Know how securely every endpoint is really configured
A firewall protects little if the systems behind it are insecurely configured. Security Configuration Management automatically assesses your endpoints against assigned hardening benchmarks like DISA STIG, CIS and ANSSI BP-028 – based on daily compliance scans by the isidaten agent, on Linux directly via OpenSCAP on the system. You see compliance score and coverage per asset and benchmark, manage justified exceptions and turn open findings directly into measures in your ISMS.
DISA STIGCIS BenchmarksANSSI BP-028BSI IT-GrundschutzPCI DSS
Features
Your benefits
1
Hardening by recognized benchmarks
Assess endpoints automatically against 28 bundled catalogs: DISA STIG, CIS, ANSSI BP-028, BSI-derived and PCI DSS profiles for Windows, RHEL, Ubuntu, Debian, SLES and macOS – instead of relying on assumptions, you know the actual level of hardening.
2
Score & coverage at a glance
Compliance score and coverage per asset and benchmark instantly show where you stand and which systems need attention.
3
Justified exceptions, not blind spots
Not every deviation is a flaw: with waiver management you document deliberate exceptions traceably and keep your score realistic.
4
Straight to action
Findings automatically become measures in your ISMS – the gap between detection and remediation closes by itself.
Capabilities
Everything this module can do
Assess against DISA STIG, CIS, ANSSI BP-028, BSI-derived and PCI DSS profiles
28 bundled benchmarks for Windows, RHEL, Ubuntu, Debian, SLES and macOS
Import your own benchmarks via XCCDF (e.g. licensed CIS content), mapped automatically
Daily compliance scans via isidaten agent
OpenSCAP integration: ComplianceAsCode profiles checked directly on the system
Compliance score per asset and benchmark
Coverage per asset and benchmark
Manage justified exceptions (waivers)
Auto-create measures in the ISMS
Experience Security Configuration Management live
Schedule a no-obligation demo – we will show you the module with your own use cases.