CIS-CAT Pro Assessor v4 reporting indicates “Pass” or “Fail” of configuration. In order to make it easier to understand why a score of “Fail” is shown, we’ve included more information. Now, an endpoint’s state and CIS Benchmark expected values appear on the HTML formatted configuration report. CIS SecureSuite Members have told us that this was a highly missed feature in v4. This addition is similar to functionality in CIS-CAT Pro Assessor v3.
Additional information has been added to the HTML configuration report, including:
The HTML report provides detailed information that can be utilized by system owners when determining the disposition of the results. For some results of “Fail,” an organization may find that the risk is already mitigated. In this case, utilize CIS-CAT Pro Dashboard to apply exceptions to the recommendations that can result in a score of “Pass” on import to CIS-CAT Pro Dashboard. Another option is to tailor the CIS Benchmark conditions or score type in CIS WorkBench.
We’ve added information to the CIS-CAT Pro Assessor v4 Online User Guide to help understand the results in the HTML report. The report now shows the overall report score and how the results were computed.
We’ve modified the display of recommendations that cannot be fully automated to show in the report body as “Manual.” Previously, these results were represented as “Informational.” This is consistent with scoring represented on our latest CIS Benchmark published documents. The *.csv and *.txt output formats on assessment configuration processes has also changed. For Members utilizing those results in ways other than importing to CIS-CAT Pro Dashboard, please verify any logic changes made in your organization’s scripts or 3rd party tools to accommodate the word change to “Manual.” This has also been modified in CIS-CAT Pro Assessor v3.0.67.
New or updated CIS Benchmark automated assessment content now supported in CIS-CAT Pro Assessor v4.0.21 includes the following technologies:
The latest CIS-CAT Pro Assessor v4 release includes additional customization options for the HTML report:
Read more about how to customize the HTML report in our online guide.
Want to be alerted more quickly when there’s a new release? Read about how to integrate CIS-CAT Pro Dashboard with CIS WorkBench.
CIS appreciates the volunteers, partners, and CIS SecureSuite Members who work together to improve configuration security for everyone. By providing feedback on best practices, testing new software builds, and sharing expertise, these communities are continuously helping CIS to improve and grow.
Interested in sharing your endpoint configuration challenges with a CIS-CAT Pro team member? Want to contribute to our design of new functionality, or test a new feature? We love hearing real-world experiences and challenges! Reach out to us at [email protected]. Your input makes a real difference.
CIS SecureSuite Members can download the latest updates to CIS-CAT Pro Dashboard by logging into CIS WorkBench. Don’t forget to check the CIS-CAT Pro Dashboard Change Log and CIS-CAT Pro Assessor v4 Change Log for a complete listing of all changes!
To take advantage of all the benefits of CIS-CAT Pro, full format CIS Benchmarks, and more, become a CIS SecureSuite Member.