skip to content

What is a CIS Benchmark, and how do its Level 1 and Level 2 profiles differ when hardening a Linux server fleet?

level: middleimportance: should knowfreq 44%

answer

  1. per product, per version
  2. consensus-based settings
  3. prudent baseline versus defence in depth
  4. Level 2 can break things

basics

~20 s

A CIS Benchmark is a consensus-based set of prescriptive configuration recommendations for one product and version. Level 1 holds practical settings with little functional impact; Level 2 adds defence-in-depth settings for high-security use that may reduce functionality or performance.

solid answer

~40 s

A **CIS Benchmark** is a prescriptive set of configuration recommendations for a specific product - CIS publishes them for more than 25 vendor product families - produced by a **consensus** process among security practitioners. Benchmarks are version-specific, so a fleet running two Linux distributions needs two Benchmarks. Recommendations are grouped into **profiles**. **Level 1** is the practical baseline: settings that give a clear security benefit without breaking normal use, suitable for most servers. **Level 2** adds recommendations meant for environments where security is paramount, as **defence in depth**, and they may reduce functionality or performance. For a server fleet, adopt Level 1 broadly, apply Level 2 to high-risk roles after testing, and document every recommendation you deliberately do not apply.

go deeper

for a junior

Recall that a CIS Benchmark is a per-product configuration guide and that Level 1 and Level 2 are its profiles.

for a middle

Explain the Level 1 versus Level 2 trade-off and why Benchmarks are chosen per distribution and version.

for a senior

Show how you would roll a Benchmark across a mixed fleet: Level 1 by default, Level 2 by role after testing, and documented exceptions.

for a principal

Discuss how to set the organization's default profile and exception policy so hardening stays in place instead of being rolled back after incidents.

## What a CIS Benchmark is A **CIS Benchmark** is a document of **prescriptive configuration recommendations** for one technology. CIS describes its Benchmarks as covering more than 25 vendor product families - operating systems, cloud platforms, network devices, databases, server and desktop software - and as the result of a **consensus-based** effort by cybersecurity experts. Each recommendation typically states the setting, why it matters, how to audit it and how to remediate it. The word *benchmark* misleads some candidates. It is not a score comparing you with peers; it is a **reference configuration** you measure your systems against. Benchmarks are **specific to product and version**. CIS publishes separate Benchmarks for different Linux distributions and for successive releases of the same distribution, because default services, file locations, package names and available security features change between them. In control-framework terms, a Benchmark is one of the "common secure configurations" that NIST SP 800-53 control `CM-6` describes - also called security configuration checklists, lockdown and hardening guides - and it is the natural way to meet **CIS Control 4**, secure configuration of enterprise assets and software. ## Profiles: Level 1 and Level 2 Recommendations are tagged with **profiles**, so that one Benchmark serves different risk appetites. | Profile | Intent | Typical effect | |---|---|---| | **Level 1** | Practical, prudent hardening with a clear security benefit | Should not stop the system doing its normal job; suits most systems | | **Level 2** | Defence in depth for environments where security is paramount | May reduce functionality, compatibility or performance; needs testing | The trade-off is the heart of the interview question: Level 2 buys extra protection by **restricting more**, and some of those restrictions have operational cost. Which specific recommendations sit at Level 2 differs by Benchmark, so the profile tags in the Benchmark document itself are what a team reads, not a general rule of thumb. ## Applying it to a Linux server fleet 1. **Inventory** the fleet by distribution and version, and pick the matching Benchmark for each. 2. **Adopt Level 1** (server profile) as the organization's default hardening standard. 3. **Identify high-risk roles** - internet-facing hosts, systems holding sensitive data - and evaluate Level 2 for them. 4. **Test** Level 2 recommendations against each application before rollout. 5. **Record exceptions**: any recommendation not applied gets a documented reason and approval, so the standard remains honest. 6. **Re-baseline** when CIS publishes a new Benchmark version or the fleet moves to a new release. ## What the fleet standard records The adopted Benchmark becomes the fleet's documented hardening standard. For each server role it records: - the Benchmark name and version, and the profile adopted; - the recommendations not applied, each with a reason and an approver; - any compensating measure for a skipped recommendation; - when the standard is next reviewed, for example at a new Benchmark release or an OS upgrade. This is what lets an engineer, months later, tell a deliberate exception from an oversight, and it is what an assessor asks for first. ## Common mistakes - **Applying Level 2 everywhere untested**, then disabling hardening wholesale after an outage. - **Using one Benchmark for every distribution**, so recommendations point at paths or services that do not exist. - **Treating "CIS hardened" as a certification.** A Benchmark is a configuration reference; conformance is something you measure, not a credential CIS grants to the organization. - **Ignoring version drift**: a Benchmark for an older release is a poor standard for its successor. A strong answer defines the Benchmark as a consensus-based, per-product configuration standard, explains that Level 1 is the practical baseline while Level 2 trades functionality for depth, and describes a tested, documented rollout across the fleet.

  • Why not apply every Level 2 recommendation to every server?
    Level 2 is intended for environments where security is paramount and can reduce functionality or performance. Applied untested across a fleet it risks outages, and teams often respond by rolling hardening back entirely. Evaluate it per role and test it first.
  • How does a CIS Benchmark relate to NIST SP 800-53 control CM-6?
    CM-6 requires configuration settings drawn from organization-defined common secure configurations, and it names hardening guides and checklists as examples. A CIS Benchmark can be the common secure configuration an organization chooses.

saying these in an interview costs you the question

  • Thinks a CIS Benchmark scores a company against its peers
  • Applies Level 2 across the whole fleet without testing
  • Uses one Linux Benchmark for every distribution and version
  • Believes Level 1 is weaker than vendor defaults
  • Treats a Benchmark as a certificate CIS awards to organizations