From d3b6161e4a8f6d1f69de0e21295556e1efd426f2 Mon Sep 17 00:00:00 2001 From: Dan Piazza <220388267+DanPiazza-Netwrix@users.noreply.github.com> Date: Fri, 31 Jul 2026 16:41:19 -0400 Subject: [PATCH 01/14] docs(changetracker): document every compliance report template Adds a comprehensive catalog of all compliance report templates Change Tracker can execute, sourced from the changetracker-compliance-reports.zip package: PCI DSS, HIPAA, SOX, DISA STIG, NIST 800-53/800-171, ISO 27001, NERC CIP-007-6, and every CIS benchmark category. Each entry lists the exact template name, and CIS entries include the template's own revision version. Notes which templates ship bundled with the Hub Server installer versus which require the Compliance Benchmarks download from the Customer Portal. Folds the former Compliance Templates page into this one for a single source of truth. --- .../8.2/compliance/compliance.md | 729 +++++++++++++++++- .../8.2/compliance/compliancetemplates.md | 97 --- 2 files changed, 727 insertions(+), 99 deletions(-) delete mode 100644 docs/changetracker/8.2/compliance/compliancetemplates.md diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index 5772076d4a..0190192551 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -9,8 +9,6 @@ sidebar_position: 80 The **Compliance** tab provides an overview of compliance scores for all devices within any selected group. -![complianceoverviewtab](/images/changetracker/8.2/admin/tabs/complianceoverviewtab.webp) - The screen shows the previous 7 compliance report results to track any drift against your selected hardened build standard and whether scores are improving or worsening. @@ -36,3 +34,730 @@ Results** button becomes available. This will run a compare of the two reports, useful for seeing what has caused a score to drop, or to establish what the difference is in configuration between two devices. + +## Compliance report templates + +Netwrix Change Tracker scores devices against a hardened build standard using compliance report +templates. + +:::info +Only Center for Internet Security (CIS) benchmark reports ship bundled with the Hub Server +installer and are ready to select when you create a compliance report. Every other report on this +page — PCI DSS, HIPAA, SOX, DISA STIG, NIST, ISO 27001, and NERC CIP-007-6 — is available through +the Compliance Benchmarks download on the +[Customer Portal](https://customer.netwrix.com/my_products.html), which you import into Change +Tracker. + +The Customer Portal download also contains newer CIS benchmark templates ahead of the next Change +Tracker release, so you can adopt an updated benchmark without waiting for a product upgrade. +::: + +### Adding a downloaded template + +After you download a template from the Customer Portal, upload it to Change Tracker: + +1. Go to **Settings** > **Policy Templates**. +2. Click the **Actions** dropdown, then click **Upload Templates**. +3. Browse to the downloaded XML file and select it. +4. To overwrite an existing template with the same name, select the corresponding checkbox. +5. Click **Upload Template**. + +Review the following for additional information: + +- [How to Upload a Compliance/Tracking Template to Change Tracker](/docs/changetracker/8.2/kb/configuration-and-setup/upload-compliance-template.md) +- [Adding or Replacing Configuration and Compliance Report Templates](/docs/changetracker/8.2/kb/configuration-and-setup/add-replace-compliance-report-templates.md) +- [Applying a Compliance Template to a Group for Automated Reporting](/docs/changetracker/8.2/kb/configuration-and-setup/apply-compliance-template-to-group.md) + +## CIS + +Change Tracker's CIS compliance reports map directly to the prescriptive configuration +recommendations in the Center for Internet Security (CIS) +[Benchmarks List](https://www.cisecurity.org/cis-benchmarks). Each Change Tracker compliance report +is [CIS approved](https://www.cisecurity.org/partner/netwrix), and every one ships bundled with the +Hub Server installer. Only a benchmark published after your installed version — for example, a +benchmark for a newly released operating system — requires a manual download and upload; the next +Change Tracker release bundles it automatically. + +**CIS Version** is the template's own revision number. Netwrix tracks it internally and uses it to +determine whether a newer template should overwrite an existing one during import. It's independent +of the underlying CIS benchmark document version — for example, some template names include the +CIS-published specification version, such as the `(2.0.0)` in "NNT CIS Amazon Web Services +Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Version. + +### Cloud + + + + + + + + + + + +
PlatformTemplateCIS Version
Amazon Web ServicesNNT CIS Amazon Web Services Foundations Benchmark (2.0.0)1.0.0.2
Google Cloud PlatformNNT CIS Google Cloud Platform Foundation Benchmark (1.2.0)1.2.0
Microsoft 365NNT CIS Microsoft 365 Foundations Benchmark (1.4.0)1.4.0.1
Microsoft AzureNNT CIS Microsoft Azure Foundations Benchmark (1.3.0)1.0.0.1
+ +### Windows + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Operating SystemTemplateCIS Version
Windows Server 2022NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - Level 1 Domain Controller1.0.0
NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - Level 1 Member Server1.0.0
NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - NxGen Security - Level 1 Domain Controller1.0.0
NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - NxGen Security - Level 1 Member Server1.0.0
NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Domain Controller3.0.0
NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Member Server3.0.0
NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Domain Controller3.0.0
NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Member Server3.0.0
NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Domain Controller3.0.0
NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Member Server3.0.0
Windows 10 Enterprise 1511NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 11.1.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 1 + Bitlocker1.1.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 21.1.0.3
NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 2 + Bitlocker1.1.0.3
Windows 10 Enterprise 1607NNT CIS Microsoft Windows 10 Enterprise (Release 1607) Benchmark - Level 11.2.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1607) Benchmark - Level 1 + Bitlocker1.2.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1607) Benchmark - Level 21.2.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1607) Benchmark - Level 2 + Bitlocker1.2.0.2
Windows 10 Enterprise 1703NNT CIS Microsoft Windows 10 Enterprise (Release 1703 Benchmark - Level 11.3.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1703) Benchmark - Level 1 + BitLocker1.3.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1703) Benchmark - Level 21.3.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1703) Benchmark - Level 2 + BitLocker1.3.0.2
Windows 10 Enterprise 1709NNT CIS Microsoft Windows 10 Enterprise (Release 1709) Benchmark - BitLocker1.4.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1709) Benchmark - Level 11.4.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1709) Benchmark - Level 21.4.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1709) Benchmark - NxGen Security1.4.0.2
Windows 10 Enterprise 1803NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - BitLocker1.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - Level 11.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - Level 1 + BitLocker1.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - Level 1 + BitLocker + NxGen1.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - Level 1 + NxGen Security1.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - Level 21.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - Level 2 + BitLocker1.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - Level 2 + BitLocker + NxGen1.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - Level 2 + NxGen Security1.5.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1803) Benchmark - NxGen Security1.5.0.2
Windows 10 Enterprise 1809NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - BitLocker1.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 11.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 1 + BitLocker1.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 1 + BitLocker + NxGen1.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 1 + NxGen1.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 1 + NxGen Security1.6.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 21.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 2 + BitLocker1.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 2 + BitLocker + NxGen1.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 2 + NxGen1.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - Level 2 + NxGen Security1.6.0.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - NxGen1.6.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1809) Benchmark - NxGen Security1.6.0.2
Windows 10 Enterprise 1903NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - BitLocker1.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - Level 11.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - Level 1 + BitLocker1.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - Level 1 + BitLocker + NxGen1.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - Level 1 + NxGen1.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - Level 21.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - Level 2 + BitLocker1.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - Level 2 + BitLocker + NxGen1.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - Level 2 + NxGen1.7.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1903) Benchmark - NxGen1.7.1.2
Windows 10 Enterprise 1909NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - BitLocker1.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - Level 11.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - Level 1 + BitLocker1.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - Level 1 + BitLocker + NxGen1.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - Level 1 + NxGen1.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - Level 21.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - Level 2 + BitLocker1.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - Level 2 + BitLocker + NxGen1.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - Level 2 + NxGen1.8.1.2
NNT CIS Microsoft Windows 10 Enterprise (Release 1909) Benchmark - NxGen1.8.1.2
Windows 10 Enterprise 2004NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - BitLocker1.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - Level 11.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - Level 1 + BitLocker1.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - Level 1 + BitLocker + NxGen1.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - Level 1 + NxGen1.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - Level 21.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - Level 2 + BitLocker1.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - Level 2 + BitLocker + NxGen1.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - Level 2 + NxGen1.9.1.1
NNT CIS Microsoft Windows 10 Enterprise (Release 2004) Benchmark - NxGen1.9.1.1
Windows 10 Enterprise 20H2NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - BitLocker1.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - Level 11.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - Level 1 + BitLocker1.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - Level 1 + BitLocker + NxGen1.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - Level 1 + NxGen1.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - Level 21.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - Level 2 + BitLocker1.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - Level 2 + BitLocker + NxGen1.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - Level 2 + NxGen1.10.0
NNT CIS Microsoft Windows 10 Enterprise (Release 20H2) Benchmark - NxGen1.10.0
Windows 10 Enterprise 21H1NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - BitLocker1.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - Level 11.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - Level 1 + BitLocker1.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - Level 1 + BitLocker + NxGen1.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - Level 1 + NxGen1.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - Level 21.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - Level 2 + BitLocker1.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - Level 2 + BitLocker + NxGen1.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - Level 2 + NxGen1.11.0
NNT CIS Microsoft Windows 10 Enterprise (Release 21H1) Benchmark - NxGen1.11.0
Windows 10 StandaloneNNT CIS Microsoft Windows 10 Standalone Benchmark - Level 12.0.0
NNT CIS Microsoft Windows 10 Standalone Benchmark - Level 1 + BitLocker2.0.0
NNT CIS Microsoft Windows 10 Standalone Benchmark - Level 1 + BitLocker + NxGen2.0.0
NNT CIS Microsoft Windows 10 Standalone Benchmark - Level 22.0.0
NNT CIS Microsoft Windows 10 Standalone Benchmark - Level 2 + BitLocker2.0.0
NNT CIS Microsoft Windows 10 Standalone Benchmark - Level 2 + BitLocker + NxGen2.0.0
Windows 11 EnterpriseNNT CIS Microsoft Windows 11 Enterprise Benchmark - BitLocker5.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - Level 15.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - Level 1 + BitLocker5.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - Level 1 + BitLocker + NxGen1.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - Level 1 + NxGen1.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - Level 25.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - Level 2 + BitLocker5.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - Level 2 + BitLocker + NxGen1.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - Level 2 + NxGen1.0.0
NNT CIS Microsoft Windows 11 Enterprise Benchmark - NxGen1.0.0
Windows 7NNT CIS Microsoft Windows 7 Benchmark - BitLocker3.2.0.2
NNT CIS Microsoft Windows 7 Benchmark - Level 13.2.0.2
NNT CIS Microsoft Windows 7 Benchmark - Level 1 + BitLocker3.2.0.2
NNT CIS Microsoft Windows 7 Benchmark - Level 23.2.0.2
NNT CIS Microsoft Windows 7 Benchmark - Level 2 + BitLocker3.2.0.2
Windows 8.1 WorkstationNNT CIS Microsoft Windows 8.1 Workstation Benchmark - Level 12.3.0.2
NNT CIS Microsoft Windows 8.1 Workstation Benchmark - Level 1 + BitLocker2.3.0.2
NNT CIS Microsoft Windows 8.1 Workstation Benchmark - Level 22.3.0.2
NNT CIS Microsoft Windows 8.1 Workstation Benchmark - Level 2 + BitLocker2.3.0.2
Windows Server 2003NNT CIS Microsoft Windows Server 2003 Benchmark - Level 1 Member Server3.1.0.4
Windows Server 2008NNT CIS Microsoft Windows Server 2008 Benchmark - Level 1 Domain Controller3.1.0.2
NNT CIS Microsoft Windows Server 2008 Benchmark - Level 1 Member Server3.1.0.2
NNT CIS Microsoft Windows Server 2008 Benchmark - Level 2 Domain Controller3.1.0.2
NNT CIS Microsoft Windows Server 2008 Benchmark - Level 2 Member Server3.1.0.2
Windows Server 2008 R2NNT CIS Microsoft Windows Server 2008 R2 Benchmark - Level 1 Domain Controller3.2.0.2
NNT CIS Microsoft Windows Server 2008 R2 Benchmark - Level 1 Member Server3.2.0.2
NNT CIS Microsoft Windows Server 2008 R2 Benchmark - Level 2 Domain Controller3.2.0.2
NNT CIS Microsoft Windows Server 2008 R2 Benchmark - Level 2 Member Server3.2.0.2
Windows Server 2012NNT CIS Microsoft Windows Server 2012 Benchmark - Level 1 Domain Controller2.1.0.2
NNT CIS Microsoft Windows Server 2012 Benchmark - Level 1 Member Server2.1.0.2
NNT CIS Microsoft Windows Server 2012 Benchmark - Level 2 Domain Controller2.1.0.2
NNT CIS Microsoft Windows Server 2012 Benchmark - Level 2 Member Server2.1.0.2
Windows Server 2012 R2NNT CIS Microsoft Windows Server 2012 R2 Benchmark - Level 1 Domain Controller2.4.0
NNT CIS Microsoft Windows Server 2012 R2 Benchmark - Level 1 Member Server2.4.0
NNT CIS Microsoft Windows Server 2012 R2 Benchmark - Level 2 Domain Controller2.4.0
NNT CIS Microsoft Windows Server 2012 R2 Benchmark - Level 2 Member Server2.4.0
Windows Server 2016NNT CIS Microsoft Windows Server 2016 Benchmark - Level 1 Domain Controller3.0.0
NNT CIS Microsoft Windows Server 2016 Benchmark - Level 1 Member Server3.0.0
NNT CIS Microsoft Windows Server 2016 Benchmark - Level 2 Domain Controller3.0.0
NNT CIS Microsoft Windows Server 2016 Benchmark - Level 2 Member Server3.0.0
NNT CIS Microsoft Windows Server 2016 Benchmark - NxGen Security - Domain Controller3.0.0
NNT CIS Microsoft Windows Server 2016 Benchmark - NxGen Security - Member Server3.0.0
NNT CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark - Level 1 Domain Controller1.1.0.2
NNT CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark - Level 1 Member Server1.1.0.2
NNT CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark - Level 2 Domain Controller1.1.0.2
NNT CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark - Level 2 Member Server1.1.0.2
NNT CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark - NxGen Security1.1.0.2
NNT CIS Microsoft Windows Server 2016 STIG Benchmark - Level 1 Domain Controller1.0.0
NNT CIS Microsoft Windows Server 2016 STIG Benchmark - Level 1 Member Server1.0.0
NNT CIS Microsoft Windows Server 2016 STIG Benchmark - Level 2 Domain Controller1.0.0
NNT CIS Microsoft Windows Server 2016 STIG Benchmark - Level 2 Member Server1.0.0
NNT CIS Microsoft Windows Server 2016 STIG Benchmark - Level 3 - STIG Domain Controller1.0.0
NNT CIS Microsoft Windows Server 2016 STIG Benchmark - Level 3 - STIG Member Server1.0.0
NNT CIS Microsoft Windows Server 2016 STIG Benchmark - NxGen Security - Domain Controller1.0.0
NNT CIS Microsoft Windows Server 2016 STIG Benchmark - NxGen Security - Member Server1.0.0
Windows Server 2019NNT CIS Microsoft Windows Server 2019 Benchmark - Level 1 Domain Controller3.0.1
NNT CIS Microsoft Windows Server 2019 Benchmark - Level 1 Member Server3.0.1
NNT CIS Microsoft Windows Server 2019 Benchmark - Level 2 Domain Controller3.0.1
NNT CIS Microsoft Windows Server 2019 Benchmark - Level 2 Member Server3.0.1
NNT CIS Microsoft Windows Server 2019 Benchmark - NxGen Security - Domain Controller3.0.1
NNT CIS Microsoft Windows Server 2019 Benchmark - NxGen Security - Member Server3.0.1
Windows Server 2025NNT CIS Microsoft Windows Server 2025 Benchmark - Level 1 Domain Controller1.0.0
NNT CIS Microsoft Windows Server 2025 Benchmark - Level 1 Member Server1.0.0
NNT CIS Microsoft Windows Server 2025 Benchmark - Level 2 Domain Controller1.0.0
NNT CIS Microsoft Windows Server 2025 Benchmark - Level 2 Member Server1.0.0
NNT CIS Microsoft Windows Server 2025 Benchmark - NxGen Security - Domain Controller1.0.0
NNT CIS Microsoft Windows Server 2025 Benchmark - NxGen Security - Member Server1.0.0
Windows XPNNT CIS Microsoft Windows XP Benchmark3.1.0.4
+ +### Linux + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Operating SystemTemplateCIS Version
Amazon Linux 2NNT CIS Amazon Linux 2 Benchmark - Level 11.0.0
NNT CIS Amazon Linux 2 Benchmark - Level 21.0.0
Amazon Linux Server 2023NNT CIS Amazon Linux 2023 Server Benchmark - Level 11.0.0
NNT CIS Amazon Linux 2023 Server Benchmark - Level 21.0.0.1
CentOS Linux Server 6NNT CIS CentOS Linux 6 Server Benchmark - Level 12.0.2.2
NNT CIS CentOS Linux 6 Server Benchmark - Level 22.0.2.2
CentOS Linux Workstation 6NNT CIS CentOS Linux 6 Workstation Benchmark - Level 12.0.2.2
NNT CIS CentOS Linux 6 Workstation Benchmark - Level 22.0.2.2
CentOS Linux Server 7NNT CIS CentOS Linux 7 Server Benchmark - Level 12.2.0.2
NNT CIS CentOS Linux 7 Server Benchmark - Level 22.2.0.2
CentOS Linux Workstation 7NNT CIS CentOS Linux 7 Workstation Benchmark - Level 12.2.0.2
NNT CIS CentOS Linux 7 Workstation Benchmark - Level 22.2.0.2
CentOS Linux Server 8NNT CIS CentOS Linux 8 Server Benchmark - Level 11.0.0.4
NNT CIS CentOS Linux 8 Server Benchmark - Level 21.0.0.4
CentOS Linux Workstation 8NNT CIS CentOS Linux 8 Workstation Benchmark - Level 11.0.0.4
NNT CIS CentOS Linux 8 Workstation Benchmark - Level 21.0.0.4
Debian Linux Server 10NNT CIS Debian Linux 10 Server Benchmark - Level 11.0.0.2
NNT CIS Debian Linux 10 Server Benchmark - Level 21.0.0.2
Debian Linux Workstation 10NNT CIS Debian Linux 10 Workstation Benchmark - Level 11.0.0.2
NNT CIS Debian Linux 10 Workstation Benchmark - Level 21.0.0.2
Debian Linux 8NNT CIS Debian Linux 8 Benchmark - Level 11.0.0.3
NNT CIS Debian Linux 8 Benchmark - Level 21.0.0.3
Debian Linux Server 8NNT CIS Debian Linux 8 Server Benchmark - Level 12.0.1.2
NNT CIS Debian Linux 8 Server Benchmark - Level 22.0.1.2
Debian Linux Workstation 8NNT CIS Debian Linux 8 Workstation Benchmark - Level 12.0.1.2
NNT CIS Debian Linux 8 Workstation Benchmark - Level 22.0.1.2
Debian Linux Server 9NNT CIS Debian Linux 9 Server Benchmark - Level 11.0.1.2
NNT CIS Debian Linux 9 Server Benchmark - Level 21.0.1.2
Debian Linux Workstation 9NNT CIS Debian Linux 9 Workstation Benchmark - Level 11.0.1.2
NNT CIS Debian Linux 9 Workstation Benchmark - Level 21.0.1.2
Oracle Linux Server 6NNT CIS Oracle Linux 6 Server Benchmark - Level 11.0.0.2
NNT CIS Oracle Linux 6 Server Benchmark - Level 21.0.0.2
Oracle Linux Workstation 6NNT CIS Oracle Linux 6 Workstation Benchmark - Level 11.0.0.2
NNT CIS Oracle Linux 6 Workstation Benchmark - Level 21.0.0.2
Oracle Linux Server 7NNT CIS Oracle Linux 7 Server Benchmark - Level 12.0.0.2
NNT CIS Oracle Linux 7 Server Benchmark - Level 22.0.0.2
Oracle Linux Workstation 7NNT CIS Oracle Linux 7 Workstation Benchmark - Level 12.0.0.2
NNT CIS Oracle Linux 7 Workstation Benchmark - Level 22.0.0.2
Oracle Linux Server 8NNT CIS Oracle Linux 8 Server Benchmark - Level 13.0.0
NNT CIS Oracle Linux 8 Server Benchmark - Level 23.0.0
Oracle Linux Workstation 8NNT CIS Oracle Linux 8 Workstation Benchmark - Level 13.0.0
NNT CIS Oracle Linux 8 Workstation Benchmark - Level 23.0.0
Oracle Solaris 10NNT CIS Oracle Solaris 10 Benchmark - Level 15.1.0.5
NNT CIS Oracle Solaris 10 Benchmark - Level 25.1.0.5
Oracle Solaris 11NNT CIS Oracle Solaris 11 Benchmark - Level 11.1.0.5
NNT CIS Oracle Solaris 11 Benchmark - Level 21.1.0.5
Red Hat Enterprise Linux Server 10NNT CIS Red Hat Enterprise Linux 10 Server Benchmark - Level 11.0.1
NNT CIS Red Hat Enterprise Linux 10 Server Benchmark - Level 21.0.1
Red Hat Enterprise Linux Workstation 10NNT CIS Red Hat Enterprise Linux 10 Workstation Benchmark - Level 11.0.1
NNT CIS Red Hat Enterprise Linux 10 Workstation Benchmark - Level 21.0.1
Red Hat Enterprise Linux 5NNT CIS Red Hat Enterprise Linux 5 Benchmark - Level 12.2.0.2
NNT CIS Red Hat Enterprise Linux 5 Benchmark - Level 22.2.0.2
Red Hat Enterprise Linux Server 6NNT CIS Red Hat Enterprise Linux 6 Server Benchmark - Level 12.0.2.2
NNT CIS Red Hat Enterprise Linux 6 Server Benchmark - Level 22.0.2.2
Red Hat Enterprise Linux Workstation 6NNT CIS Red Hat Enterprise Linux 6 Workstation Benchmark - Level 12.0.2.2
NNT CIS Red Hat Enterprise Linux 6 Workstation Benchmark - Level 22.0.2.2
Red Hat Enterprise Linux Server 7NNT CIS Red Hat Enterprise Linux 7 Server Benchmark - Level 12.2.0.3
NNT CIS Red Hat Enterprise Linux 7 Server Benchmark - Level 22.2.0.3
Red Hat Enterprise Linux Workstation 7NNT CIS Red Hat Enterprise Linux 7 Workstation Benchmark - Level 12.2.0.3
NNT CIS Red Hat Enterprise Linux 7 Workstation Benchmark - Level 22.2.0.3
Red Hat Enterprise Linux Server 8NNT CIS Red Hat Enterprise Linux 8 Server Benchmark - Level 11.0.0.2
NNT CIS Red Hat Enterprise Linux 8 Server Benchmark - Level 21.0.0.2
Red Hat Enterprise Linux Workstation 8NNT CIS Red Hat Enterprise Linux 8 Workstation Benchmark - Level 11.0.0.2
NNT CIS Red Hat Enterprise Linux 8 Workstation Benchmark - Level 21.0.0.2
Red Hat Enterprise Linux Server 9NNT CIS Red Hat Enterprise Linux 9 Server Benchmark - Level 12.0.0
NNT CIS Red Hat Enterprise Linux 9 Server Benchmark - Level 22.0.0
Red Hat Enterprise Linux Workstation 9NNT CIS Red Hat Enterprise Linux 9 Workstation Benchmark - Level 12.0.0
NNT CIS Red Hat Enterprise Linux 9 Workstation Benchmark - Level 22.0.0
Rocky Linux Server 8NNT CIS Rocky Linux 8 Server Benchmark - Level 11.0.0
NNT CIS Rocky Linux 8 Server Benchmark - Level 21.0.0
Rocky Linux Workstation 8NNT CIS Rocky Linux 8 Workstation Benchmark - Level 11.0.0
NNT CIS Rocky Linux 8 Workstation Benchmark - Level 21.0.0
SUSE Linux Enterprise Server 12NNT CIS SUSE Linux Enterprise 12 Server Benchmark - Level 12.0.0.3
NNT CIS SUSE Linux Enterprise 12 Server Benchmark - Level 22.0.0.3
SUSE Linux Enterprise Workstation 12NNT CIS SUSE Linux Enterprise 12 Workstation Benchmark - Level 12.0.0.3
NNT CIS SUSE Linux Enterprise 12 Workstation Benchmark - Level 22.0.0.3
SUSE Linux Enterprise Server 15NNT CIS SUSE Linux Enterprise Linux 15 Server Benchmark - Level 12.0.1
NNT CIS SUSE Linux Enterprise Linux 15 Server Benchmark - Level 22.0.1
SUSE Linux Enterprise Workstation 15NNT CIS SUSE Linux Enterprise Linux 15 Workstation Benchmark - Level 12.0.1
NNT CIS SUSE Linux Enterprise Linux 15 Workstation Benchmark - Level 22.0.1
SUSE Linux Enterprise Server 11NNT CIS SUSE Linux Enterprise Server 11 Benchmark - Level 11.0.0.2
NNT CIS SUSE Linux Enterprise Server 11 Benchmark - Level 21.0.0.2
Ubuntu 12.04NNT CIS Ubuntu 12.04 - Level 11.0.0.2
NNT CIS Ubuntu 12.04 - Level 21.0.0.2
Ubuntu Linux LTS Server 14.04NNT CIS Ubuntu Linux 14.04 LTS Server Benchmark - Level 12.0.0.2
NNT CIS Ubuntu Linux 14.04 LTS Server Benchmark - Level 22.0.0.2
Ubuntu Linux LTS Workstation 14.04NNT CIS Ubuntu Linux 14.04 LTS Workstation Benchmark - Level 12.0.0.2
NNT CIS Ubuntu Linux 14.04 LTS Workstation Benchmark - Level 22.0.0.2
Ubuntu Linux LTS Server 16.04NNT CIS Ubuntu Linux 16.04 LTS Server Benchmark - Level 11.0.0.2
NNT CIS Ubuntu Linux 16.04 LTS Server Benchmark - Level 21.0.0.2
Ubuntu Linux LTS Workstation 16.04NNT CIS Ubuntu Linux 16.04 LTS Workstation Benchmark - Level 11.0.0.2
NNT CIS Ubuntu Linux 16.04 LTS Workstation Benchmark - Level 21.0.0.2
Ubuntu Linux LTS Server 18.04NNT CIS Ubuntu Linux 18.04 LTS Server Benchmark - Level 11.0.0.3
NNT CIS Ubuntu Linux 18.04 LTS Server Benchmark - Level 21.0.0.3
Ubuntu Linux LTS Workstation 18.04NNT CIS Ubuntu Linux 18.04 LTS Workstation Benchmark - Level 11.0.0.3
NNT CIS Ubuntu Linux 18.04 LTS Workstation Benchmark - Level 21.0.0.3
Ubuntu Linux LTS Server 20.04NNT CIS Ubuntu Linux 20.04 LTS Server Benchmark - Level 11.1.0
NNT CIS Ubuntu Linux 20.04 LTS Server Benchmark - Level 21.1.0
Ubuntu Linux LTS Workstation 20.04NNT CIS Ubuntu Linux 20.04 LTS Workstation Benchmark - Level 11.1.0
NNT CIS Ubuntu Linux 20.04 LTS Workstation Benchmark - Level 21.1.0
Ubuntu Linux LTS Server 22.04NNT CIS Ubuntu Linux 22.04 LTS Server Benchmark - Level 13.0.0
NNT CIS Ubuntu Linux 22.04 LTS Server Benchmark - Level 23.0.0
Ubuntu Linux LTS Workstation 22.04NNT CIS Ubuntu Linux 22.04 LTS Workstation Benchmark - Level 13.0.0
NNT CIS Ubuntu Linux 22.04 LTS Workstation Benchmark - Level 23.0.0
Ubuntu Linux LTS Server 24.04NNT CIS Ubuntu Linux 24.04 LTS Server Benchmark - Level 11.0.0
NNT CIS Ubuntu Linux 24.04 LTS Server Benchmark - Level 21.0.0
Ubuntu Linux LTS Workstation 24.04NNT CIS Ubuntu Linux 24.04 LTS Workstation Benchmark - Level 11.0.0
NNT CIS Ubuntu Linux 24.04 LTS Workstation Benchmark - Level 21.0.0
+ +### Databases + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
DatabaseTemplateCIS Version
Microsoft SQL Server 2008R2NNT CIS Microsoft SQL Server 2008R2 Database Engine Benchmark - Level 11.1.0.2
Microsoft SQL Server 2012NNT CIS Microsoft SQL Server 2012 Database Engine Benchmark - Level 11.0.0.2
Microsoft SQL Server 2014NNT CIS Microsoft SQL Server 2014 Database Engine Benchmark - Level 11.1.0.2
Microsoft SQL Server 2016NNT CIS Microsoft SQL Server 2016 Benchmark - Level 1 - AWS RDS1.4.0
NNT CIS Microsoft SQL Server 2016 Benchmark - Level 1 - Database Engine 1.4.0
NNT CIS Microsoft SQL Server 2016 Benchmark - Level 1 - Windows1.4.0
NNT CIS Microsoft SQL Server 2016 Benchmark - Level 2 - Database Engine1.4.0
Microsoft SQL Server 2017NNT CIS Microsoft SQL Server 2017 Benchmark - Level 1 - AWS RDS1.2.0
NNT CIS Microsoft SQL Server 2017 Benchmark - Level 1 - Database Engine 1.2.0
NNT CIS Microsoft SQL Server 2017 Benchmark - Level 1 - Windows1.2.0
Microsoft SQL Server 2019NNT CIS Microsoft SQL Server 2019 Benchmark - Level 1 - AWS RDS1.5.2
NNT CIS Microsoft SQL Server 2019 Benchmark - Level 1 - Database Engine1.5.2
NNT CIS Microsoft SQL Server 2019 Benchmark - Level 1 - Windows1.5.2
NNT CIS Microsoft SQL Server 2019 Benchmark - Level 2 - Database Engine1.5.2
Microsoft SQL Server 2022NNT CIS Microsoft SQL Server 2022 Benchmark - Level 1 - AWS RDS1.1.0
NNT CIS Microsoft SQL Server 2022 Benchmark - Level 1 - Database Engine1.1.0
NNT CIS Microsoft SQL Server 2022 Benchmark - Level 1 - Windows1.1.0
NNT CIS Microsoft SQL Server 2022 Benchmark - Level 2 - Database Engine1.1.0
Oracle Database 12cNNT CIS Oracle Database 12c Benchmark1.2.2.3
NNT CIS Oracle Database 12c Benchmark - Level 1 - Linux Host OS using Traditional Auditing3.0.0
NNT CIS Oracle Database 12c Benchmark - Level 1 - Linux Host OS using Unified Auditing3.0.0
NNT CIS Oracle Database 12c Benchmark - Level 1 - RDBMS using Traditional Auditing3.0.0
NNT CIS Oracle Database 12c Benchmark - Level 1 - RDBMS using Unified Auditing3.0.2
NNT CIS Oracle Database 12c Benchmark - Level 1 - Windows Server Host OS using Traditional Auditing3.0.0
NNT CIS Oracle Database 12c Benchmark - Level 1 - Windows Server Host OS using Unified Auditing3.0.0
NNT CIS Oracle Database 12c Benchmark - Linux1.2.0.2
NNT CIS Oracle Database 12c Benchmark - Windows1.2.0.2
Oracle Database 19cNNT CIS Oracle Database 19c Benchmark - Level 1 - Linux Host OS using Traditional Auditing1.1.0
NNT CIS Oracle Database 19c Benchmark - Level 1 - Linux Host OS using Unified Auditing1.1.0
NNT CIS Oracle Database 19c Benchmark - Level 1 - RDBMS using Traditional Auditing1.1.0
NNT CIS Oracle Database 19c Benchmark - Level 1 - RDBMS using Unified Auditing1.1.0
NNT CIS Oracle Database 19c Benchmark - Level 1 - Windows Server Host OS using Traditional Auditing1.1.0
NNT CIS Oracle Database 19c Benchmark - Level 1 - Windows Server Host OS using Unified Auditing1.1.0
+ +### Network Devices + + + + + + + + + + + + + + + + + + +
DeviceTemplateCIS Version
F5F5 Networks Compliance Report1.0.0
NNT CIS F5 Networks Benchmark - Level 11.0.0
NNT CIS F5 Networks Benchmark - Level 21.0.0
Fortigate 7.4.xNNT CIS Fortigate 7.4.x Benchmark - Level 11.0.1
NNT CIS Fortigate 7.4.x Benchmark - Level 21.0.1
Palo Alto Firewall 11NNT CIS Palo Alto Firewall 11 Benchmark - Level 11.1.0.1
NNT CIS Palo Alto Firewall 11 Benchmark - Level 21.1.0.1
Fortigate 7.0.xNNT Fortigate 7.0.x Benchmark - Level 11.3.0
NNT Fortigate 7.0.x Benchmark - Level 21.3.0
Juniper OSNNT Juniper OS - Level 12.1.0
NNT Juniper OS - Level 22.1.0
+ +### Cisco + + + + + + + + + + + + + + + + +
DeviceTemplateCIS Version
Cisco FirewallNNT CIS Cisco Firewall Benchmark3.0.2.2
Cisco IOS 12NNT CIS Cisco IOS 12 - Level 14.0.0.2
NNT CIS Cisco IOS 12 - Level 24.0.0.2
Cisco IOS 15NNT CIS Cisco IOS 15 - Level 14.1.1
NNT CIS Cisco IOS 15 - Level 24.1.1
Cisco IOS 16NNT CIS Cisco IOS 16 - Level 12.0.0
NNT CIS Cisco IOS 16 - Level 22.0.0
Cisco IOS 17.xNNT CIS Cisco IOS 17.x - Level 12.0.0
NNT CIS Cisco IOS 17.x - Level 22.0.0
+ +### Unix + + + + + + + + + + + +
Operating SystemTemplateCIS Version
IBM AIX 5.3-6.1NNT CIS IBM AIX 5.3-6.1 Benchmark - Level 11.1.0.2
NNT CIS IBM AIX 5.3-6.1 Benchmark - Level 21.1.0.2
IBM AIX 7.2NNT CIS IBM AIX 7.2 Benchmark - Level 11.1.0
NNT CIS IBM AIX 7.2 Benchmark - Level 21.1.0
+ +### Apple OSX + + + + + + + + + +
Operating SystemTemplateCIS Version
Apple OSX 10.11NNT CIS Apple OSX 10.11 Benchmark - Level 11.0.0.2
NNT CIS Apple OSX 10.11 Benchmark - Level 21.0.0.2
+ +### Desktop Office + + + + + + + + + + + + + + + + + + + + + + + +
ApplicationTemplateCIS Version
Adobe Acrobat Reader XNNT Adobe Acrobat Reader X Secure Configuration Benchmark1.0.0.3
Microsoft Excel 2013NNT CIS Excel 2013 Benchmark1.0.0.2
Microsoft Excel 2016NNT CIS Excel 2016 Benchmark1.0.0.2
Google ChromeNNT CIS Google Chrome Benchmark - Level 13.0.0
NNT CIS Google Chrome Benchmark - Level 23.0.0
Microsoft EdgeNNT CIS Microsoft Edge Benchmark - Level 12.0.0
NNT CIS Microsoft Edge Benchmark - Level 22.0.0
Microsoft Internet Explorer 11NNT CIS Microsoft Internet Explorer 11 Benchmark1.0.0.2
Mozilla Firefox 38 ESRNNT CIS Mozilla Firefox 38 ESR Benchmark1.0.0.2
Microsoft Office 2013NNT CIS Office 2013 Benchmark1.0.0.2
Microsoft Outlook 2016NNT CIS Outlook 2016 Benchmark1.0.0.2
Microsoft Outlook 2013NNT CIS Outlook2013 Benchmark1.0.0.2
Microsoft PowerPoint 2013NNT CIS PowerPoint 2013 Benchmark1.0.0.2
Microsoft PowerPoint 2016NNT CIS PowerPoint 2016 Benchmark1.0.0.2
Microsoft Word 2013NNT CIS Word 2013 Benchmark1.0.0.2
Microsoft Word 2016NNT CIS Word 2016 Benchmark1.0.0.2
+ +### Virtualization + + + + + + + + + + + + + + + + + + + + + +
PlatformTemplateCIS Version
VMware ESXi 5.5NNT CIS VMware ESXi 5.5 Benchmark - Level 11.2.0.2
NNT CIS VMware ESXi 5.5 Benchmark - Level 21.2.0.2
VMware ESXi 6.5NNT CIS VMware ESXi 6.5 Benchmark - Level 11.0.0
NNT CIS VMware ESXi 6.5 Benchmark - Level 21.0.0
VMware ESXi 6.7NNT CIS VMware ESXi 6.7 Benchmark - Level 11.1.0
NNT CIS VMware ESXi 6.7 Benchmark - Level 21.1.0
Netwrix CIS VMware ESXi 6.7 Benchmark v1.2.0 - Level 11.0.0.2
Netwrix CIS VMware ESXi 6.7 Benchmark v1.2.0 - Level 21.0.0.2
VMware ESXi 7.0NNT CIS VMware ESXi 7.0 Benchmark - Level 11.1.0
NNT CIS VMware ESXi 7.0 Benchmark - Level 21.1.0
Netwrix CIS VMware ESXi 7.0 Benchmark v1.1.0 - Level 11.0.0.2
Netwrix CIS VMware ESXi 7.0 Benchmark v1.1.0 - Level 21.0.0.2
VMware ESXi 8.0NNT CIS VMware ESXi 8.0 Benchmark - Level 11.2.0
NNT CIS VMware ESXi 8.0 Benchmark - Level 21.2.0
+ +### Web Servers + + + + + + + + + + + + + + + + + + + +
PlatformTemplateCIS Version
Apache HTTP Server 2.2NNT CIS Apache HTTP Server 2.2 Benchmark - Level 13.6.0
NNT CIS Apache HTTP Server 2.2 Benchmark - Level 23.6.0
Apache HTTP Server 2.4NNT CIS Apache HTTP Server 2.4 Benchmark - Level 12.3.0
NNT CIS Apache HTTP Server 2.4 Benchmark - Level 22.3.0
Apache Tomcat 10.1NNT CIS Apache Tomcat 10.1 Benchmark - Level 11.1.0.1
NNT CIS Apache Tomcat 10.1 Benchmark - Level 21.1.0.1
Apache Tomcat 5.5-6.0NNT CIS Apache Tomcat 5.5-6.0 Benchmark - Level 11.0.0.9
NNT CIS Apache Tomcat 5.5-6.0 Benchmark - Level 21.0.0.9
Microsoft IIS 10NNT CIS Microsoft IIS 10 Benchmark - Level 11.2.2
NNT CIS Microsoft IIS 10 Benchmark - Level 21.2.2
Microsoft IIS 8NNT CIS Microsoft IIS 8 Benchmark - Level 11.4.0.2
NNT CIS Microsoft IIS 8 Benchmark - Level 21.4.0.2
+ +## PCI DSS + +Payment Card Industry Data Security Standard (PCI DSS) reports. + +| Operating System | Template | +| --- | --- | +| IBM AIX 7.1 | NNT PCI DSS AIX 7.1 | +| Apache Tomcat 5.5-6.0 | NNT PCI DSS Apache Tomcat 5.5-6.0 | +| Cisco IOS 12 | NNT PCI DSS Cisco IOS 12 Benchmark | +| Cisco IOS 15 | NNT PCI DSS Cisco IOS 15 Benchmark | +| Microsoft IIS 10 | NNT PCI DSS Microsoft IIS 10 Benchmark | +| Microsoft IIS 7.0 | NNT PCI DSS Microsoft IIS 7.0 Benchmark | +| Microsoft IIS 7.5 | NNT PCI DSS Microsoft IIS 7.5 Benchmark | +| Microsoft IIS 8 | NNT PCI DSS Microsoft IIS 8 Benchmark | +| Microsoft Member Server 2003 | NNT PCI DSS Microsoft Member Server 2003 | +| Microsoft Member Server 2003 (Agentless) | NNT PCI DSS Microsoft Member Server 2003 (Agentless) | +| Microsoft Member Server 2008 | NNT PCI DSS Microsoft Member Server 2008 | +| Microsoft Member Server 2008R2 | NNT PCI DSS Microsoft Member Server 2008R2 | +| Microsoft Member Server 2012 | NNT PCI DSS Microsoft Member Server 2012 | +| Microsoft Member Server 2016 | NNT PCI DSS Microsoft Member Server 2016 v1217 | +| Microsoft Member Server 2019 | NNT PCI DSS Microsoft Member Server 2019 | +| Microsoft Member Server 2022 | NNT PCI DSS Microsoft Member Server 2022 | +| Microsoft SQL Server 2008R2 | NNT PCI DSS Microsoft SQL Server 2008R2 Database Engine | +| Microsoft Windows 7 | NNT PCI DSS Microsoft Windows 7 | +| Microsoft Windows Server 2003 | NNT PCI DSS Microsoft Windows Server 2003 | +| Oracle Database 12c | NNT PCI DSS Oracle Database 12c Benchmark | +| Red Hat Enterprise Linux 5 | NNT PCI DSS RHEL 5 | +| Red Hat Enterprise Linux 6 | NNT PCI DSS RHEL 6 v0817 | +| Red Hat Enterprise Linux 7 | NNT PCI DSS RHEL 7 | +| Red Hat Enterprise Linux 8 | NNT PCI DSS RHEL 8 Server v1.0.0.3 | +| VMware ESXi 5.5 | NNT PCI DSS VMware ESXi 5.5 | +| Microsoft Windows 10 Enterprise 1709 | NNT PCI DSS Windows 10 Enterprise 1709 v1217 | + +## HIPAA + +Health Insurance Portability and Accountability Act (HIPAA) reports. + +| Operating System | Template | +| --- | --- | +| Microsoft Member Windows Server 2008R2 | NNT HIPAA Microsoft Member Windows Server 2008R2 | +| Microsoft Member Windows Server 2012 | NNT HIPAA Microsoft Member Windows Server 2012 | +| Microsoft Member Windows Server 2012R2 | NNT HIPAA Microsoft Member Windows Server 2012R2 | +| Microsoft Member Windows Server 2016 | NNT HIPAA Microsoft Member Windows Server 2016 | +| Microsoft Windows 10 Enterprise 1709 | NNT HIPAA Microsoft Windows 10 Enterprise 1709 | +| Oracle Linux 7 | NNT HIPAA Oracle Linux 7 Benchmark | +| Red Hat Enterprise Linux 7 | NNT HIPAA RedHat Enterprise Linux 7 Benchmark | +| Red Hat Enterprise Linux 8 | NNT HIPAA RedHat Enterprise Linux 8 Benchmark | +| Windows Server 2019 | NNT HIPAA Windows Server 2019 Benchmark | +| Windows Server 2022 | NNT HIPAA Windows Server 2022 Benchmark | +| Windows Server 2025 | NNT HIPAA Windows Server 2025 Benchmark | + +## SOX + +Sarbanes-Oxley Act (SOX) reports. + +| Operating System | Template | +| --- | --- | +| Microsoft Member Server 2008R2 | NNT SOX Microsoft Member Server 2008R2 | +| Microsoft Member Server 2012 | NNT SOX Microsoft Member Server 2012 | +| Microsoft Member Server 2012R2 | NNT SOX Microsoft Member Server 2012R2 | +| Microsoft Member Server 2016 | NNT SOX Microsoft Member Server 2016 | +| Microsoft Windows 7 | NNT SOX Microsoft Windows 7 | +| Microsoft Windows 10 Enterprise 1709 | NNT SOX Windows 10 Enterprise 1709 | + +## DISA STIG + +Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) reports. + +| Operating System | Template | +| --- | --- | +| Adobe Acrobat Reader X | NNT Adobe Acrobat Reader X Secure Configuration Benchmark | +| Google Chrome | NNT U Google Chrome STIG V1R19 Manual | +| Microsoft Windows 11 | NNT U MS Windows 11 STIG | +| Microsoft Windows Server 2019 | NNT U MS Windows Server 2019 STIG | +| Microsoft Windows Server 2022 | NNT U MS Windows Server 2022 STIG | +| Microsoft Windows Server 2025 | NNT U MS Windows Server 2025 STIG | +| Red Hat Enterprise Linux 7 | NNT U Red Hat Enterprise Linux 7 STIG V2R5 Manual | +| Red Hat Enterprise Linux 6 | NNT U RedHat 6 V1R14 STIG | +| Oracle Solaris (SPARC) 10 | NNT U Solaris 10 SPARC V1R17 STIG SCAP | +| Oracle Solaris (x86) 10 | NNT U Solaris 10 X86 V1R17 STIG SCAP | +| Oracle Solaris (SPARC) 11 | NNT U Solaris 11 SPARC V1R5 STIG | +| Oracle Solaris (x86) 11 | NNT U Solaris 11 X86 V1R5 STIG SCAP | +| Microsoft Windows 10 | NNT U Windows 10 V1R6 STIG | +| Microsoft Windows Server (member server) 2012 / 2012 R2 | NNT U Windows 2012 and 2012 R2 MS V2R7 STIG | +| Microsoft Windows 7 | NNT U Windows 7 V1R31 | +| Microsoft Windows Server (member server) 2016 | NNT U Windows Member Server 2016 STIG V1R1 | +| Microsoft Windows Server (member server) 2008 R2 | NNT Windows 2008 R2 MS V1R20 STIG | +| Microsoft Windows 8 – 8.1 | NNT Windows 8 - 8.1 Security Technical Implementation Guide V1R14 | +| Microsoft Internet Explorer 11 | NNT_U_MS_IE11_STIG_V1R19_Manual | + +## NIST 800-53 + +National Institute of Standards and Technology (NIST) Special Publication 800-53 reports. + +| Operating System | Template | +| --- | --- | +| Microsoft Windows 10 Enterprise 1703 | NNT NIST 800-53 Microsoft Windows 10 Enterprise 1703 | +| Microsoft Windows 10 Enterprise 20H2 | NNT NIST 800-53 Microsoft Windows 10 Enterprise 20H2 | +| Microsoft Windows Server 2008 | NNT NIST 800-53 Microsoft Windows Server 2008 Benchmark | +| Microsoft Windows Server 2008 R2 | NNT NIST 800-53 Microsoft Windows Server 2008 R2 Benchmark | +| Microsoft Windows Server 2012 | NNT NIST 800-53 Microsoft Windows Server 2012 Benchmark | +| Microsoft Windows Server 2012 R2 | NNT NIST 800-53 Microsoft Windows Server 2012 R2 Benchmark | +| Microsoft Windows Server 2016 | NNT NIST 800-53 Microsoft Windows Server 2016 Benchmark | +| Microsoft Windows Server 2019 | NNT NIST 800-53 Microsoft Windows Server 2019 Benchmark | +| Microsoft Windows Server 2022 | NNT NIST 800-53 Microsoft Windows Server 2022 Benchmark | +| Microsoft Windows Server 2025 | NNT NIST 800-53 Microsoft Windows Server 2025 Benchmark | +| Oracle Linux 6 | NNT NIST 800-53 Oracle Linux 6 Server | +| Oracle Linux 7 | NNT NIST 800-53 Oracle Linux 7 Server | +| Red Hat Enterprise Linux 7 | NNT NIST 800-53 RHEL 7 Server v1.1.0 | +| Red Hat Enterprise Linux 8 | NNT NIST 800-53 RHEL 8 Server v1.1.5 | +| Ubuntu Linux 20.04 | NNT NIST 800-53 Ubuntu Linux 20.04 Benchmark | +| Ubuntu Linux 22.04 | NNT NIST 800-53 Ubuntu Linux 22.04 Benchmark | +| Ubuntu Linux 24.04 | NNT NIST 800-53 Ubuntu Linux 24.04 Benchmark | +| VMware ESXi 5.5 | NNT NIST 800-53 VMware ESXi 5.5 Benchmark | +| VMware ESXi 8.0 | NNT NIST 800-53 VMware ESXi 8.0 Benchmark | + +## NIST 800-171 + +NIST Special Publication 800-171 reports. + +| Operating System | Template | +| --- | --- | +| Microsoft Windows 10 Enterprise 2004 | NNT NIST 800-171 Microsoft Windows 10 Enterprise 2004 Benchmark | +| Microsoft Windows 10 Enterprise 20H2 | NNT NIST 800-171 Microsoft Windows 10 Enterprise 20H2 Benchmark | +| Microsoft Windows 11 | NNT NIST 800-171 Microsoft Windows 11 Benchmark | +| Microsoft Windows Server 2008 | NNT NIST 800-171 Microsoft Windows Server 2008 Benchmark | +| Microsoft Windows Server 2008 R2 | NNT NIST 800-171 Microsoft Windows Server 2008 R2 Benchmark | +| Microsoft Windows Server 2012 | NNT NIST 800-171 Microsoft Windows Server 2012 Benchmark | +| Microsoft Windows Server 2012 R2 | NNT NIST 800-171 Microsoft Windows Server 2012 R2 Benchmark | +| Microsoft Windows Server 2016 | NNT NIST 800-171 Microsoft Windows Server 2016 Benchmark | +| Microsoft Windows Server 2019 | NNT NIST 800-171 Microsoft Windows Server 2019 Benchmark | +| Microsoft Windows Server 2022 | NNT NIST 800-171 Microsoft Windows Server 2022 Benchmark | +| Microsoft Windows Server 2025 | NNT NIST 800-171 Microsoft Windows Server 2025 Benchmark | +| Oracle Linux 6 | NNT NIST 800-171 Oracle Linux 6 Server | +| Oracle Linux 7 | NNT NIST 800-171 Oracle Linux 7 Server | +| Red Hat Enterprise Linux 7 | NNT NIST 800-171 RHEL 7 v1.1.0 Server | +| Red Hat Enterprise Linux 8 | NNT NIST 800-171 RHEL 8 v1.1.1 Server | +| Ubuntu Linux 20.04 | NNT NIST 800-171 Ubuntu Linux 20.04 Benchmark | +| Ubuntu Linux 22.04 | NNT NIST 800-171 Ubuntu Linux 22.04 Benchmark | +| Ubuntu Linux 24.04 | NNT NIST 800-171 Ubuntu Linux 24.04 Benchmark | +| VMware ESXi 5.5 | NNT NIST 800-171 VMware ESXi 5.5 Benchmark | +| VMware ESXi 8.0 | NNT NIST 800-171 VMware ESXi 8.0 Benchmark | + +## ISO 27001 + +International Organization for Standardization (ISO)/International Electrotechnical Commission +(IEC) 27001 reports. + +| Operating System | Template | +| --- | --- | +| Microsoft SQL Server 2008R2 | NNT ISO 27K Microsoft SQL Server 2008R2 Database Engine Benchmark | +| Microsoft SQL Server 2012 | NNT ISO 27K Microsoft SQL Server 2012 Database Engine Benchmark | +| Microsoft Windows 10 | NNT ISO27K Microsoft Windows 10 Benchmark | +| Microsoft Windows 11 | NNT ISO27K Microsoft Windows 11 Benchmark | +| Microsoft Windows Server (member server) 2003 | NNT ISO27K Microsoft Windows Server 2003 Benchmark - L1 Member Server | +| Microsoft Windows Server (domain controller) 2008R2 | NNT ISO27K Microsoft Windows Server 2008R2 Benchmark - L1 Domain Controller | +| Microsoft Windows Server (member server) 2008R2 | NNT ISO27K Microsoft Windows Server 2008R2 Benchmark - L1 Member Server | +| Microsoft Windows Server (domain controller) 2012 R2 | NNT ISO27K Microsoft Windows Server 2012 R2 Benchmark - L1 Domain Controller | +| Microsoft Windows Server (member server) 2012 R2 | NNT ISO27K Microsoft Windows Server 2012 R2 Benchmark - L1 Member Server | +| Microsoft Windows Server (domain controller) 2016 | NNT ISO27K Microsoft Windows Server 2016 Benchmark - L1 Domain Controller | +| Microsoft Windows Server (member server) 2016 | NNT ISO27K Microsoft Windows Server 2016 Benchmark - L1 Member Server | +| Microsoft Windows Server 2019 | NNT ISO27K Microsoft Windows Server 2019 Benchmark | +| Oracle Linux 6 | NNT ISO27K Oracle Linux 6 Benchmark | +| Oracle Linux 7 | NNT ISO27K Oracle Linux 7 Benchmark | +| Oracle Solaris 10 | NNT ISO27K Oracle Solaris 10 Benchmark | +| Red Hat Enterprise Linux 6 | NNT ISO27K Red Hat Enterprise Linux 6 Benchmark | +| Red Hat Enterprise Linux 7 | NNT ISO27K Red Hat Enterprise Linux 7 Benchmark | + +## NERC CIP-007-6 + +North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) +CIP-007-6 reports, each covering a specific requirement table for Windows devices. + +| Focus Area | Template | +| --- | --- | +| R1 – Hardened Ports Assessment | NNT NERC CIP-007-6 Table R1 – Hardened Ports Assessment for Windows 2 | +| R1 – Hardened Services Assessment | NNT NERC CIP-007-6 Table R1 – Hardened Services Assessment for Windows 2 | +| R3 – Malicious Code Prevention | NNT NERC CIP-007-6 Table R3 – Malicious Code Prevention for Windows 2 | +| R4 – Security Event Monitoring | NNT NERC CIP-007-6 Table R4 – Security Event Monitoring for Windows 2 | +| R5 – System Access Control | NNT NERC CIP-007-6 Table R5 – System Access Control for Windows 2 | + diff --git a/docs/changetracker/8.2/compliance/compliancetemplates.md b/docs/changetracker/8.2/compliance/compliancetemplates.md deleted file mode 100644 index df20887409..0000000000 --- a/docs/changetracker/8.2/compliance/compliancetemplates.md +++ /dev/null @@ -1,97 +0,0 @@ ---- -title: "Compliance Templates" -description: "Compliance Templates" -sidebar_position: 10 ---- - -# Compliance Templates - -Change Tracker's compliance templates map directly to the prescriptive configuration recommendations -in the Center for Internet Security (CIS) -[Benchmarks List](https://www.cisecurity.org/cis-benchmarks). Each Change Tracker compliance report -is [CIS approved](https://www.cisecurity.org/partner/netwrix). - -The tables below list the CIS benchmarks that have been implemented as compliance reports and the -operating systems that they support. - -## Cloud - -| Platform | -| ------------- | -| Azure | -| Microsoft 365 | -| AWS | -| GCP | - -## Windows - -| Operating System | OS Versions | -| ---------------- | ---------------------- | -| Windows Desktop | 11, 10, 8, 7 | -| Windows Server | 2025, 2022, 2019, 2016, 2012 | - -## Linux - -| Operating System | OS Versions | -| ------------------------------------ | ------------------- | -| Amazon Linux | 2, 2023 | -| CentOS Workstation | 8, 7, 6 | -| CentOS Server | 8, 7, 6 | -| Debian Workstation | 10, 9, 8 | -| Debian Server | 10, 9, 8 | -| Oracle Linux Workstation | 7, 6 | -| Oracle Linux Server | 7, 6 | -| Red Hat Enterprise Linux Workstation | 9, 8, 7, 6 | -| Red Hat Enterprise Linux Server | 9, 8, 7, 6 | -| Rocky Linux Workstation | 8 | -| Rocky Linux Server | 8 | -| SUSE Workstation | 15 | -| SUSE Server | 15 | -| Ubuntu Workstation | 20.04, 18.04, 16.04 | -| Ubuntu Server | 20.04, 18.04, 16.04 | - -## Other Operating Systems - -| Operating System | OS Versions | -| ---------------- | ----------- | -| IBM AIX | 6.1, 5.3 | -| Oracle Solaris | 11 | - -## Databases - -Database compliance templates come in three major types: - -- RDBMS (Relational Database Management System) -- Windows -- Linux - -Other types exist for cloud platforms like AWS's RDS. - -The RDBMS template contains all of the checks done via a database connection. All other types extend -this base template with checks at the OS level using shell scripts, PowerShell, etc or they override -certain checks with code that is specific to the platform. - -The database connection only RDBMS type compliance templates enable the opportunity to support a -database product on operating systems not listed below due to the lack of OS level checks. These -missing OS level checks must be mitigated and there is a risk that the targeted OS caused certain -checks to fail because of certain settings that are specific to that OS. Individual checks can be -disabled, but mitigation would be required. - -| Database | Database Version | Compliance Template Types | -| -------------------- | ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Microsoft SQL Server | 2019 | RDBMS, Windows, RDS | -| Microsoft SQL Server | 2017 | RDBMS, Windows, RDS | -| Microsoft SQL Server | 2016 | RDBMS, Windows, RDS | -| Microsoft SQL Server | 2014 | Windows | -| Microsoft SQL Server | 2012 | Windows | -| Microsoft SQL Server | 2008R2 | Windows | -| Oracle | 19c | RDBMS - Traditional Auditing, RDBMS - Unified Auditing, Linux - Traditional Auditing, Linux - Unified Auditing, Windows - Traditional Auditing, Windows - Unified Auditing, | -| Oracle | 12c | RDBMS, Linux, Windows | - -## Network Devices - -| Operating System | OS Versions | -| ---------------- | ----------- | -| Cisco IOS | 17, 16, 15 | -| F5 | All | -| Juniper | All | From d2bfa3b2f4390ab767313c677686c30ccf54435f Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 31 Jul 2026 20:48:21 +0000 Subject: [PATCH 02/14] fix(vale): auto-fix style issues (Vale + Dale) --- docs/changetracker/8.2/compliance/compliance.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index 0190192551..637cbd4efe 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -17,8 +17,8 @@ Hardened Build Standard. View estate/device compliance by selecting a different from the Compliance Report selector then drill into report results by clicking on the Report Score for any Device. -Any individual report can be viewed by clicking the result score, and reports selected using the -checkboxes can be exported in a range of formats (pdf, excel or csv) with an option to select more +You can view any individual report by clicking the result score, and export the reports you select +with the checkboxes in a range of formats (pdf, excel, or csv), with an option to select more detailed results. Review the following for additional information: @@ -29,11 +29,11 @@ Review the following for additional information: ## Comparing Results -By selecting any two results, either for the same device or for two different devices, the **Compare -Results** button becomes available. +When you select any two results, either for the same device or for two different devices, the +**Compare Results** button becomes available. -This will run a compare of the two reports, useful for seeing what has caused a score to drop, or to -establish what the difference is in configuration between two devices. +This runs a comparison of the two reports, which helps you see what caused a score to drop or +identify the configuration differences between two devices. ## Compliance report templates From c11f89826fe1cdb792d2a8b75af38609e16b9936 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 31 Jul 2026 22:00:12 +0000 Subject: [PATCH 03/14] docs: apply fixes from PR review - Demote compliance standard families (CIS, PCI DSS, HIPAA, SOX, DISA STIG, NIST 800-53/800-171, ISO 27001, NERC CIP-007-6) to H3 under Compliance report templates, and CIS sub-tables to H4 - Define Hub Server on first use - Expand NIST to NIST 800-53, NIST 800-171 in the info admonition - Clarify which checkbox overwrites templates during upload Co-Authored-By: Claude --- .../8.2/compliance/compliance.md | 49 ++++++++++--------- 1 file changed, 25 insertions(+), 24 deletions(-) diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index 637cbd4efe..750480d911 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -42,9 +42,10 @@ templates. :::info Only Center for Internet Security (CIS) benchmark reports ship bundled with the Hub Server -installer and are ready to select when you create a compliance report. Every other report on this -page — PCI DSS, HIPAA, SOX, DISA STIG, NIST, ISO 27001, and NERC CIP-007-6 — is available through -the Compliance Benchmarks download on the +installer (the Change Tracker management server) and are ready to select when you create a +compliance report. Every other report on this page — PCI DSS, HIPAA, SOX, DISA STIG, NIST 800-53, +NIST 800-171, ISO 27001, and NERC CIP-007-6 — is available through the Compliance Benchmarks +download on the [Customer Portal](https://customer.netwrix.com/my_products.html), which you import into Change Tracker. @@ -59,7 +60,7 @@ After you download a template from the Customer Portal, upload it to Change Trac 1. Go to **Settings** > **Policy Templates**. 2. Click the **Actions** dropdown, then click **Upload Templates**. 3. Browse to the downloaded XML file and select it. -4. To overwrite an existing template with the same name, select the corresponding checkbox. +4. To replace an existing template that has the same name, select the checkbox that overwrites templates on upload. 5. Click **Upload Template**. Review the following for additional information: @@ -68,7 +69,7 @@ Review the following for additional information: - [Adding or Replacing Configuration and Compliance Report Templates](/docs/changetracker/8.2/kb/configuration-and-setup/add-replace-compliance-report-templates.md) - [Applying a Compliance Template to a Group for Automated Reporting](/docs/changetracker/8.2/kb/configuration-and-setup/apply-compliance-template-to-group.md) -## CIS +### CIS Change Tracker's CIS compliance reports map directly to the prescriptive configuration recommendations in the Center for Internet Security (CIS) @@ -84,7 +85,7 @@ of the underlying CIS benchmark document version — for example, some template CIS-published specification version, such as the `(2.0.0)` in "NNT CIS Amazon Web Services Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Version. -### Cloud +#### Cloud @@ -98,7 +99,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Windows +#### Windows @@ -281,7 +282,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Linux +#### Linux @@ -399,7 +400,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Databases +#### Databases @@ -442,7 +443,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Network Devices +#### Network Devices @@ -463,7 +464,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Cisco +#### Cisco @@ -482,7 +483,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Unix +#### Unix @@ -496,7 +497,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Apple OSX +#### Apple OSX @@ -508,7 +509,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Desktop Office +#### Desktop Office @@ -534,7 +535,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Virtualization +#### Virtualization @@ -558,7 +559,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-### Web Servers +#### Web Servers @@ -580,7 +581,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve
-## PCI DSS +### PCI DSS Payment Card Industry Data Security Standard (PCI DSS) reports. @@ -613,7 +614,7 @@ Payment Card Industry Data Security Standard (PCI DSS) reports. | VMware ESXi 5.5 | NNT PCI DSS VMware ESXi 5.5 | | Microsoft Windows 10 Enterprise 1709 | NNT PCI DSS Windows 10 Enterprise 1709 v1217 | -## HIPAA +### HIPAA Health Insurance Portability and Accountability Act (HIPAA) reports. @@ -631,7 +632,7 @@ Health Insurance Portability and Accountability Act (HIPAA) reports. | Windows Server 2022 | NNT HIPAA Windows Server 2022 Benchmark | | Windows Server 2025 | NNT HIPAA Windows Server 2025 Benchmark | -## SOX +### SOX Sarbanes-Oxley Act (SOX) reports. @@ -644,7 +645,7 @@ Sarbanes-Oxley Act (SOX) reports. | Microsoft Windows 7 | NNT SOX Microsoft Windows 7 | | Microsoft Windows 10 Enterprise 1709 | NNT SOX Windows 10 Enterprise 1709 | -## DISA STIG +### DISA STIG Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) reports. @@ -670,7 +671,7 @@ Defense Information Systems Agency (DISA) Security Technical Implementation Guid | Microsoft Windows 8 – 8.1 | NNT Windows 8 - 8.1 Security Technical Implementation Guide V1R14 | | Microsoft Internet Explorer 11 | NNT_U_MS_IE11_STIG_V1R19_Manual | -## NIST 800-53 +### NIST 800-53 National Institute of Standards and Technology (NIST) Special Publication 800-53 reports. @@ -696,7 +697,7 @@ National Institute of Standards and Technology (NIST) Special Publication 800-53 | VMware ESXi 5.5 | NNT NIST 800-53 VMware ESXi 5.5 Benchmark | | VMware ESXi 8.0 | NNT NIST 800-53 VMware ESXi 8.0 Benchmark | -## NIST 800-171 +### NIST 800-171 NIST Special Publication 800-171 reports. @@ -723,7 +724,7 @@ NIST Special Publication 800-171 reports. | VMware ESXi 5.5 | NNT NIST 800-171 VMware ESXi 5.5 Benchmark | | VMware ESXi 8.0 | NNT NIST 800-171 VMware ESXi 8.0 Benchmark | -## ISO 27001 +### ISO 27001 International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 27001 reports. @@ -748,7 +749,7 @@ International Organization for Standardization (ISO)/International Electrotechni | Red Hat Enterprise Linux 6 | NNT ISO27K Red Hat Enterprise Linux 6 Benchmark | | Red Hat Enterprise Linux 7 | NNT ISO27K Red Hat Enterprise Linux 7 Benchmark | -## NERC CIP-007-6 +### NERC CIP-007-6 North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) CIP-007-6 reports, each covering a specific requirement table for Windows devices. From b4ef6c555b761b891e392ce6a10b2aefcdd9e456 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 31 Jul 2026 22:03:14 +0000 Subject: [PATCH 04/14] docs: fix broken KB links in compliance report catalog The editorial fixes landed in the previous commit but the three KB article links still used the versioned /docs/changetracker/8.2/kb/...md form, which does not resolve against the source tree and fails the broken-link check. Switch to the /docs/kb/changetracker/... form (no version, no .md extension) used elsewhere in the docs, matching the copied KB content and unblocking the build. Co-Authored-By: Claude --- docs/changetracker/8.2/compliance/compliance.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index 750480d911..fbb1eddd46 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -65,9 +65,9 @@ After you download a template from the Customer Portal, upload it to Change Trac Review the following for additional information: -- [How to Upload a Compliance/Tracking Template to Change Tracker](/docs/changetracker/8.2/kb/configuration-and-setup/upload-compliance-template.md) -- [Adding or Replacing Configuration and Compliance Report Templates](/docs/changetracker/8.2/kb/configuration-and-setup/add-replace-compliance-report-templates.md) -- [Applying a Compliance Template to a Group for Automated Reporting](/docs/changetracker/8.2/kb/configuration-and-setup/apply-compliance-template-to-group.md) +- [How to Upload a Compliance/Tracking Template to Change Tracker](/docs/kb/changetracker/configuration-and-setup/upload-compliance-template) +- [Adding or Replacing Configuration and Compliance Report Templates](/docs/kb/changetracker/configuration-and-setup/add-replace-compliance-report-templates) +- [Applying a Compliance Template to a Group for Automated Reporting](/docs/kb/changetracker/configuration-and-setup/apply-compliance-template-to-group) ### CIS From 5ec3394d4153acfb61bdcdb6e13594ca07de49b6 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Fri, 31 Jul 2026 22:06:05 +0000 Subject: [PATCH 05/14] fix(vale): auto-fix style issues (Vale + Dale) --- docs/changetracker/8.2/compliance/compliance.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index fbb1eddd46..9dd59ead5c 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -32,7 +32,7 @@ Review the following for additional information: When you select any two results, either for the same device or for two different devices, the **Compare Results** button becomes available. -This runs a comparison of the two reports, which helps you see what caused a score to drop or +This compares the two reports, which helps you see what caused a score to drop or identify the configuration differences between two devices. ## Compliance report templates From a861499d00cecc086afa32aff841d6b89a27d4a0 Mon Sep 17 00:00:00 2001 From: Dan Piazza <220388267+DanPiazza-Netwrix@users.noreply.github.com> Date: Mon, 3 Aug 2026 14:16:38 -0400 Subject: [PATCH 06/14] docs(changetracker): update CIS templates for 03-08-2026 snapshot Reflects the latest changetracker-compliance-reports.zip: version bumps for Windows Server 2022 base templates (3.0.0 -> 5.1.0) and VMware ESXi 8.0 (1.2.0 -> 1.3.0), new Cisco IOS XE 17.x and Cisco NX-OS entries, new IBM AIX 7 entry, and a restructured Oracle Database 19c set (replacing the old auditing-variant templates with the new RDBMS/RDBMS-on-host-OS templates). Oracle Database 12c's surviving auditing-variant templates are unchanged. Temporarily highlights every changed/added row with for review; remove before merging. --- .../8.2/compliance/compliance.md | 36 +++++++++---------- 1 file changed, 18 insertions(+), 18 deletions(-) diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index 9dd59ead5c..b2ec7623d0 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -110,12 +110,12 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - Level 1 Member Server1.0.0 NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - NxGen Security - Level 1 Domain Controller1.0.0 NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - NxGen Security - Level 1 Member Server1.0.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Domain Controller3.0.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Member Server3.0.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Domain Controller3.0.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Member Server3.0.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Domain Controller3.0.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Member Server3.0.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Domain Controller5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Member Server5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Domain Controller5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Member Server5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Domain Controller5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Member Server5.1.0 Windows 10 Enterprise 1511NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 11.1.0.2 NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 1 + Bitlocker1.1.0.2 NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 21.1.0.3 @@ -425,21 +425,15 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS Microsoft SQL Server 2022 Benchmark - Level 1 - Database Engine1.1.0 NNT CIS Microsoft SQL Server 2022 Benchmark - Level 1 - Windows1.1.0 NNT CIS Microsoft SQL Server 2022 Benchmark - Level 2 - Database Engine1.1.0 - Oracle Database 12cNNT CIS Oracle Database 12c Benchmark1.2.2.3 - NNT CIS Oracle Database 12c Benchmark - Level 1 - Linux Host OS using Traditional Auditing3.0.0 + Oracle Database 12cNNT CIS Oracle Database 12c Benchmark - Level 1 - Linux Host OS using Traditional Auditing3.0.0 NNT CIS Oracle Database 12c Benchmark - Level 1 - Linux Host OS using Unified Auditing3.0.0 NNT CIS Oracle Database 12c Benchmark - Level 1 - RDBMS using Traditional Auditing3.0.0 NNT CIS Oracle Database 12c Benchmark - Level 1 - RDBMS using Unified Auditing3.0.2 NNT CIS Oracle Database 12c Benchmark - Level 1 - Windows Server Host OS using Traditional Auditing3.0.0 NNT CIS Oracle Database 12c Benchmark - Level 1 - Windows Server Host OS using Unified Auditing3.0.0 - NNT CIS Oracle Database 12c Benchmark - Linux1.2.0.2 - NNT CIS Oracle Database 12c Benchmark - Windows1.2.0.2 - Oracle Database 19cNNT CIS Oracle Database 19c Benchmark - Level 1 - Linux Host OS using Traditional Auditing1.1.0 - NNT CIS Oracle Database 19c Benchmark - Level 1 - Linux Host OS using Unified Auditing1.1.0 - NNT CIS Oracle Database 19c Benchmark - Level 1 - RDBMS using Traditional Auditing1.1.0 - NNT CIS Oracle Database 19c Benchmark - Level 1 - RDBMS using Unified Auditing1.1.0 - NNT CIS Oracle Database 19c Benchmark - Level 1 - Windows Server Host OS using Traditional Auditing1.1.0 - NNT CIS Oracle Database 19c Benchmark - Level 1 - Windows Server Host OS using Unified Auditing1.1.0 + Oracle Database 19cNNT CIS Oracle Database 19c - Level 1 - RDBMS2.0.0 + NNT CIS Oracle Database 19c - Level 1 - RDBMS On Host OS - Windows2.0.0 + NNT CIS Oracle Database 19c - Level 1 - RDBMS On Host OS - Linux2.0.0 @@ -480,6 +474,10 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS Cisco IOS 16 - Level 22.0.0 Cisco IOS 17.xNNT CIS Cisco IOS 17.x - Level 12.0.0 NNT CIS Cisco IOS 17.x - Level 22.0.0 + Cisco IOS XE 17.xNNT CIS Cisco IOS XE 17.x - Level 12.2.1 + NNT CIS Cisco IOS XE 17.x - Level 22.2.1 + Cisco NX-OSNNT CIS Cisco NX-OS - Level 11.2.0 + NNT CIS Cisco NX-OS - Level 21.2.0 @@ -494,6 +492,8 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS IBM AIX 5.3-6.1 Benchmark - Level 21.1.0.2 IBM AIX 7.2NNT CIS IBM AIX 7.2 Benchmark - Level 11.1.0 NNT CIS IBM AIX 7.2 Benchmark - Level 21.1.0 + IBM AIX 7NNT CIS IBM AIX 7 Benchmark - Level 11.2.0 + NNT CIS IBM AIX 7 Benchmark - Level 21.2.0 @@ -554,8 +554,8 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS VMware ESXi 7.0 Benchmark - Level 21.1.0 Netwrix CIS VMware ESXi 7.0 Benchmark v1.1.0 - Level 11.0.0.2 Netwrix CIS VMware ESXi 7.0 Benchmark v1.1.0 - Level 21.0.0.2 - VMware ESXi 8.0NNT CIS VMware ESXi 8.0 Benchmark - Level 11.2.0 - NNT CIS VMware ESXi 8.0 Benchmark - Level 21.2.0 + VMware ESXi 8.0NNT CIS VMware ESXi 8.0 Benchmark - Level 11.3.0 + NNT CIS VMware ESXi 8.0 Benchmark - Level 21.3.0 From d3ffef9c1a51f1fba290404f22cc07686e15c271 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Mon, 3 Aug 2026 18:31:56 +0000 Subject: [PATCH 07/14] docs: apply fixes from PR review - Capitalize file-format abbreviations (PDF, Excel, CSV) - Use imperative task heading 'Add a downloaded template' - Rename inaccurate 'Operating System' header to 'Platform' on the PCI DSS, DISA STIG, and ISO 27001 tables Co-Authored-By: Claude --- docs/changetracker/8.2/compliance/compliance.md | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index b2ec7623d0..33fb57c9fd 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -18,7 +18,7 @@ from the Compliance Report selector then drill into report results by clicking o for any Device. You can view any individual report by clicking the result score, and export the reports you select -with the checkboxes in a range of formats (pdf, excel, or csv), with an option to select more +with the checkboxes in a range of formats (PDF, Excel, or CSV), with an option to select more detailed results. Review the following for additional information: @@ -53,7 +53,7 @@ The Customer Portal download also contains newer CIS benchmark templates ahead o Tracker release, so you can adopt an updated benchmark without waiting for a product upgrade. ::: -### Adding a downloaded template +### Add a downloaded template After you download a template from the Customer Portal, upload it to Change Tracker: @@ -585,7 +585,7 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve Payment Card Industry Data Security Standard (PCI DSS) reports. -| Operating System | Template | +| Platform | Template | | --- | --- | | IBM AIX 7.1 | NNT PCI DSS AIX 7.1 | | Apache Tomcat 5.5-6.0 | NNT PCI DSS Apache Tomcat 5.5-6.0 | @@ -649,7 +649,7 @@ Sarbanes-Oxley Act (SOX) reports. Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) reports. -| Operating System | Template | +| Platform | Template | | --- | --- | | Adobe Acrobat Reader X | NNT Adobe Acrobat Reader X Secure Configuration Benchmark | | Google Chrome | NNT U Google Chrome STIG V1R19 Manual | @@ -729,7 +729,7 @@ NIST Special Publication 800-171 reports. International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 27001 reports. -| Operating System | Template | +| Platform | Template | | --- | --- | | Microsoft SQL Server 2008R2 | NNT ISO 27K Microsoft SQL Server 2008R2 Database Engine Benchmark | | Microsoft SQL Server 2012 | NNT ISO 27K Microsoft SQL Server 2012 Database Engine Benchmark | From d8dc99f782f737cc25ca429f66a7640d7743ce1a Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Mon, 3 Aug 2026 18:36:20 +0000 Subject: [PATCH 08/14] docs: apply fixes from PR review Align the 'Add a downloaded template' procedure with the authoritative UI names for uploading a benchmark XML template: Action button and Upload Template. Co-Authored-By: Claude --- docs/changetracker/8.2/compliance/compliance.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index 33fb57c9fd..893f756568 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -58,7 +58,7 @@ Tracker release, so you can adopt an updated benchmark without waiting for a pro After you download a template from the Customer Portal, upload it to Change Tracker: 1. Go to **Settings** > **Policy Templates**. -2. Click the **Actions** dropdown, then click **Upload Templates**. +2. Click the **Action** button, then click **Upload Template**. 3. Browse to the downloaded XML file and select it. 4. To replace an existing template that has the same name, select the checkbox that overwrites templates on upload. 5. Click **Upload Template**. From eed50c0bf30e1b36db46d06f76ce1bec5d448a1a Mon Sep 17 00:00:00 2001 From: Dan Piazza <220388267+DanPiazza-Netwrix@users.noreply.github.com> Date: Tue, 4 Aug 2026 09:29:20 -0400 Subject: [PATCH 09/14] docs(changetracker): remove temporary review highlights --- .../8.2/compliance/compliance.md | 34 +++++++++---------- 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/docs/changetracker/8.2/compliance/compliance.md b/docs/changetracker/8.2/compliance/compliance.md index 893f756568..f87f60ab1c 100644 --- a/docs/changetracker/8.2/compliance/compliance.md +++ b/docs/changetracker/8.2/compliance/compliance.md @@ -110,12 +110,12 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - Level 1 Member Server1.0.0 NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - NxGen Security - Level 1 Domain Controller1.0.0 NNT CIS Azure Compute Microsoft Windows Server 2022 Benchmark - NxGen Security - Level 1 Member Server1.0.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Domain Controller5.1.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Member Server5.1.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Domain Controller5.1.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Member Server5.1.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Domain Controller5.1.0 - NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Member Server5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Domain Controller5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - Level 1 Member Server5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Domain Controller5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - Level 2 Member Server5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Domain Controller5.1.0 + NNT CIS Microsoft Windows Server 2022 Benchmark - NxGen Security - Member Server5.1.0 Windows 10 Enterprise 1511NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 11.1.0.2 NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 1 + Bitlocker1.1.0.2 NNT CIS Microsoft Windows 10 Enterprise (Release 1511) Benchmark - Level 21.1.0.3 @@ -431,9 +431,9 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS Oracle Database 12c Benchmark - Level 1 - RDBMS using Unified Auditing3.0.2 NNT CIS Oracle Database 12c Benchmark - Level 1 - Windows Server Host OS using Traditional Auditing3.0.0 NNT CIS Oracle Database 12c Benchmark - Level 1 - Windows Server Host OS using Unified Auditing3.0.0 - Oracle Database 19cNNT CIS Oracle Database 19c - Level 1 - RDBMS2.0.0 - NNT CIS Oracle Database 19c - Level 1 - RDBMS On Host OS - Windows2.0.0 - NNT CIS Oracle Database 19c - Level 1 - RDBMS On Host OS - Linux2.0.0 + Oracle Database 19cNNT CIS Oracle Database 19c - Level 1 - RDBMS2.0.0 + NNT CIS Oracle Database 19c - Level 1 - RDBMS On Host OS - Windows2.0.0 + NNT CIS Oracle Database 19c - Level 1 - RDBMS On Host OS - Linux2.0.0 @@ -474,10 +474,10 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS Cisco IOS 16 - Level 22.0.0 Cisco IOS 17.xNNT CIS Cisco IOS 17.x - Level 12.0.0 NNT CIS Cisco IOS 17.x - Level 22.0.0 - Cisco IOS XE 17.xNNT CIS Cisco IOS XE 17.x - Level 12.2.1 - NNT CIS Cisco IOS XE 17.x - Level 22.2.1 - Cisco NX-OSNNT CIS Cisco NX-OS - Level 11.2.0 - NNT CIS Cisco NX-OS - Level 21.2.0 + Cisco IOS XE 17.xNNT CIS Cisco IOS XE 17.x - Level 12.2.1 + NNT CIS Cisco IOS XE 17.x - Level 22.2.1 + Cisco NX-OSNNT CIS Cisco NX-OS - Level 11.2.0 + NNT CIS Cisco NX-OS - Level 21.2.0 @@ -492,8 +492,8 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS IBM AIX 5.3-6.1 Benchmark - Level 21.1.0.2 IBM AIX 7.2NNT CIS IBM AIX 7.2 Benchmark - Level 11.1.0 NNT CIS IBM AIX 7.2 Benchmark - Level 21.1.0 - IBM AIX 7NNT CIS IBM AIX 7 Benchmark - Level 11.2.0 - NNT CIS IBM AIX 7 Benchmark - Level 21.2.0 + IBM AIX 7NNT CIS IBM AIX 7 Benchmark - Level 11.2.0 + NNT CIS IBM AIX 7 Benchmark - Level 21.2.0 @@ -554,8 +554,8 @@ Foundations Benchmark (2.0.0)," which can differ from that template's own CIS Ve NNT CIS VMware ESXi 7.0 Benchmark - Level 21.1.0 Netwrix CIS VMware ESXi 7.0 Benchmark v1.1.0 - Level 11.0.0.2 Netwrix CIS VMware ESXi 7.0 Benchmark v1.1.0 - Level 21.0.0.2 - VMware ESXi 8.0NNT CIS VMware ESXi 8.0 Benchmark - Level 11.3.0 - NNT CIS VMware ESXi 8.0 Benchmark - Level 21.3.0 + VMware ESXi 8.0NNT CIS VMware ESXi 8.0 Benchmark - Level 11.3.0 + NNT CIS VMware ESXi 8.0 Benchmark - Level 21.3.0 From b52ac2281456a2951f04ad5e5d5dfc45155e0e1c Mon Sep 17 00:00:00 2001 From: Dan Piazza <220388267+DanPiazza-Netwrix@users.noreply.github.com> Date: Tue, 4 Aug 2026 13:57:35 -0400 Subject: [PATCH 10/14] Revert incorrect anchor fix and correct check-anchors.sh's slug algorithm The Palo Alto KB article's link to "Step 4 -- Configure the Login Script" was correct all along: github-slugger (used by Docusaurus) produces a double hyphen there, since the em dash is stripped but the two spaces around it are each preserved as a literal hyphen. An earlier commit "fixed" this link to single-hyphen based on a false positive from check-anchors.sh, which broke the production build. check-anchors.sh collapsed runs of hyphens and multiple spaces before converting them, which github-slugger does not do. Removed that collapsing step so the local pre-commit check matches the real Docusaurus/github-slugger algorithm; verified against github-slugger directly across several test cases (em dashes, ampersands, parentheses, multiple spaces, leading/trailing whitespace). --- .../add-palo-alto-proxied-device.md | 2 +- scripts/check-anchors.sh | 9 ++++++--- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/docs/kb/changetracker/configuration-and-setup/add-palo-alto-proxied-device.md b/docs/kb/changetracker/configuration-and-setup/add-palo-alto-proxied-device.md index 35733ff684..af15c4d82f 100644 --- a/docs/kb/changetracker/configuration-and-setup/add-palo-alto-proxied-device.md +++ b/docs/kb/changetracker/configuration-and-setup/add-palo-alto-proxied-device.md @@ -76,7 +76,7 @@ Before adding the device in the console, complete the following on the Palo Alto ``` Replace `username` and `hostname` with the actual credential username and device hostname. -8. Configure the **Login Script** using the directives in [Step 4 — Configure the Login Script](#step-4-configure-the-login-script). +8. Configure the **Login Script** using the directives in [Step 4 — Configure the Login Script](#step-4--configure-the-login-script). 9. Click **Update** to save the credential, then click **Update** again on the proxied device to save the device. ### Step 4 — Configure the Login Script diff --git a/scripts/check-anchors.sh b/scripts/check-anchors.sh index c76102b09a..67ec31a6e2 100755 --- a/scripts/check-anchors.sh +++ b/scripts/check-anchors.sh @@ -38,13 +38,16 @@ slugify() { printf '%s' "${BASH_REMATCH[1]}" return fi + # Mirrors github-slugger's behavior (used by Docusaurus): each removed + # character leaves its surrounding whitespace intact, so runs of hyphens + # are NOT collapsed and leading/trailing hyphens are NOT trimmed. A + # heading like "Step 4 — Configure" (em dash stripped, two spaces + # remain) slugs to "step-4--configure", not "step-4-configure". printf '%s' "$heading" \ | sed -E 's/^#+ +//' \ | tr '[:upper:]' '[:lower:]' \ | sed -E "s/[^a-z0-9 -]//g" \ - | sed -E 's/ +/-/g' \ - | sed -E 's/-+/-/g' \ - | sed -E 's/^-+//;s/-+$//' + | sed -E 's/ /-/g' } load_headings() { From cf8bf4644e662250d3eb3142d101177f06c82ae4 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Tue, 4 Aug 2026 18:08:59 +0000 Subject: [PATCH 11/14] docs(changetracker): apply editorial review fixes - Lowercase 'Comparing Results' heading to sentence case for consistency with the surrounding headings on the page - Add an orienting sentence to the Compliance report templates intro so readers scanning the section know the tables catalog templates and supported platforms per compliance standard Co-Authored-By: Claude Opus 4.8 (1M context) --- docs/changetracker/compliance/compliance.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/docs/changetracker/compliance/compliance.md b/docs/changetracker/compliance/compliance.md index 55f9ed10bd..cd8d1efd7f 100644 --- a/docs/changetracker/compliance/compliance.md +++ b/docs/changetracker/compliance/compliance.md @@ -27,7 +27,7 @@ Review the following for additional information: - [Policy Tab](/docs/changetracker/compliance/compliancepolicy.md) - [Details Tab ](/docs/changetracker/compliance/compliancedetails.md) -## Comparing Results +## Comparing results When you select any two results, either for the same device or for two different devices, the **Compare Results** button becomes available. @@ -38,7 +38,8 @@ identify the configuration differences between two devices. ## Compliance report templates Netwrix Change Tracker scores devices against a hardened build standard using compliance report -templates. +templates. The tables below list the templates available for each compliance standard and the +platforms they support. :::info Only Center for Internet Security (CIS) benchmark reports ship bundled with the Hub Server From a9fd441be0a6f1fbc819cd8e187d58aff10eec33 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Tue, 4 Aug 2026 19:25:44 +0000 Subject: [PATCH 12/14] docs: apply fixes from PR review - Trim the CIS section intro so it no longer repeats the bundled-vs-download rule already stated in the download admonition - Note that template names (including the NNT prefix) appear exactly as shown in Change Tracker Co-Authored-By: Claude --- docs/changetracker/compliance/compliance.md | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/docs/changetracker/compliance/compliance.md b/docs/changetracker/compliance/compliance.md index cd8d1efd7f..c79ffb49ad 100644 --- a/docs/changetracker/compliance/compliance.md +++ b/docs/changetracker/compliance/compliance.md @@ -39,7 +39,8 @@ identify the configuration differences between two devices. Netwrix Change Tracker scores devices against a hardened build standard using compliance report templates. The tables below list the templates available for each compliance standard and the -platforms they support. +platforms they support. Template names appear exactly as shown in Change Tracker; the `NNT` prefix +(and the `Netwrix` prefix on some templates) is part of the name. :::info Only Center for Internet Security (CIS) benchmark reports ship bundled with the Hub Server @@ -75,10 +76,7 @@ Review the following for additional information: Change Tracker's CIS compliance reports map directly to the prescriptive configuration recommendations in the Center for Internet Security (CIS) [Benchmarks List](https://www.cisecurity.org/cis-benchmarks). Each Change Tracker compliance report -is [CIS approved](https://www.cisecurity.org/partner/netwrix), and every one ships bundled with the -Hub Server installer. Only a benchmark published after your installed version — for example, a -benchmark for a newly released operating system — requires a manual download and upload; the next -Change Tracker release bundles it automatically. +is [CIS approved](https://www.cisecurity.org/partner/netwrix). **CIS Version** is the template's own revision number. Netwrix tracks it internally and uses it to determine whether a newer template should overwrite an existing one during import. It's independent From b903c031dfd8d74b48c7d64538cdbe14a33d02a5 Mon Sep 17 00:00:00 2001 From: "claude[bot]" <41898282+claude[bot]@users.noreply.github.com> Date: Tue, 4 Aug 2026 19:28:06 +0000 Subject: [PATCH 13/14] fix(vale): auto-fix style issues (Vale + Dale) --- docs/changetracker/compliance/compliance.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/changetracker/compliance/compliance.md b/docs/changetracker/compliance/compliance.md index c79ffb49ad..02114a9944 100644 --- a/docs/changetracker/compliance/compliance.md +++ b/docs/changetracker/compliance/compliance.md @@ -38,7 +38,7 @@ identify the configuration differences between two devices. ## Compliance report templates Netwrix Change Tracker scores devices against a hardened build standard using compliance report -templates. The tables below list the templates available for each compliance standard and the +templates. The following tables list the templates available for each compliance standard and the platforms they support. Template names appear exactly as shown in Change Tracker; the `NNT` prefix (and the `Netwrix` prefix on some templates) is part of the name. From 609a79ec116df54daa67da1bc944e588537595d0 Mon Sep 17 00:00:00 2001 From: Tay Caliguiri Date: Tue, 4 Aug 2026 17:08:07 -0400 Subject: [PATCH 14/14] Document Entra Cloud Environment support in tenant configuration wizard (#1313) Adds the Cloud Environment selection step (Commercial, GCC High, DoD, China) to the Add Tenant Configuration wizard, matching the option introduced in build 3.1.5.30. --- .../3.1/admin/configuration/entraid.md | 36 +++++++++++++------ 1 file changed, 26 insertions(+), 10 deletions(-) diff --git a/docs/identityrecovery/3.1/admin/configuration/entraid.md b/docs/identityrecovery/3.1/admin/configuration/entraid.md index eb434e2dd5..711a37eeba 100644 --- a/docs/identityrecovery/3.1/admin/configuration/entraid.md +++ b/docs/identityrecovery/3.1/admin/configuration/entraid.md @@ -41,12 +41,28 @@ Tenant Configuration wizard. ![Add Tenant Configuration wizard - Entra Id page](/images/identityrecovery/3.1/product/configuration/entra_id/entra_id_configuration_page1.png) -**Step 2 –** Enter a tenant [example.tenant.com] in the Tenant field. +**Step 2 –** Select the Microsoft cloud environment for this tenant from the **Cloud Environment** +dropdown. The following options are available: -**Step 3 –** Enter the Client Id [CLIENTID] for backups, rollbacks, and +- Commercial (Global) – Standard Microsoft cloud. This is the default for most organizations. +- US Government (GCC High / L4) – Microsoft Azure Government cloud for US government agencies and + contractors at Impact Level 4. +- US Government DoD (L5) – Microsoft Azure Government DoD cloud for US Department of Defense + environments at Impact Level 5. +- China (21Vianet) – Microsoft Azure operated by 21Vianet for organizations in China. + +:::note +The cloud environment determines the authentication and Microsoft Graph endpoints used for all +backup, rollback, and recovery operations for this tenant. Select the environment that matches where +your Entra tenant is hosted before entering credentials. +::: + +**Step 3 –** Enter a tenant [example.tenant.com] in the Tenant field. + +**Step 4 –** Enter the Client Id [CLIENTID] for backups, rollbacks, and recoveries in the Client ID field. -**Step 4 –** Enter the secret for the application registration in the Secret field. +**Step 5 –** Enter the secret for the application registration in the Secret field. :::note The application registration must have the following Microsoft Graph access: @@ -75,17 +91,17 @@ The application registration must have the following Microsoft Graph access: ::: -**Step 5 –** Click **Next**. +**Step 6 –** Click **Next**. ![Add Tenant Configuration wizard - Backup Schedule page](/images/identityrecovery/3.1/product/configuration/entra_id/entra_id_configuration_page2.png) -**Step 6 –** Select the days of the week in the Run the backup on section to indicate when to run +**Step 7 –** Select the days of the week in the Run the backup on section to indicate when to run backups. -**Step 7 –** Select a start time (UTC) in the Start the backup at field to begin the backup. The +**Step 8 –** Select a start time (UTC) in the Start the backup at field to begin the backup. The default time is 12:00 AM. -**Step 8 –** In the Repeat every field, enter a frequency, in minutes, to set the time between the +**Step 9 –** In the Repeat every field, enter a frequency, in minutes, to set the time between the start of each domain backup. Consider the size of the environment when configuring this option. Click **Next**. @@ -97,18 +113,18 @@ time. ![Add Tenant Configuration wizard - Notifications page](/images/identityrecovery/3.1/product/configuration/entra_id/entra_id_configuration_page3.png) -**Step 9 –** To set notifications, select the Send email notifications checkbox and enter the +**Step 10 –** To set notifications, select the Send email notifications checkbox and enter the email address of one or more users and/or groups to receive the job start and end notifications. Use a semicolon (;) to separate multiple recipients. See the [Notifications Page](/docs/identityrecovery/3.1/admin/configuration/notifications.md) topic for additional information. If you don't want notifications, skip this step. -**Step 10 –** Click **Next**. +**Step 11 –** Click **Next**. ![Add Tenant Configuration wizard - Confirm page](/images/identityrecovery/3.1/product/configuration/entra_id/entra_id_configuration_page4.png) -**Step 11 –** The Confirm page displays a summary of the settings you provided on the pages of the +**Step 12 –** The Confirm page displays a summary of the settings you provided on the pages of the wizard. Use the Back button to return to a previous page and change any setting. Click **Done** to finish the wizard.