CIS Benchmarks Monthly Update October 2025
![]()
The following CIS Benchmarks® and CIS Build Kits have been updated or recently released. We've highlighted the major updates below. Each Benchmark and Build Kit includes a full changelog that references all changes.
CIS Benchmarks Updated Last Month
- CIS Google Android Benchmark v1.6.0
 - CIS Microsoft Windows Server 2016 Benchmark v4.0.0
 - CIS Oracle MySQL 8.0 Enterprise Edition Benchmark v1.5.0
 
CIS Google Android Benchmark v1.6.0
We are excited to announce the updated CIS Google Android Benchmark v1.6.0. Major milestones for this release:
- Updated guidance to mirror the CIS Apple iOS Benchmark
 - Added recommendations based on community input
 
A huge thanks to the CIS Google Android Community for making this happen and a special thanks to Randie Bejar. Without her, this version of the Benchmark would not be possible.
Download the CIS Google Android Benchmark v1.6.0 in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
CIS Microsoft Windows Server 2016 Benchmark v4.0.0
We are excited to announce the publication of the updated CIS Microsoft Windows Server 2016 Benchmark v4.0.0. Our team has devoted significant time and effort to enhance the content of this Benchmark, ensuring it remains relevant and valuable to members. Here's a quick overview of the key improvements we've made in this update:
- Added 13 new security settings
 - Updated 8 settings
 - Renamed 4 settings
 - Moved 1 setting
 - Moved, added, and removed sections due to updated ADMX templates
 
A change log detailing the modifications made is included in the Word Doc and PDF versions of the Benchmark. A huge thank you to the CIS Windows Community and Windows Team for making this Benchmark happen. Special thanks to Haemish Edgerton and Aaron Margosis.
Download the CIS Microsoft Windows Server 2016 Benchmark v4.0.0 in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
CIS Oracle MySQL 8.0 Enterprise Edition Benchmark v1.5.0
We are excited to announce the publication of the updated CIS Oracle MySQL 8.0 Enterprise Edition Benchmark v1.5.0. Here are some highlights of the work that was done:
- Corrected typos and other errors to address 11 tickets
 - Backported a recommendation for FIPS 140-2 Open_SSL Cryptography
 - Backported changes for a recommendation requiring passwords for all MySQL accounts
 
A change log detailing the modifications made is included in the Doc and PDF versions of the Benchmark. A huge thank you to the CIS Oracle MySQL Benchmark Community for making this Benchmark happen. Special thanks to Mike Frank and Oracle.
Download the CIS Oracle MySQL 8.0 Enterprise Edition Benchmark v1.5.0 in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
We are pleased to announce the release of CIS FortiGate 7.4.x Benchmark v1.0.0. A lot of work went into the drafting of this Benchmark. It could not have happened without the assistance of the Fortinet community. 
Special thanks to Eric Leong, Tim Smith, and Peter Tomis.
Download the CIS FortiGate 7.4.x Benchmark v1.0.0 in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
We are excited to announce the release of the CIS Sophos Firewall v21 Benchmark v1.0.0. A lot of effort and coordination went into the creation of this Benchmark. Without the aid of the Sophos community this would not have been possible. Special thanks to Jayesh Panicker, Priyanka Yadav and Bill Prout for providing the expertise and building this benchmark.
Download the CIS Sophos Firewall v21 Benchmark v1.0.0 in PDF.
CIS SecureSuite Members can visit CIS WorkBench here to download other formats and related resources.
CIS Build Kits Created Last Month
Get involved by helping us develop content, review recommendations, and test CIS Benchmarks. Join a community today!
We're looking for contributors for the following technologies:
If you're interested, please reach out to us at [email protected]. You can also learn more on the CIS Benchmarks Community page.
CIS Benchmarks Which Will No Longer Be Active Without Community Volunteers
Due to a lack of Subject Matter Expert (SME) support CIS plans on archive all versions of the CIS Zoom Benchmarks, the CIS Check Point Firewall Benchmarks, and the CIS Bottlerocket Benchmarks on October 10, 2025. This can be prevented with renewed SME support! If you are an SME in this area and can assist, please contact the CIS Benchmark Development team at [email protected] ASAP.
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.
