CIS: Windows Server 2022


This topic provides information about the hotfix containing Windows Server 2022  Security Configuration Benchmark Version 3.0.0. This template contains implementation for 444 rules that that can be installed on TrueSight Server Automation 24.4.

Determine whether you need to install the template

If you are installing TrueSight Server Automation version 24.4 for the first time (fresh installation), no action is required because this template is installed as a part of the 24.4 installation process.

If you have upgraded to 24.4 or later, this template is not installed automatically. To install this template, do one of the following actions:

  • Perform the steps mentioned in this topic.
    Through this method, the CIS template for Windows Server 2022 is installed.
  • Upgrade the compliance content by using one of the following methods:

    Important

    Rename any existing customized template before you run the Auto Content Import Job or install the template manually. 

    • Through the Auto Content Import Job after the upgrade. During the Application Server upgrade, the Network Shell script of this job is updated. After you upgrade TrueSight Server Automation, execute this job to obtain the latest compliance content.
      Through this method, the latest version of all the templates that are available in version 24.4 are installed. For the complete list of supported templates and their versions, see Compliance-Content-support-and-requirements.
    • Install manually by using the content installer. Ensure that you use the content installer of the same version as the Application Server version. For information about how to install the compliance content manually, see Walkthrough-Loading-compliance-content
      When you use this method, you have the flexibility to choose the template that you want to install from the set of templates that are available in version 24.4.

Before you begin

Before you install this hotfix, make sure that you perform the following:

  • Some policy settings require the installation of the SecGuide custom templates. The SecGuide.admx and SecGuide.adml (These files can be downloaded from Microsoft site) must be copied to the Target Machine at \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
  • Some policy settings require the installation of the MSS-Legacy custom templates. The MSS-Legacy.admx and MSS-Legacy.adml (These files can be downloaded from Microsoft site) must be copied to the Target Machine at \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
  • Save a backup of the extended_objects folder, which is at the following location on the file server:
    <File_Server_Root>/extended_objects/
  • If existing template is customized, make sure to rename it before importing new one and then perform the steps mentioned in the following sections.
  • Make sure to review the template's local and global properties default values to match with the organization standards.

Step 1: Downloading and installing the files

  1. Download the CIS - Windows Server 2022 package from the EPD location by following these steps:
    1. Login to BMC EPD Website.
    2. Navigate to Additional Products tab, under ‘View By Category’, select Server Automation.
    3. Navigate to:
      1. TrueSight Server Automation > TrueSight Server Automation 24.2.0.0 or
      2. Navigate to TrueSight Server Automation Compliance Module > TrueSight Server Automation Compliance Module 24.2.0.0.
    4. Download the TSSA 24.2.00 CIS Updates for Windows Server 2022.

      The downloaded file includes the following:

      1. CIS - Windows Server 2022.zip
      2. CIS_Microsoft_Windows_Server_2022_Benchmark_v3.0.0.pdf
      3. RELEASE_NOTES_FOR_HOTFIX_OF_CIS_WINDOWS_2022.docx
      Click here to expand checksum related infromation

      Verify the downloaded content by using the following check sums.

      S.No

      File Name

      MD5SUM

      1

      CIS - Windows Server 2022.zip

      fde469942984a6ceb4d7cd613c89bfb0

      The Extended Object zip file is not provided purposely as there is no change in it.

      Important

      For TSSA versions 24.2 and below, the security setting of the rule (1.2.3 Ensure Allow Administrator account lockout is set to Enabled (MS only) is not available, hence compliance check needs to be evaluated manually.

  2. Move the CIS - Windows Server 2022 package to your RCP client server.

Important

The extended object zip file has been intentionally excluded as there are no modifications or updates to it.

Step 3: Importing the Compliance Content

  1. Log on the Console.
  2. Right-click on Component Templates and click Import.
    cis1.png 
  3. Select the Import (Version-neutral) option and click OK.
    cis2.png
  4. Select the updated CIS - Windows Server 2022.zip package from the temporary location.
    The CIS template for CIS - Windows Server 2022 is available in the CIS - Windows Server 2022.zip package. To import the templates, select the CIS - Windows Server 2022.zip and click Next
    cis3.png
  5. Ensure that you select the Use existing objects and Preserve template group path options and click Next.
    cis4.png
  6. Navigate to the last screen of the wizard and click Finish.

    cis5.png

  7. Click OK The templates are imported successfully and are shown under CIS Compliance Content > CIS.
    cis6.png

Summary

Additional Information: The hotfix is containing Center for Internet Security (CIS) template for CIS - Windows Server 2022, with implementation for 444 rules that can be installed on TrueSight Server Automation 24.2. This template is created based on the recommended settings defined by CIS Microsoft Windows Server 2022 Benchmark Version 3.0.0, published on March 19, 2024.

The template contains 444 rules.

Rules within the template

The following are the details of the 444 rules provided in the zip package. It contains the following types of rules:

  • Rules that check for compliance(audit) and provides remediation = 423
  • Rules that check for compliance(audit) but do not provide remediation = 20
  • Rules that do not check for compliance and do not provide remediation = 1

The following are the details of the rules that are divided into parts:

  • Rules not divided into parts = 421
  • Rules divided into two parts (5 Rules) so (5* 2) = 10
  • Rules divided into four parts (2 Rules) so (2 * 4) = 8
  • Rules divided into five parts (1 Rule) so (1 * 5) = 5

So, the current rule count according to CIS – Windows Server 2022 template after running the compliance job is 444(421+10+8+5).


Important

Make sure that you have gone through the following points before you run the compliance checks or perform remediation:

  • While running compliance jobs on domain controller targets, set the target server's DOMAIN property to DC.
  • Leave DOMAIN property blank for member servers and standalone systems.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*