Consulting/Auditing Use of CIS Security Resources

Overview

The CIS Security Benchmarks Division’s Consulting/Auditing Use Agreement enables IT security consultants and auditors to use the Benchmarks, Metrics, and Configuration Assessment Tools on behalf of multiple security consulting, auditing, and managed IT services clients.


The Consulting/Auditing Agreement allows IT security consultants and auditors to help their clients:

  • Assess their systems’ security configuration settings.
  • Compare their security configuration settings to the Security Benchmarks' recommendations.
  • Establish a baseline for setting performance goals.
  • Develop customized configuration policies and processes that are based on the Security Benchmarks and Metrics.
  • Measure system configuration improvement.
  • Monitor system configuration compliance over time.
  • Report security configuration compliance status to customers, auditors, and business partners.
  • Back to Top

    Why Does the CIS Security Benchmarks Division Offer a Consulting/Auditing Use Agreement?

    The CIS Security Benchmarks Division meets the needs of IT consultants and auditors to bring best practices and tools to multiple client organizations without requiring that the client organizations take any special steps, such as licensing materials directly from the CIS Security Benchmarks Division.

     

    Please note that the CIS Security Benchmarks Terms of Use prohibits the public from redistributing the Division’s resources and from using them for commercial purposes.  Also, this is to ensure that end users are always working with the latest versions of the CIS Security Benchmarks Division's resources that have been developed through the CIS consensus process. 

    Back to Top

    Membership Options and How to Obtain a Consulting/Auditing Use Agreement?

    Organizations and individuals may sign an agreement to use the CIS Security Benchmarks Division's resources in consulting and/or auditing engagements.  There are two membership agreement options: (1) one for all consultants/auditors employed by a company; and (2) one for specific individual consultant(s)/auditor(s). 

    Company-wide Consulting/Auditing (Annual Membership Fee - $14,000) Enroll Now

    Organizations may enroll as a Security Benchmarks Consulting/Auditing Member, which entitles an unlimited number of employees within the organization to use the Security Benchmarks Division's resources in an unlimited number of consulting/auditing and/or managed IT services engagements.  The term of the membership and the consulting/auditing use agreement is one year from the date of execution.  An Organizational Consulting/Auditing Membership also entitles the company to additional significant benefits described on the Membership page.

    Individual Consultants/Auditors (Annual Membership Fee - $3,000 per named consultant) Enroll Now

    Individual Consultants/Auditors can sign an agreement to use the CIS Security Benchmarks Division's resources in an unlimited number of consulting/auditing and/or security service engagements. The term of the agreement is one year from the date of execution.  This membership agreement is offered to individuals working in consulting/audit companies, as well as to self-employed consultants/auditors.  Procurement of the Named Consultant Agreement also entitles the named consultants/auditors to use the resources to secure the organizations internal systems. This right and use of the resources internally only applies to the named consultants/auditors.

     

    Each company or individual must:   

  • Agree to the terms and conditions of the CIS Security Benchmarks' Consulting/Distribution Agreement; and
  • Keep the Security Benchmarks Division membership outreach and support staff updated with accurate contact and business profile information.  By continually providing the Security Benchmarks Division with updated information, you will help ensure that appropriate referrals are provided to your organization.

  • To learn more about the Consulting Use/Auditing Membership Agreement, please contact us.

     

    CIS-CAT Consulting Engagement Membership (30-day CIS-CAT Use - $495) Enroll Now

    This membership allows a single named IT security consultant or auditor to use the CIS Configuration Assessment Tool (CIS-CAT) in support of one or more security consulting, auditing, and managed IT services clients for a 30-day time period.  This membership is for consulting/auditing engagements on client system(s) only and not authorized for internal use within the consultant/auditor's organization. Learn more about this membership.  

    Back to Top

    CIS Security Benchmarks and IT Consultants/Auditors

    The CIS Security Benchmarks Division does not directly provide consulting and auditing services to end user organizations. Consulting/Auditing Use Members are independent of the division’s resources and are not agents of, partners with, nor part of any joint-venture relationship with the CIS Security Benchmarks Division.

    Back to Top

    Who's Already Using the CIS Security Benchmarks Consulting/Auditing Membership Agreement?

    The leading IT consulting groups and individual consultants below have obtained CIS Security Benchmarks Consulting/Auditing Membership in order to better serve their clients.

    Organizations with Consulting/Auditing Memberships:

  • Diebold
  • HP Technology Solutions Group - Consulting and Integration Organization
  • Leviathan Security Group
  • Lockheed Martin
  • MorphoTrust USA
  • Qualys

  • Individuals with Consulting/Auditing Memberships:

  • Barry Anderson, C61 Pty. Ltd.
  • Per Brax, Brax Consulting AB
  • Drew Buhr, MNP LLP
  • Dan Didier, NetSecureIA
  • Ralph Durkee, Durkee Consulting, Inc.
  • Justin Hall, CBTS
  • Patrick Harbauer, Neohapsis, Inc.
  • Jessica Katz, M.A. Polce Consulting, Inc.
  • George Manso, Fotis Networks
  • Craig Moir, MyDBA
  • Mikko Niemela, Silverskin Information Security
  • Dmytro Petrashchuk, BMS Consulting
  • Jayen Purohit, Combitech AB
  • WidePoint Solutions Corporation
  • e-Cop Pte Ltd, Cecil Su
  • Back to Top

    Learn More

    For more information about the CIS Security Benchmarks Division and the commercial use of the CIS Security Benchmarks Division's resources, please contact us.

    Back to Top


    Enroll Now