# Fetch CIS benchmark rule details for a compliance profile Retrieves CIS benchmark rule-level details for a specific profile and resource. Shows the hierarchical rule tree (groups/subgroups/rules), scan results, and remediation fix text. ## Endpoints `GET /dcapi/scap/compliance/benchmark` ## Request ### Request URL `https://`[{serverurl}](https://www.manageengine.com/products/desktop-central/help/api/cloud/oauth-authentication-endpoint-domain.html)`/dcapi/scap/compliance/benchmark` ### Scope `DesktopCentralCloud.VulnerabilityMgmt.READ` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ### Request Parameters #### Query Parameters | Parameter | Type | Required | Description | |---|---|---|---| | profileId | long | Optional | CIS profile/benchmark ID | | profileType | long | Optional | Profile type. 1 = XCCDF, 0 = OVAL | | resourceId | long | Optional | Computer/resource ID | | collectionId | long | Optional | Collection ID of the compliance association | ### Sample Request ```curl curl --request GET \ --url https://appdomains/dcapi/scap/compliance/benchmark \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' ``` ## Response Parameters ### HTTP Code 200 Response Body: `application/json` | Parameter | Type | Description | |---|---|---| | scanStatus | string | Scan status. `SCAN_COMPLETED` or `YET_TO_SCAN` | | profileId | long | The queried profile ID | | title | string | Constructed as policyName - profileTitle | | summary | string | Profile description (sanitized HTML) | | scapType | string | SCAP standard type. `XCCDF` or `OVAL` | | source | string | Built-in or Custom | | date | string | Upload timestamp of the benchmark | | steps | JSON Array | Hierarchical tree of groups/rules with scan results | | totalCount | string | Total number of rules | ### HTTP Code 401 Response Body: `application/json` | Parameter | Type | Description | |---|---|---| | errorCode | long | Unauthorized error code: credentials missing, expired, or invalid | | errorMsg | string | Authentication failure reason | ### HTTP Code 429 Response Body: `application/json` | Parameter | Type | Description | |---|---|---| | errorCode | long | Rate limit error code returned when the API call reached threshold | | errorMsg | string | Rate limit exceeded message with retry guidance | ## Possible Response Codes | Code | Type | |---|---| | 200 | HTTP code | | 401 | HTTP code | | 429 | HTTP code | ## Sample Responses ### HTTP 200 #### Benchmark details with scanned rule results ```json { "summary": "This profile covers Level 1 CIS benchmark rules for Windows Server 2019", "date": "2026-01-15 10:30:00", "scapType": "XCCDF", "profileId": 50001, "scanStatus": "SCAN_COMPLETED", "source": "Built-in", "title": "CIS Windows Server 2019 - CIS Level 1 (L1)", "totalCount": 245, "steps": [ { "itemId": 1, "children": [ { "itemId": 101, "cssClass": "compliance--status__passed", "statusText": "Passed", "fixText": "View Details", "title": "Ensure Account lockout threshold is set to 5 or fewer", "type": "rule", "status": 0 }, { "itemId": 102, "cssClass": "compliance--status__failed", "statusText": "Failed", "fixText": "View Resolution", "title": "Ensure Password length is 14 or more", "type": "rule", "status": 1 } ], "title": "Account Policies", "type": "group" } ] } ``` #### Benchmark details before scan has been executed ```json { "summary": "This profile covers Level 1 CIS benchmark rules for Windows Server 2019", "date": "2026-01-15 10:30:00", "scapType": "XCCDF", "profileId": 50001, "scanStatus": "YET_TO_SCAN", "source": "Built-in", "title": "CIS Windows Server 2019 - CIS Level 1 (L1)", "totalCount": 245, "steps": [] } ``` ### HTTP 401 Authentication credentials are missing or invalid. ```json { "errorMessage": "Authentication required", "errorCode": "UNAUTHORIZED" } ``` ### HTTP 429 API call threshold exceeded. ```json { "errorMessage": "Rate limit exceeded. Retry after some time", "errorCode": "TOO_MANY_REQUESTS" } ``` ## API Rate Limit ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.