Skip to main content

Security Services

CIS Hardening Services for Linux

Strengthen your Linux configurations against recognised security benchmarks

Secure configurations are difficult to maintain as systems, applications and operational requirements change.

Understand where your systems stand
  • Identifying the applicable CIS Benchmark and profile
  • Assessing current configurations against the selected baseline
  • Reviewing findings and identifying legitimate exceptions
  • Prioritising changes according to risk and operational impact
  • Producing a prioritised plan for any remediation needed
Discuss your environment with a Linux specialist

Level 1

Level 2

  • Filesystem and boot configuration
  • Services, packages and listening ports
  • Firewall and network settings
  • User accounts, authentication and password controls
  • Privileged and administrative access
  • SSH configuration
  • File permissions and ownership
  • Logging, auditing and time synchronisation
  • Update and patch-related configuration
  • Security policies and configuration consistency
  • Building a new Linux platform
  • Standardising configurations across an existing estate
  • Responding to a security assessment or audit finding
  • Preparing for a compliance or customer-assurance exercise
  • Reviewing cyber-insurance requirements
  • Moving workloads into a cloud or hybrid environment
  • Strengthening systems that handle sensitive data or critical services
  • Looking for a repeatable security baseline for future deployments

1. Assessment

2. Remediation

3. Ongoing support

Customer success: secure Linux in a regulated environment

Tiger Computing has implemented CIS hardening for Sucden Financial and supports more than 36 Linux systems within its trading-platform environment, where uptime, security and compliance are critical.

The result is improved stability, stronger operational oversight and greater confidence that the environment is proactively maintained.

Read the Sucden Financial case study
GET HELP NOW

What is a CIS Benchmark?

A CIS Benchmark is a set of prescriptive configuration recommendations developed through a consensus-based process led by the Center for Internet Security. Benchmarks are available for numerous operating systems, cloud platforms, server products and other technologies.

Is CIS hardening the same as a penetration test or vulnerability scan?

No. CIS hardening focuses on secure configuration against a defined Benchmark. Penetration testing and vulnerability scanning address different aspects of security and may be used alongside configuration hardening.

Will CIS hardening affect our applications?

Configuration changes can affect applications or operational processes. This is why the selected recommendations should be reviewed in context and tested before production implementation. Level 2 recommendations require particular care.

Does CIS alignment make us compliant?

Not on its own. CIS-aligned configurations can support wider security and compliance programmes, but compliance depends on the complete set of applicable technical, procedural and organisational requirements.

How often are systems reassessed?

The appropriate frequency is agreed as part of the support arrangement and depends on the systems, risk profile and operational requirements. Automated assessments can be run on a regular schedule, with the results reviewed for configuration drift and recommended actions.

What happens when a CIS Benchmark changes?

Ongoing support can include keeping the customised baseline aligned with applicable minor Benchmark revisions. A major Benchmark version or changes requiring substantial remediation may need a separate assessment and implementation project.

How is this different from Tiger's Linux Security Hardening service?

Linux Security Hardening is Tiger’s broader service for identifying and addressing security weaknesses across a Linux environment. CIS Hardening Services provide a more defined route for assessing and improving configurations against an agreed CIS Benchmark and profile.