Fetch CIS benchmark rule details for a compliance profile

Open in ChatGPT Open in ChatGPT to ask questions about this page
Open in Claude Open in Claude to ask questions about this page
Copy as MarkdownCopy this page as markdown to use with AI assistants
View as Markdown Open this page as markdown in a new tab

Retrieves CIS benchmark rule-level details for a specific profile and resource. Shows the hierarchical rule tree (groups/subgroups/rules), scan results, and remediation fix text

Request URL

https://{server-hostname}:8383/dcapi/scap/compliance/benchmark

Scope

VulnerabilityMgmt.READCopied!

Header

Authorization: d92d4xxxxxxxxxxxxx15f52

Sample Request

Curl
Java
Python
Deluge
PowerShell
Copied!
curl --request GET \
  --url https://appdomain/dcapi/scap/compliance/benchmark \
  --header 'Authorization:  d92d4xxxxxxxxxxxxx15f52'
Show full

Response Parameters

- HTTP code 200

Response Body - application/json
JSON object
Hide Sub-Attributes
scanStatusstring

Scan status. SCAN_COMPLETED or YET_TO_SCAN

profileIdlong

The queried profile ID

titlestring

Constructed as policyName - profileTitle

summarystring

Profile description (sanitized HTML)

scapTypestring

SCAP standard type. XCCDF or OVAL

sourcestring

Built-in or Custom

datestring

Upload timestamp of the benchmark

stepsJSON array

Hierarchical tree of groups/rules with scan results

Show Sub-Attributes
JSON object
Show Sub-Attributes
itemIdlong

Unique identifier of the group or rule

titlestring

Title of the group or rule

typestring

Item type. group or rule

statusstring

Rule result status code. 0=Passed, 1=Failed, 2=Unknown, 3=Error, 4=NotApplicable, 5=Unscored, 6=Unselected, 7=Informational, 8=Fixed

statusTextstring

Human-readable status label (e.g., Passed, Failed, Error)

cssClassstring

CSS class for status styling

fixTextstring

Fix text label: View Resolution, View Details, or View Reason

childrenJSON array

Child groups and rules (recursive hierarchy)

Show Sub-Attributes
JSON object
Show Sub-Attributes
Refer to benchmarkStepItem
totalCountstring

Total number of rules

- HTTP code 401

Response Body - application/json
JSON object
Hide Sub-Attributes
errorCodelong

Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required)

errorMsgstring

Authentication failure reason

- HTTP code 429

Response Body - application/json
JSON object
Hide Sub-Attributes
errorCodelong

Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes

errorMsgstring

Rate limit exceeded message with retry guidance

Possible Response Codes

200HTTP code
401HTTP code
429HTTP code

Sample Response: HTTP 200

Benchmark details with scanned rule results

Copied!
  {
    "summary": "This profile covers Level 1 CIS benchmark rules for Windows Server 2019",
    "date": "2026-01-15 10:30:00",
    "scapType": "XCCDF",
    "profileId": 50001,
    "scanStatus": "SCAN_COMPLETED",
    "source": "Built-in",
    "title": "CIS Windows Server 2019 - CIS Level 1 (L1)",
    "totalCount": 245,
    "steps": [
      {
        "itemId": 1,
        "children": [
          {
            "itemId": 101,
            "cssClass": "compliance--status__passed",
            "statusText": "Passed",
            "fixText": "View Details",
            "title": "Ensure Account lockout threshold is set to 5 or fewer",
            "type": "rule",
            "status": 0
          },
          {
            "itemId": 102,
            "cssClass": "compliance--status__failed",
            "statusText": "Failed",
            "fixText": "View Resolution",
            "title": "Ensure Password length is 14 or more",
            "type": "rule",
            "status": 1
          }
        ],
        "title": "Account Policies",
        "type": "group"
      }
    ]
  }
                
Show full

Benchmark details before scan has been executed

Copied!
  {
    "summary": "This profile covers Level 1 CIS benchmark rules for Windows Server 2019",
    "date": "2026-01-15 10:30:00",
    "scapType": "XCCDF",
    "profileId": 50001,
    "scanStatus": "YET_TO_SCAN",
    "source": "Built-in",
    "title": "CIS Windows Server 2019 - CIS Level 1 (L1)",
    "totalCount": 245,
    "steps": []
  }
                
Show full

Sample Response: HTTP 401

Authentication credentials are missing or invalid

Copied!
  {
    "errorMessage": "Authentication required",
    "errorCode": "UNAUTHORIZED"
  }
                
Show full

Sample Response: HTTP 429

API call threshold exceeded

Copied!
  {
    "errorMessage": "Rate limit exceeded. Retry after some time",
    "errorCode": "TOO_MANY_REQUESTS"
  }
                
Show full

Duration: 1 minute | Threshold: 30 | Lock period: 5 minutes

Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.