CIS Download Files
EDUCAUSE has established a license for redistribution of the Security Configuration Benchmarks and Scoring Tools developed by the members of The Center for Internet Security (CIS). The license enables all EDUCAUSE Institutional Members to download the Benchmarks and Scoring Tools from this web site, and distribute them in accordance with the terms of use below, under the heading "EDUCAUSE INSTITUTIONAL MEMBER TERMS OF USE NOTIFICATION".
The license provides several benefits to EDUCAUSE Institutional Members:
The right to redistribute CIS Benchmarks and Scoring Tools on all systems owned by the college or university at no cost to the college or university.
The right to redistribute CIS Benchmarks and Scoring Tools to college or university students, faculty and employees for use on computers owned by the students, faculty and employees. Redistribution to students, faculty and employees is permitted by any electronic means so long as the college or university (a) requires that the students and staff electronically accept the CIS Terms of Use, (b) authenticate the identity of each student, faculty member, or employee; and (c) authenticate the integrity of the files to be downloaded.
The opportunity for faculty, students and employees of EDUCAUSE member colleges and universities to voluntarily participate in the CIS consensus process, thereby ensuring that the benchmarks and scoring Tools meet the unique needs of EDUCAUSE member colleges and universities, and their students, faculty and staff.
The Center for Internet Security (CIS) is a not-for-profit membership organization.
The
members
of CIS are an international group of security professionals from public and private organizations who are collaborating to develop consensus security configuration Benchmarks for the most widely-used operating systems, software applications, and network devices.
The Benchmarks are developed and kept up to date via a consensus process involving thousands of security specialists from end-user and consulting organizations worldwide.
CIS Scoring Tools provide a quick and easy way to evaluate the level of a system's security by comparing its current configuration to the consensus Benchmarks. Scoring Tool reports guide administrators and users in securing both new installations and production systems, and can be used to monitor systems' conformity with the Benchmark configurations.
Go To
CIS PRIVACY POLICY
First Name:
Last Name:
Organization:
Email:
Select Benchmark
Package(s):
Windows XP Professional
Win 2000 Professional (Level-2)
Win 2000 Server (Level-2)
Win 2000 (Level-1)
Win NT (Level-1)
Windows Server 2003
Apache Level 1&2
Solaris (Level-1) (All Versions)
Oracle Level 1&2
Cisco IOS Router/PIX
(Level-1/Level-2)
FreeBSD Level-1
HP-UX Level-1
OS X Level-1
Linux Level-1
AIX Level-1
Wireless Networks
Exchange Server
SQL Server 2000
BIND
Select Download:
Automated Scanning Tool for the SANS/FBI "Top 20" List
Patchwork Utility for Windows NT
EDUCAUSE INSTITUTIONAL MEMBER TERMS OF USE NOTIFICATION
I. Background
The Center for Internet Security ("
CIS
") provides benchmarks, scoring tools, software, data, information, suggestions, ideas, and other services and materials from the CIS website or elsewhere ("
Products
") as a public service to Internet users worldwide. Recommendations contained in the Products ("
Recommendations
") result from a consensus-building process that involves many security experts and are generally generic in nature. The Recommendations are intended to provide helpful information to organizations attempting to evaluate or improve the security of their networks, systems, and devices. Proper use of the Recommendations requires careful analysis and adaptation to specific user requirements. The Recommendations are not in any way intended to be a "quick fix" for anyone's information security needs.
II. Grant of Limited Rights.
CIS hereby grants to each Educause Institutional Member the following rights, but only so long as the user complies with all of the terms of these Educause Institutional Member Terms of Use:
To use and distribute, within the confines of the Educational Institutional Member's organization, the CIS Benchmarks and Scoring Tools, plus associated documentation ("
Licensed Products
"), that are available at the CIS website via the secure portal on the Educause website at
http://www.educause.edu/CISDownloadFiles/2634
, and
To distribute the Licensed Products to the Educational Institutional Member's students, faculty, and employees for use on the students', faculty's, and employees' personally owned computers in connection with use of the Educational Institutional Member's computer networks and systems by either: (1) directing the students or employees to the CIS website,
www.cisecurity.org
; or (2) through electronic distribution, provided that the Educause Institutional Member: (a) require that the students, faculty members, or employees review and agree to the standard CIS Terms of Use, a current version of which is available here; (b) authenticate the identity of each student, faculty member, or employee; and (c) authenticate the integrity of the Benchmark and Scoring Tool files..
III. Retention of Intellectual Property Rights; Limitations on Distribution.
The Licensed Products are protected by copyright and other intellectual property laws and by international treaties. We acknowledge and agree that: (A) we are not acquiring any ownership or proprietary right, title, or interest in or to the Licensed Products, or the copyrights, trademarks, or other rights related thereto and (B) that full title and all ownership rights to the Licensed Products will remain the exclusive property of CIS or CIS Parties. CIS reserves all rights not expressly granted to users in the preceding section entitled "Grant of limited rights."
I
V. Limitations on Use and Distribution.
A. Receipt of the Licensed Products does not permit:
Selling, licensing, or leasing the Licensed Products, or exploiting them for any commercial purpose;
Distribution of the Licensed Products outside the Educause Institutional Member's organization by any means, including, but not limited to, the Internet or other electronic distribution, except that the Licensed Products may be distributed to individual students, faculty, and employees of Educause Institutional Members for use on their personal computers in accordance with Section II. B. of these Terms of Use. The Licensed Products may be distributed freely within the Educause Institutional Member's organization, provided this Terms of Use language in its entirety is included. Distribution to any entities outside the confines of the Educause Institutional Member organization is prohibited
Posting the Licensed Products or associated documentation on any internal or external web site, except for the purpose of internal distribution within the Educause Member's organization.
V. No Representations, Warranties, or Covenants.
CIS makes no representations, warranties, or covenants whatsoever as to (A) the positive or negative effect of the Licensed Products on the operation or the security of any particular network, computer system, network device, software, hardware, or any component of any of the foregoing or (B) the accuracy, reliability, timeliness, or completeness of the Licensed Products. CIS is providing the Licensed Products "as is" and "as available" without representations, warranties, or covenants of any kind.
VI. Educause Institutional Member User Agreements.
By using the Licensed Products or following the Recommendations contained within the Licensed Products ("
Recommendations
"), the Educause Institutional Member on behalf of itself and members of its organization ("
We
") agree and acknowledge that:
No network, system, device, hardware, software, or component can be made fully secure;
We are using the Licensed Products and/or the Recommendations solely at our own risk;
We are not compensating CIS to assume any liabilities associated with our use of the Licensed Products and/or the Recommendations, even risks that result from CIS's negligence or failure to perform;
We have the sole responsibility to evaluate the risks and benefits of the Licensed Products and/or Recommendations to us and to adapt the Licensed Products and/or the Recommendations to our particular circumstances and requirements;
CIS has no responsibility to make any corrections, updates, upgrades, or bug fixes; or to notify us of the need for any such corrections, updates, upgrades, or bug fixes; and
To the extent permitted by law, CIS does not have nor will it have any liability to us whatsoever (whether based in contract, tort, strict liability or otherwise) for any direct, indirect, incidental, consequential, or special damages (including without limitation loss of profits, loss of sales, loss of or damage to reputation, loss of customers, loss of software, data, information or emails, loss of privacy, loss of use of any computer or other equipment, business interruption, wasted management or other staff resources or claims of any kind against us from third parties) arising out of or in any way connected with our use of or our inability to use any of the Licensed Products and/or Recommendations (even if CIS has been advised of the possibility of such damages), including without limitation any liability associated with infringement of intellectual property, defects, bugs, errors, omissions, viruses, worms, backdoors, Trojan horses or other harmful items.
We agree that we will not (a) decompile, disassemble, reverse engineer, or otherwise attempt to derive the source code for any software Product that is not already in the form of source code; (b) except as provided in II.B. above, distribute, redistribute, encumber, sell, rent, lease, lend, sublicense, or otherwise transfer or exploit rights to any Product or any component of a Product; (c) post any Product or any component of a Product on any website, bulletin board, ftp server, newsgroup, or other similar mechanism or device, without regard to whether such mechanism or device is internal or external, (d) remove or alter trademark, logo, copyright or other proprietary notices, legends, symbols or labels in any Product or any component of a Product; (e) remove these Agreed Terms of Use from, or alter these Agreed Terms of Use as they appear in, any Product or any component of a Product; (f) use any Product or any component of a Product with any derivative works based directly on a Product or any component of a Product; (g) use any Product or any component of a Product with other products or applications that are directly and specifically dependent on such Product or any component for any part of their functionality, or (h) represent or claim a particular level of compliance with a CIS Benchmark, scoring tool or other Product. We will not facilitate or otherwise aid other individuals or entities in any of the activities listed in this paragraph.
If any of these Educational Institutional Terms of Use shall be determined to be unlawful, void, or for any reason unenforceable, then such terms shall be deemed severable and shall not affect the validity and enforceability of any remaining provisions.
We acknowledge and agree that the foregoing grant is subject to these Educational Institutional Member Terms of Use and that they be modified or terminated by CIS at any time.
WE ACKNOWLEDGE THAT WE HAVE READ THESE AGREED TERMS OF USE IN THEIR ENTIRETY, UNDERSTAND THEM, AND WE AGREE TO BE BOUND BY THEM IN ALL RESPECTS.
I ACCEPT
I DO NOT ACCEPT
Privacy Policy
© 2005, the Center for Internet Security.