CIS Standards

Tripwire CIS compliance—IT security based on industry best practices

With the rise of security threats, increased regulation and compliance issues, the CIS benchmarks have become a cornerstone for good system security. Many organizations rely on the Center for Internet Security (CIS) benchmarks for ensuring reliable security controls within the data center.


Tripwire makes continuous compliance with CIS benchmarks easy and straightforward-providing up-front assessment and ongoing analysis to ensure your configurations remain in conformance with best practices.

Tripwire delivers a comprehensive solution by:

  • Covering a variety of data center components with 27 of the CIS benchmarks included in its default configuration,
  • Testing configuration compliance against a benchmark, framework or regulation on a schedule or in near real-time to detect out-of-compliance configurations.
  • Arranging configuration tests, such as benchmark settings, into policies, and providing the ability to create customized policies.
  • Importing pre-defined configuration policies.
  • Reporting on compliance with configuration policies, as well as providing automated remediation that help bring the non-compliant systems into compliance.

Tripwire is a Category 1 Member of the CIS, and because Tripwire’s products meet the configuration prescription of the benchmarks, Tripwire has been awarded CIS Security Software Certification. Tripwire’s clients receive the additional benefit of Tripwire’s CIS Policies, which have been examined by CIS and meet the requirements of the CIS benchmark program. CIS-certified Tripwire products are listed on the CIS Web site at: https://benchmarks.cisecurity.org/en-us/?route=membership.roster.


CIS Resources

    • Infosecurity Europe 2012 Wrap Up
      Infosec expert and ‘cynic’ Javvad Malik summarizes the most important aspects of Infosecurity Europe 2012. Some of the top trends and key takeaways: risk management and the rising role of the CISO....
    • Communicating the value of Information Security – Part 3
      In part 2 of this series, I talked about getting to know the "language" of your particular business. This week, I want to talk about how to leverage Enterprise Architects, if they are available. They can be...
    • The Growing Pains of the New CISO
      Recently we had an opportunity to interview Phil Cracknell (@PCracknell on Twitter) during Infosecurity Europe. Infosec expert and ‘cynic’ Javvad Malik asks Mr. Cracknell, Global Security and...

To read more blog posts, visit the State of Security Blog.

To browse more, visit the company news section.

Resource Library

Resource Library

Read, watch or listen to valuable information about Tripwire solutions, customer success stories, IT security and compliance best practices, and more.

Resource Library