The Center for Internet Security (CIS) provides globally recognized, industry-standard benchmarks to securely configure systems, applications, and networks. However, these rules may not be directly applicable to every organization’s compliance and operational requirements, as each environment has unique security, business, and regulatory needs.
Compliance requirements vary across industries. Healthcare organizations must protect sensitive patient data, while financial institutions focus on transaction security, fraud prevention, and auditability. Retail organizations prioritize securing payment systems and customer data, whereas government entities emphasize strict access controls and data sovereignty. Similarly, manufacturing environments often need to balance security with operational continuity to avoid disruptions. These differences make it essential to customize CIS benchmarks to align with specific organizational requirements.
Using Vulnerability Manager Plus, organizations can tailor CIS compliance by creating custom rules from scratch, modifying existing rules, or combining multiple rules into policy templates. This flexibility ensures that compliance policies are aligned with CIS standards while adapting to business needs, enabling consistent security enforcement and effective compliance audits across endpoints.
Go to Compliance → Policy Templates, and click on Create Custom Policy. Select the required operating system (Windows or Linux). After selecting the required Operating System, you can either create policies with custom rules from scratch or import and customize exisitng policy to suit your needs.




To know more about configuring rule categories for windows, refer to this page. For linux refer to this page.



Note: Ensure that the rules and policies you select while customizing or importing are of the same OS/Software Identifier. If different OS/Software Identifiers are selected, the compliance audit will still be performed, but the rule will be marked as Not Applicable. A warning message similar to the one below will also be displayed.

Note: Under each rule group/policy, a maximum of 1000 rules can be configured, and under each rule, you can configure up to 50 checks. If you want to configure more than the mentioned limit, create additional rule groups or policies or rules as needed.
Once you have published the customized policy, you can use them to perform compliance audits. To learn more about compliance audits, refer to this page.