Azure CIS benchmarks policy update timeline inquiry

What is the policy roadmap for updating Azure CIS benchmarks?

In AWS, we have versions v1.2.0 and v1.5.0, while its latest CIS version is v2.0.0. In Azure, we have v1.3.0 in CloudQuery, and its CIS latest version is v2.0.0.

Considering that CIS v2.0.0 is quite recent, I find it acceptable for AWS with v1.5.0. However, I’m interested in when we can expect policies for Azure CIS v1.5.0. :star_struck:

Hey @calm-walrus, thanks for the feedback! We’re working on our policies and have updates to CIS on our roadmap.

We’ve got quite a big yet exciting work planned for our policies and visualizations. That includes recent work on AWS Foundational Security Best Practices (over 200 controls): AWS FSBP Policies Blog and a soon-to-be-announced Kubernetes policy update.

Our plans are to skip 1.5.0 and build 2.0.0 for Azure. Would that meet your desires/requirements?

I’m happy to chat and share more about our roadmap and plans.

Thanks for the updates. I am fine for both v1.5.0 or v2.0.0. Of course, we can go directly with v2.0.0 if it is available.

Could I ask when it could be available? A month, quarter, or year plan?

Yes! I can’t promise official dates, but the current forecast is within a quarter given the team’s current priorities.

Does that meet your timeline?

All fine to me, thanks for the updates.

@stunning-dodo, I have a similar question regarding Azure compliance benchmarks. Is the “Microsoft Cloud Security Benchmark” already available?

Also, for the Azure CIS 1.3 that is already available, can the Azure free plugin be used for that?

@dynamic-starling - We don’t have the Microsoft Cloud Security Benchmark available. I’d be happy to consider adding it to our roadmap - would you be open to a conversation about it?

To answer your other question, yes - you can currently use the Azure free plugin for the CIS 1.3 that’s available. Are you looking at the Azure CIS policy here: Azure CIS Policy?

Thanks for clarifying.