Security benchmark tools available

Federal CIS download site

All federal agencies can now freely distribute and use the security configuration tools developed by the independent Center for Internet Security (CIS) and endorsed by federal security experts.

The General Services Administration's Federal Computer Incident Response Center this week announced an agreement signed with CIS for the redistribution licenses, paid for by FedCIRC, the National Security Agency, the Defense Department and other federal organizations.

The downloads are available through a site set up specifically for federal users at www.cisecurity.org/federalcisusers.

The tools offer a high-level security benchmark for commonly used operating systems, applications and appliances, and organizations can use the tools to check configurations. The tools are developed in collaboration with all of the center's members — including experts from government, industry and academia — but the center does not allow the companies that make the products to be members, said Franklin Reeder, chairman of the center.

In July, the center and several federal agencies announced the release of the latest tool, a benchmark for Microsoft Corp.'s Windows 2000 operating system. Tools are also available for other operating systems — including Windows NT, Sun Microsystems Inc.'s Solaris and Linux — and for Cisco Systems Inc.'s IOS routers.

The tools are available for free on the center's site, but unless an agency has signed up as a member, the tools cannot be redistributed throughout the organization for use on multiple systems. The FedCIRC agreement does not provide full membership privileges, but it does allow agency systems administrators to distribute the tools internally, according to a center official.

Membership also allows agencies to participate in the development of new tools and the updates to existing tools, as well as open access to discussions among members.

Several agencies are already full members, including the Justice Department and the Naval Surface Warfare Center.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.