CIS Benchmarks March 2025 Update
![]()
The following CIS Benchmarks® and CIS Build Kit have been updated or recently released. We've highlighted the major updates below. Each Benchmark and Build Kit includes a full changelog that references all changes.
CIS Benchmarks Updated Last Month
- CIS Apache Tomcat 10.1 Benchmark v1.1.0
- CIS Oracle Cloud Infrastructure Foundations Benchmark v3.0.0
- CIS SUSE Linux Enterprise 15 Benchmark v2.0.1
CIS Apache Tomcat 10.1 Benchmark v1.1.0
This Benchmark includes support for the latest version of Tomcat 10.1. All automated recommendations have been reviewed, tested, and validated to support Tomcat 10.1.
This Benchmark exemplifies the great things a community of users, vendors, and subject matter experts can accomplish through consensus collaboration. The CIS community thanks the entire consensus team. Special recognition goes to Matt Reagan, Tony Wilwerding, Joern Krueger, and James Scott.
Download the CIS Apache Tomcat Benchmark in PDF.
CIS SecureSuite® Members can visit CIS WorkBench here to download other formats and related resources.
Some items of note for this update:
- Added three new recommendations
- Removed steps for OCI IAM without Identity Domains
- Updated multiple audit CLI steps
A huge thank you to Josh Hammer for the immense amount of time he put in on this update!
Download the CIS Oracle Cloud Infrastructure Benchmark in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
A huge thank you to the CIS Linux Community for making this Benchmark happen.
Download the CIS SUSE Linux Enterprise Server Benchmark in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
All automated recommendations have been reviewed, tested, and validated to support Tomcat 11.
This Benchmark exemplifies the great things a community of users, vendors, and subject matter experts can accomplish through consensus collaboration. The CIS community thanks the entire consensus team. Special recognition goes to Matt Reagan, Tony Wilwerding, Joern Krueger, and James Scott.
Download the CIS Apache Tomcat Benchmark in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
This Build Kit supports all profiles available in the Benchmark and will remediate the target accordingly. In testing against a default SUSE Linux Enterprise 15 sp6 installation for the Level 2 Server profile, the Build Kit remediates more than 120 default settings that do not comply with the Benchmark guidance. A follow-up scan by CIS-CAT® Pro returns a PASS result over 93%.
Some items of note for this release:
- Several new scripts added to support updated recommendations
- Existing scripts updated for better execution
Download the CIS SUSE Linux Enterprise Server Benchmark in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
Get involved by helping us develop content, review recommendations, and test CIS Benchmarks. Join a community today!
If you're interested, please reach out to us at [email protected]. You can also learn more on the CIS Benchmarks Community page.As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.