Understanding Compliance Policies
The compliance feature helps with adherence to specific baseline configurations for endpoints to improve security and meet regulatory requirements. Endpoint Central's compliance module regularly audits your systems' configurations against known standards like CIS benchmarks and provides detailed steps to help comply with them.
Overview
Each compliance policy is a collection of rules based on globally-accepted standards and best practice guidelines for security configurations, which can be used to audit your endpoints and the software running on them to understand and improve their security posture. The first line of defense against cyber attacks is to ensure foundational security configurations are implemented and maintained in your endpoints.
Applies to:
- Windows
- Linux
CIS Policies
The Center for Internet Security (CIS) develops benchmarks for a variety of applications, operating systems, servers, and databases through a unique consensus-based process involving a community of cybersecurity professionals and subject matter experts from around the world. CIS Benchmarks contain standards and best practices for fine-tuning security configurations of a target system and are used by organizations across the globe in meeting security and compliance objectives. Configuration recommendations detailed in PCI DSS, HIPAA, FISMA, and other regulatory frameworks align with and point to CIS benchmarks as the definitive standard.
Endpoint Central out-of-box CIS policies are direct derivatives of the latest CIS benchmarks and are officially certified by CIS to be used in audits. The certifications are earned by submitting test cases for all the rules (recommendations for configurations) within each benchmark for validation by CIS personnel. With the Endpoint Central CIS compliance feature, endpoint security configurations can be assessed for compliance with the rules in CIS policies, and remediation actions are recommended for each violation.
Each rule in the policy is assigned a profile. The profile indicates the security level of the recommended configuration:
- Profile Level 1 (L1) — Indicates minimum configuration recommendations, generally considered safe to apply to most systems without extensive performance impact. Policies with a Level 1 profile label contain only Level 1 configuration recommendations or rules.
- Profile Level 2 (L2) — Considered defense-in-depth, these include configuration recommendations for highly secure environments and require more coordination and planning to implement with minimal business disruption. Policies with a Level 2 profile contain both Level 1 and Level 2 configuration recommendations or rules.
View the complete list of CIS benchmarks officially supported by Endpoint Central.
Navigating CIS Policies in the Console
Navigate to Compliance → Policy Groups and click the Create Group button. After selecting the platform, you will be redirected to a new window where you can see a list of policies. Selecting a policy reveals a detailed breakdown of its constituent rules. The following image shows how a CIS benchmark policy is structured.

Understanding Policy Rules
The rules within each CIS policy are grouped based on the component they pertain to, such as password policies, account lockout policies, and so on. Click on a component title to expand and view its rules. Each rule suggests a recommended value for a security configuration. During the audit scan, your systems' security configurations will be assessed for compliance with these rules. Clicking on a rule reveals:
- A detailed summary of the security setting or configuration, the default value, the range of values it accepts, and the recommended value.
- A rationale that offers a detailed reasoning for the recommended value.
- A How to Fix column that provides detailed steps to implement the recommended value if your system's setting has violated the rule.
After selecting the required CIS compliance policies, click Create Group to finish creating the policy group. You can use this policy group for CIS compliance audit purposes.