Included Compliance Profiles
The following profiles are provided with SIMP Enterprise. Use these profile names in the SIMP Compliance Engine configuration to report on and enforce these industry standard benchmarks.
RHEL / CentOS / Oracle Linux 7 and 8
Center for Internet Security (CIS) - Linux
Control coverage details are documented here.
Compliance module usage details are documented here
- cis:level:1:server
- cis:level:2:server
Windows Server 2012 / 2012 R2 / 2016 / 2019
Center for Internet Security (CIS) - Windows
Control coverage details are documented here.
Compliance module usage details are documented here
- cis:level:1:domain:controller
- cis:level:2:domain:controller
- cis:level:1:member:server
- cis:level:2:member:server
Please note the following profiles are only defined by CIS on Windows 2016 and 2019. They provide enforcement for boot and virtualization options that are not available in previous versions of Windows. If needed, these profiles should be specified in addition to Level 1 or Level 2 profiles.
- cis:next:generation:windows:security:domain:controller
- cis:next:generation:windows:security:member:server
Control coverage details are documented here.
- disa_stig:xccdf_mil.disa.stig_profile_mac-1_classified
- disa_stig:xccdf_mil.disa.stig_profile_mac-1_public
- disa_stig:xccdf_mil.disa.stig_profile_mac-1_sensitive
- disa_stig:xccdf_mil.disa.stig_profile_mac-2_classified
- disa_stig:xccdf_mil.disa.stig_profile_mac-2_public
- disa_stig:xccdf_mil.disa.stig_profile_mac-2_sensitive
- disa_stig:xccdf_mil.disa.stig_profile_mac-3_classified
- disa_stig:xccdf_mil.disa.stig_profile_mac-3_public
- disa_stig:xccdf_mil.disa.stig_profile_mac-3_sensitive
- disa_stig:xccdf_mil.disa.stig_profile_disable_slow_rules
- disa_stig:xccdf_mil.disa.stig_profile_cat_i_only