Sophos Cloud Optix has now been certified by the Center for Internet Security (CIS) to accurately assess AWS, Azure and GCP environments based on best practices for secure configuration.
Developed through a unique consensus-based process comprised of cybersecurity professionals and subject matter experts around the world, CIS Benchmarks are recommended as industry-accepted system hardening standards.
The standards are used by organizations in meeting compliance requirements for the Federal Information Security Management Act, PCI, the Health Insurance Portability Accountability Act and other security requirements.
- Amazon Web Services CIS Benchmarks
- Microsoft Azure CIS Benchmarks
- Google Cloud Platform CIS Benchmarks
By certifying Cloud Optix with CIS, Sophos has demonstrated commitment to actively solve the foundational problem of ensuring secure configurations are used throughout AWS, Azure and GCP environments.
Not all certifications are equal
CIS Benchmark Certification is awarded on two profile levels. The aim of the level 1 profile is to lower the attack surface of your organization while keeping machines usable and not hindering business functionality. The level 2 profile is considered “defense in depth” and is intended for environments where security is paramount.
Organizations should investigate whether a vendor offers the level of certification required for their industry, or compliance standard. Sophos has provided evidence that Cloud Optix can accurately report security recommendations in both level 1 and level 2 CIS Benchmark profiles.