CIS Benchmark

CIS Benchmark coverage

How LockList's checks map to the CIS Benchmarks: the Microsoft 365 and Google Workspace Foundations Benchmarks below, the CIS GitHub, AWS, and Azure Foundations Benchmarks (referenced on every finding), and the CIS Critical Security Controls v8 for NinjaOne endpoint checks.

Hardening guidance, not certification. CIS Benchmarks define recommended security configurations. LockList evidences whether key hardening recommendations are in place. Confirm applicability with your security team or auditor.

Microsoft 365 Foundations

CIS sectionWhat LockList assesses
1.1MFA for adminsConditional Access policies requiring MFA for admin roles; Security Defaults state as a fallback baseline.
1.2MFA for all usersConditional Access coverage for all users; MFA registration percentage and available authentication methods.
1.3Legacy authentication blockedConditional Access policies blocking legacy authentication protocols (Basic Auth, SMTP AUTH, etc.).
2.1Global admins minimisedCount of accounts holding Global Administrator and other high privilege directory roles.
2.2Privileged Identity ManagementPIM (just in time activation) usage for eligible role assignments vs. permanently active assignments.
3.1Audit logs enabledSign in log and directory audit log accessibility; unified audit log status.
4.1SharePoint external sharingTenant level SharePoint and OneDrive external sharing posture (Anyone / Existing guests / New & existing / Disabled).
4.2External email forwardingMailbox level auto forwarding rules sending mail to external domains.
5.1App registrations reviewedApp registrations holding high risk Microsoft Graph permissions (Directory.ReadWrite.All, Mail.ReadWrite, etc.).
6.1Security Defaults or Conditional AccessBaseline protection posture, whether Security Defaults are enabled or replaced by equivalent Conditional Access policies.

Google Workspace

CIS sectionWhat LockList assesses
1.12-Step Verification enforcedOrg wide 2-Step Verification enforcement policy and admin account enrollment status.
1.22SV coveragePercentage of users with 2-Step Verification registered across the organisation.
2.1Super admin countNumber of accounts with Super Admin privileges, flagged when count exceeds best practice limits.
2.2Admin role assignmentsReview of delegated admin roles and their assigned users.
3.1Audit log accessibilityLogin audit log and admin audit log accessibility in the Admin console.
4.1Dormant account reviewSuspended and dormant accounts that may represent stale access.
4.2Domain verificationDomain verification posture for all domains associated with the organisation.

GitHub

The GitHub connector assesses organisation level security controls mapped to the CIS GitHub Benchmark.

CIS sectionWhat the GitHub connector assesses
1.12FA enforcementOrg wide 2FA requirement enforced for all members.
1.2SAML SSOSAML single sign on configuration and enforcement for the organisation.
2.1Branch protectionDefault branch protection rules, required reviews, required status checks, and force push restrictions.
2.2Secret scanning & push protectionSecret scanning enablement and push protection across repositories in the organisation.
3.1Admin / member reviewOwner role inventory and outside collaborator access review.
3.2Deploy keysRepository deploy key inventory, flagging keys with write access or keys that appear stale.

NinjaOne — CIS Critical Security Controls v8

The NinjaOne connector assesses RMM / endpoint posture mapped to the CIS Critical Security Controls v8, the cross platform safeguards that apply to managed devices.

CSC safeguardWhat the NinjaOne connector assesses
1.1Enterprise asset inventoryDevice inventory and RMM agent coverage across the organisation.
1.2Unauthorised / stale assetsStale and offline agents that may represent unmanaged or forgotten endpoints.
7.3 / 7.4Automated patch managementOS patch status across managed endpoints, flagging devices with missing or failed patches.
10.1 / 10.2Malware defensesAntivirus deployment coverage and health on managed devices.
13.1Security event alertingOpen alert review across the device fleet.
8.2Audit log collectionActivity log accessibility for actions taken in the RMM console.

Every finding in your LockList Report carries its CIS section alongside SOC 2, ISO 27001, HIPAA, HITRUST CSF, and CMMC 2.0 mappings. Run a free assessment →