Policy Rules

CIS Microsoft Windows 11 Stand-alone Benchmark: 484 Checks

CIS Benchmark checks for stand-alone Microsoft Windows 11: account and local policies, system services, Windows Firewall, audit policy, and administrative templates.

The Center for Internet Security (CIS) is a nonprofit that publishes the CIS Benchmarks: consensus-developed secure configuration guides for operating systems, cloud platforms, and applications. Each benchmark enumerates numbered recommendations, most assigned a Level 1 (broadly safe hardening) or Level 2 (defense-in-depth, may reduce functionality) profile, together with the audit procedure and remediation for each. Wartiva maps a benchmark's recommendations onto policy rules so an endpoint's observed configuration can be assessed against the published baseline.

These checks apply to domain-joined and Intune-managed Windows 11 machines as well as stand-alone ones.

  • High 109
  • Medium 338
  • Low 37

1 Account Policies 11 checks

2.2 User Rights Assignment 38 checks

2.3 Security Options 53 checks

5 System Services 44 checks

9 Windows Defender Firewall with Advanced Security 14 checks

17 Advanced Audit Policy Configuration 27 checks

18.1 Control Panel 4 checks

18.4 MS Security Guide 6 checks

18.5 MSS (Legacy) 12 checks

18.6 Network 27 checks

18.7 Printers 18 checks

18.8 Start Menu and Taskbar 2 checks

18.9 System 57 checks

18.10 Windows Components 158 checks

18.11 Custom Settings 2 checks

19 Administrative Templates (User) 11 checks

See your environment the way it really exists

Wartiva is in early access. Request your spot and talk to the team that built the endpoint platform they always wished they had.

Request Early Access