Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conflicting statements on CIS benchmarks #97

Closed
Bojan023 opened this issue Mar 22, 2023 · 1 comment
Closed

Conflicting statements on CIS benchmarks #97

Bojan023 opened this issue Mar 22, 2023 · 1 comment

Comments

@Bojan023
Copy link
Contributor

Bojan023 commented Mar 22, 2023

Firstly, thank you for trying to condense so much information out there. I think this is a perfect starting point for self-hosters at home.

However, within a couple of minutes reading there are two conflicting statements regarding CIS benchmarks:

- The [Center for Internet Security (CIS)](https://www.cisecurity.org/) provides [benchmarks](https://www.cisecurity.org/cis-benchmarks/) that are exhaustive, industry trusted, step-by-step instructions for securing many flavors of Linux. Check their [About Us](https://www.cisecurity.org/about-us/) page for details. My recommendation is to go through this guide first and then CIS's guide. That way their recommendations will trump anything in this guide.

- I would also recommend you go through the [CIS Benchmarks](https://www.cisecurity.org/cis-benchmarks/) before you start with this guide.

The first recommends to follow this guide first and a CIS Benchmark afterwards. The latter one states the opposite. My suggestion is to stick to the first statement and thus alter the second statement.

imthenachoman added a commit that referenced this issue Mar 24, 2023
@imthenachoman
Copy link
Owner

Thanks. I tweaked the verbiage. Is that better?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants