Skip to content

CIS Benchmarks: Update Windows 10 to v4.0.0 #35118

Description

@noahtalerman

Goal

User story
As an endpoint engineer,
I want Fleet to support the latest Windows 10 CIS Benchmarks (v.4.0.0)
so that I can be sure I'm using the latest version of the benchmarks to meet compliance needs.

Roadmap item

None. Fleet is committed to maintaining CIS Benchmarks for Windows workstations.

Original requests

None.

Resources

None.

Changes

Product

  • CIS policies changes: Update Windows 10 to cover v4.0.0.
  • UI changes: No changes.
  • CLI (fleetctl) usage changes: No changes.
  • YAML changes: No changes.
  • REST API changes: No changes.
  • Fleet's agent (fleetd) changes: No changes.
  • GitOps mode changes: No changes.
  • Activity changes: No changes.
  • Permissions changes: No changes.
  • Changes to paid features or tiers: Fleet Premium
  • Transparency changes: No changes.
  • First draft of test plan added
  • Other reference documentation changes: Already applied to main
  • Once shipped, requester has been notified
  • Once shipped, dogfooding issue has been filed

Engineering

  • Test plan is finalized

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

QA

Risk assessment

  • Requires load testing: No
  • Risk level: Low
  • Risk description: Risk is limited to the modified queries.

Test plan

Make sure to go through the list and consider all events that might be related to this story, so we catch edge cases earlier.

  • Open the PR that updated the CIS policies for Windows 10. For every policy that changed, run this policy on a Windows workstation and verify that the policy passes and fails when expected.
  • Create and link an Google sheet here of all changed and tested benchmarks.

Testing notes

Confirmation

  1. Engineer: Added comment to user story confirming successful completion of test plan.
  2. QA: Added comment to user story confirming successful completion of test plan.

Metadata

Metadata

Labels

#g-supply-chainSupply Chain product groupstoryA user story defining an entire feature~contextFeature that customers consider mission critical for their particular buying situation.

Type

No type

Projects

Status
No status
Status
✔️Awaiting QA

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions