A CIS Benchmark is a set of prescriptive configuration recommendations developed through a consensus-based process led by the Center for Internet Security. Benchmarks are available for numerous operating systems, cloud platforms, server products and other technologies.
Security Services
CIS Hardening Services for Linux
Strengthen your Linux configurations against recognised security benchmarks
Secure configurations are difficult to maintain as systems, applications and operational requirements change.
Tiger Computing helps organisations assess and harden Linux systems against the appropriate CIS Benchmark. We identify configuration gaps, establish a practical target baseline and help implement improvements without losing sight of application dependencies, performance or service continuity.
The assessment is the entry point. Remediation can follow where it is needed, while ongoing support helps maintain the agreed baseline as systems and CIS Benchmarks evolve.
Book a discovery call to discuss:
- The Linux systems and distributions in scope
- Your reason for considering CIS hardening
- The Benchmark or security requirements you need to address
- How to scope an initial assessment
- How remediation and ongoing baseline management could follow if required
Understand where your systems stand
Book a discovery call with Shaun Poole.
Start with a clear assessment
Tiger Computing applies CIS guidance in the context of your real environment.
We work with your technical and security teams to understand the systems in scope, their purpose, application dependencies and the level of assurance required. We then help you establish and implement an appropriate baseline.
Depending on your requirements, the engagement can include:
- Identifying the applicable CIS Benchmark and profile
- Assessing current configurations against the selected baseline
- Reviewing findings and identifying legitimate exceptions
- Prioritising changes according to risk and operational impact
- Producing a prioritised plan for any remediation needed
The assessment is valuable in its own right. It gives you a clearer view of your current configuration, the gaps that matter and the practical next steps, without assuming that every recommendation must be implemented immediately.
CIS Level 1 or Level 2?
Most CIS Benchmarks include more than one configuration profile.
Level 1
A base set of recommendations intended to reduce the attack surface while limiting the impact on usability and business functionality.
Level 2
Builds on and extends Level 1 with additional defence-in-depth recommendations for environments where security is paramount. These controls require greater care because they can affect system operation if they are applied without appropriate testing and planning.
What can CIS hardening address?
The applicable recommendations depend on the selected Benchmark and your environment. Areas commonly reviewed can include:
- Filesystem and boot configuration
- Services, packages and listening ports
- Firewall and network settings
- User accounts, authentication and password controls
- Privileged and administrative access
- SSH configuration
- File permissions and ownership
- Logging, auditing and time synchronisation
- Update and patch-related configuration
- Security policies and configuration consistency
Scope note: Supported Linux distributions, cloud platforms, assessment tooling and the precise technical scope must be confirmed for each engagement.
When should you consider CIS hardening?
CIS hardening may be relevant when you are:
- Building a new Linux platform
- Standardising configurations across an existing estate
- Responding to a security assessment or audit finding
- Preparing for a compliance or customer-assurance exercise
- Reviewing cyber-insurance requirements
- Moving workloads into a cloud or hybrid environment
- Strengthening systems that handle sensitive data or critical services
- Looking for a repeatable security baseline for future deployments
CIS-aligned configurations can support wider security and compliance programmes. They do not, by themselves, guarantee compliance or certification.
A journey from assessment to ongoing assurance
Each stage delivers a strategic business outcome. You can progress according to your priorities, risks and operational readiness.
1. Assessment
We establish the scope, agree the appropriate CIS Benchmark and customised baseline, assess the current configuration and produce a prioritised remediation plan.
Outcome: A clear view of your current position and the work required to improve it.
2. Remediation
Where you decide to proceed, remediation is scoped as one project or several phases depending on the number of systems, findings and operational complexity. Agreed changes are tested and introduced through a controlled approach before the resulting configuration is validated.
Outcome: Agreed hardening improvements implemented with dependencies, exceptions and service continuity considered.
3. Ongoing support
Under an appropriate support arrangement, Tiger can run automated assessments at an agreed frequency to check systems against the customised baseline. We review the results, identify configuration drift and recommend any action needed to restore alignment.
Ongoing support can also keep the baseline aligned with applicable minor revisions to the CIS Benchmark. Significant changes, including major Benchmark versions or substantial remediation, are assessed and scoped separately.
Outcome: Continued visibility and a maintainable baseline as systems and Benchmark recommendations evolve.
Customer success: secure Linux in a regulated environment
The result is improved stability, stronger operational oversight and greater confidence that the environment is proactively maintained.
Why Tiger Computing?
Linux specialists
Linux has been Tiger Computing’s focus since 2002. Our engineers understand how security changes interact with real Linux applications and operational environments.
Practical implementation
We can support each stage of the journey: assessing the current position, planning and implementing separately scoped remediation, and maintaining the agreed baseline through ongoing support.
Risk-based recommendations
We consider system purpose, dependencies and service continuity instead of treating every recommendation as an isolated tick-box requirement.
Security-conscious delivery
Tiger Computing is ISO 27001 certified. Detailed certification wording and scope should be checked before publication.
If you’re facing a critical Linux issue, we’re ready to help.
Call us on 01600 404 270 or support@tiger-computing.co.uk and one of our engineers will be in touch without delay.
Frequently asked questions
Is CIS hardening the same as a penetration test or vulnerability scan?
No. CIS hardening focuses on secure configuration against a defined Benchmark. Penetration testing and vulnerability scanning address different aspects of security and may be used alongside configuration hardening.
Will CIS hardening affect our applications?
Configuration changes can affect applications or operational processes. This is why the selected recommendations should be reviewed in context and tested before production implementation. Level 2 recommendations require particular care.
Does CIS alignment make us compliant?
Not on its own. CIS-aligned configurations can support wider security and compliance programmes, but compliance depends on the complete set of applicable technical, procedural and organisational requirements.
How often are systems reassessed?
The appropriate frequency is agreed as part of the support arrangement and depends on the systems, risk profile and operational requirements. Automated assessments can be run on a regular schedule, with the results reviewed for configuration drift and recommended actions.
What happens when a CIS Benchmark changes?
Ongoing support can include keeping the customised baseline aligned with applicable minor Benchmark revisions. A major Benchmark version or changes requiring substantial remediation may need a separate assessment and implementation project.
How is this different from Tiger's Linux Security Hardening service?
Linux Security Hardening is Tiger’s broader service for identifying and addressing security weaknesses across a Linux environment. CIS Hardening Services provide a more defined route for assessing and improving configurations against an agreed CIS Benchmark and profile.