CIS Benchmark
CIS Benchmark coverage
How LockList's checks map to the CIS Benchmarks: the Microsoft 365 and Google Workspace Foundations Benchmarks below, the CIS GitHub, AWS, and Azure Foundations Benchmarks (referenced on every finding), and the CIS Critical Security Controls v8 for NinjaOne endpoint checks.
Hardening guidance, not certification. CIS Benchmarks define recommended security configurations. LockList evidences whether key hardening recommendations are in place. Confirm applicability with your security team or auditor.
Microsoft 365 Foundations
| CIS section | What LockList assesses |
|---|---|
| 1.1MFA for admins | Conditional Access policies requiring MFA for admin roles; Security Defaults state as a fallback baseline. |
| 1.2MFA for all users | Conditional Access coverage for all users; MFA registration percentage and available authentication methods. |
| 1.3Legacy authentication blocked | Conditional Access policies blocking legacy authentication protocols (Basic Auth, SMTP AUTH, etc.). |
| 2.1Global admins minimised | Count of accounts holding Global Administrator and other high privilege directory roles. |
| 2.2Privileged Identity Management | PIM (just in time activation) usage for eligible role assignments vs. permanently active assignments. |
| 3.1Audit logs enabled | Sign in log and directory audit log accessibility; unified audit log status. |
| 4.1SharePoint external sharing | Tenant level SharePoint and OneDrive external sharing posture (Anyone / Existing guests / New & existing / Disabled). |
| 4.2External email forwarding | Mailbox level auto forwarding rules sending mail to external domains. |
| 5.1App registrations reviewed | App registrations holding high risk Microsoft Graph permissions (Directory.ReadWrite.All, Mail.ReadWrite, etc.). |
| 6.1Security Defaults or Conditional Access | Baseline protection posture, whether Security Defaults are enabled or replaced by equivalent Conditional Access policies. |
Google Workspace
| CIS section | What LockList assesses |
|---|---|
| 1.12-Step Verification enforced | Org wide 2-Step Verification enforcement policy and admin account enrollment status. |
| 1.22SV coverage | Percentage of users with 2-Step Verification registered across the organisation. |
| 2.1Super admin count | Number of accounts with Super Admin privileges, flagged when count exceeds best practice limits. |
| 2.2Admin role assignments | Review of delegated admin roles and their assigned users. |
| 3.1Audit log accessibility | Login audit log and admin audit log accessibility in the Admin console. |
| 4.1Dormant account review | Suspended and dormant accounts that may represent stale access. |
| 4.2Domain verification | Domain verification posture for all domains associated with the organisation. |
GitHub
The GitHub connector assesses organisation level security controls mapped to the CIS GitHub Benchmark.
| CIS section | What the GitHub connector assesses |
|---|---|
| 1.12FA enforcement | Org wide 2FA requirement enforced for all members. |
| 1.2SAML SSO | SAML single sign on configuration and enforcement for the organisation. |
| 2.1Branch protection | Default branch protection rules, required reviews, required status checks, and force push restrictions. |
| 2.2Secret scanning & push protection | Secret scanning enablement and push protection across repositories in the organisation. |
| 3.1Admin / member review | Owner role inventory and outside collaborator access review. |
| 3.2Deploy keys | Repository deploy key inventory, flagging keys with write access or keys that appear stale. |
NinjaOne — CIS Critical Security Controls v8
The NinjaOne connector assesses RMM / endpoint posture mapped to the CIS Critical Security Controls v8, the cross platform safeguards that apply to managed devices.
| CSC safeguard | What the NinjaOne connector assesses |
|---|---|
| 1.1Enterprise asset inventory | Device inventory and RMM agent coverage across the organisation. |
| 1.2Unauthorised / stale assets | Stale and offline agents that may represent unmanaged or forgotten endpoints. |
| 7.3 / 7.4Automated patch management | OS patch status across managed endpoints, flagging devices with missing or failed patches. |
| 10.1 / 10.2Malware defenses | Antivirus deployment coverage and health on managed devices. |
| 13.1Security event alerting | Open alert review across the device fleet. |
| 8.2Audit log collection | Activity log accessibility for actions taken in the RMM console. |
Every finding in your LockList Report carries its CIS section alongside SOC 2, ISO 27001, HIPAA, HITRUST CSF, and CMMC 2.0 mappings. Run a free assessment →