CIS Security Benchmarks

This one is for the security conscious. If you are performing a hardening procedure for your OS, application/web server, other applications you might wonder how are other people doing that and where can you draw the line by saying that it is secure-enough. A great place of resource in such a case is the CIS Security specifically their resources download page. There you’ll find a form that allows you to choose and download a whole bunch of security benchmarks for various products like Apache HTTP server, Tomcat, Apple OSX, FreeBSD, Windows OSes, Firefox, MySQL, Oracle and various others. When presented with a list make sure to download a copy that’s relevant to the version of the product you’re using. There are archives for some products which include older versions that are less popular now. Newer documents have a very nice layout that include the following