CIS Benchmark integration (Level 1 and Level 2)
Customers already using CIS Benchmarks (Level 1 and Level 2) via other security tools want to see those standards reflected in OCC. Currently OCC supports frameworks like Cyber Essentials, ISO 27001, and SOC 2, but does not map to CIS Benchmarks. Customers running CIS Level 1 hardening against Microsoft environments need OCC to either import CIS results or natively support CIS controls so everything is in one place.
Proposed Solution:
1. Add CIS Benchmark Level 1 and Level 2 as supported standards in the Standards module.
2. Map CIS controls to existing OCC controls where overlap exists (e.g. CIS Level 1 MFA requirements → existing MFA controls under Cyber Essentials / ISO 27001).
3. Support importing CIS scan results from third-party tools (e.g. CIS-CAT, Microsoft Secure Score) to auto-populate detection and compliance status.
4. Include CIS controls in the cross-mapping view alongside other frameworks.
Acceptance Criteria:
1. CIS Level 1 and Level 2 are available as standards in the Standards module.
2. CIS controls are cross-mapped to overlapping controls in other frameworks.
3. Third-party CIS scan results can be imported.
4. CIS controls appear in the cross-mapping view.
5. Detections from CIS scans create tasks and update compliance posture.
Log in to comment and vote
No comments yet
Be the first to share your thoughts.