C4K-linuxmint-10-25-2025.iso to install CIS-configured Linux Mint 22.2 Cinnamon for the Reno Cigar Lions Club's Computers 4 Kids giveaways. I ...
Suggested by: Eric Feign (16 Feb) Upvoted: 16 Feb Comments: 1
Done

9.1.10 - (L1) : Service principals can use Fabric APIs

The option : Service principals can use Fabric APIs is not an option anymore. Probaply changed or removed. ...
Suggested by: Dimitri Hendriks (29 Jan) Upvoted: 29 Jan Comments: 1

network security auditing

i want to audit network security in the financial sector, for perfect assessment network efficiency i want a good checklists for the success of my audit points ...
Suggested by: lencho kimo (28 Jan) Upvoted: 28 Jan Comments: 1

Request for CIS Benchmark Comparison Feature

I’m looking for a way to compare Windows 11 Enterprise CIS Benchmarks version 3.0 against version 4.0. It has been challenging to identify which policies have ...
Suggested by: Bryan (12 Jan) Upvoted: 12 Jan Comments: 1
Done

No Active License Keys

Hello, there is No Active License Keys for Orange. I can not use my Assessor Pro application. Do you know what happened? Regards Paweł Giergoń Orange Polska
Suggested by: Paweł Giergoń (12 Jan) Upvoted: 12 Jan Comments: 1

More helpful email notifications

I get a lot of emails about work being done in Workbench, but few of them seem to give me the context I need within the email or in the link to understand what was ...
Suggested by: Tim Smith (08 Jan) Upvoted: 08 Jan Comments: 1

Delays in CIS-CAT Assessor v4.57 continue to be unexplained

There is a continued lack of communication in the status of the release of v4.57 this is impacting my project and put at risk our longstanding recommendation of its ...
Suggested by: Steve Cobrin (13 Nov, '25) Upvoted: 13 Nov, '25 Comments: 1
Done

ASLR checks in versions of RHEL CIS are giving False positives

Hi, I have looked into the profiles of CIS for Red Hat Enterprise, and found the checks for ASLR are implemented differently. (FP = False Positive) CIS Red Hat ...
Suggested by: Mattias Lindström (11 Nov, '25) Upvoted: 11 Nov, '25 Comments: 1

Review webinars page for Linux

If you visit https://workbench.cisecurity.org/support-center/pages/recorded-webinars you will see a link to a video on CIS-CAT Pro on Linux/Unix but the video link is ...
Suggested by: Eddie Rowe (31 Oct, '25) Upvoted: 31 Oct, '25 Comments: 1
Done

Windows 2016: 2.3.10.1: 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'

CIS Microsoft Windows Server 2016 Benchmark v4.0.0 2.3.10.1 (L1) Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled' Below Audit ...
Suggested by: Deepak Sridharan (28 Oct, '25) Upvoted: 28 Oct, '25 Comments: 1

2.6.6.6.2.1.1 Audit Procedure Path incorrect

The Audit procedure for 2.6.6.6.2.1.1 in the Office Enterprise benchmark suggests the path to be: "HKEY_USERS\[USER ...
Suggested by: Mehmanesh (28 Oct, '25) Upvoted: 28 Oct, '25 Comments: 1

TOAD SERVER

Dear Team, We are using Toad server but when we perform cis scan then we got an error oci error kindly check
Suggested by: Muhammad Asim (16 Oct, '25) Upvoted: 16 Oct, '25 Comments: 1

motd and network access

We see that motd accesses a server on AWS on port 8089. But should this service not be disabled, or at least not being able to contact servers on the internet and ...
Suggested by: Jacques (09 Oct, '25) Upvoted: 09 Oct, '25 Comments: 1
Gathering user feedback

add user button

add user button does not always work when I click on it.
Suggested by: Vanessa Smith (03 Oct, '25) Upvoted: 03 Oct, '25 Comments: 1
Gathering user feedback

Typo on benchmark for macOS 14.

When going to your v2.1.0 build kit => CIS Apple macOS 14.0 Sonoma Benchmark v2.1.0 - Build Kit We are offered to download this build kit => ...
Suggested by: Jules DAVID (24 Sep, '25) Upvoted: 24 Sep, '25 Comments: 1

Link broken

Tried to view the "What's changed" URL and got a 401 error. Assessor v4.56.0 (latest) Analyze target systems configuration and generate reports. See what's changed.
Suggested by: Brad Beckenhauer (15 Aug, '25) Upvoted: 15 Aug, '25 Comments: 1

Clarification of 4.1.5Secure Permissions for the Primary Archive Log Location (LOGARCHMETH1)

The control is about secure archive log location but the benchmark requirement is "Although there are many ways to ensure that your primary logs will be archived, we ...
Suggested by: Rex Liu (30 Jul, '25) Upvoted: 30 Jul, '25 Comments: 1

Question

Hey Guys, So my suggestion is that you make all your effort a little bit more intuitive or user-friendly, maybe also actualize the infos, I have the feeling there ...
Suggested by: Marcelo Ramos (23 Jul, '25) Upvoted: 23 Jul, '25 Comments: 1