Evan Romasco-Kelly
01/25/2024, 11:05 PMRachel Perkins
01/26/2024, 2:52 PMEvan Romasco-Kelly
01/26/2024, 5:35 PMRachel Perkins
01/26/2024, 6:36 PMEvan Romasco-Kelly
01/26/2024, 7:03 PMRachel Perkins
01/26/2024, 7:44 PMyml
files of policies in the /cis
subdirectoryEvan Romasco-Kelly
01/26/2024, 9:41 PMThese benchmarks are intended to gauge your organization’s security posture, rather than the current state of a given host. A host may fail a CIS Benchmark policy despite having the correct settings enabled if there is not a specific policy in place to enforce that setting.Part of the reason we’re interested in Fleet is that osquery can serve as a middle ground between full MDM and unmanaged BYOD. Curious if you know of queries folks have developed that are explicitly focused on current status of devices instead of status and MDM policies
Rachel Perkins
01/29/2024, 2:50 PMif there is not a specific policy in place to enforce that setting--I'm not quite sure which policies fail if it's not enforced through MDM. I personally written and tested a lot of the Windows 10 CIS policies without MDM and they all worked.
Rachel Perkins
01/29/2024, 2:56 PMEvan Romasco-Kelly
01/29/2024, 7:00 PMRachel Perkins
01/29/2024, 7:50 PM