Summary
The end goal of everything we've discussed – the regulatory frameworks, the critical controls, and the security benchmarks – is to make it easier to better secure your hosts and data centers. The key in each of these guidance constructs is to give you enough direction to get you where you need to go, without having to be a security expert. Each in turn gets more and more specific. The regulatory frameworks are generally very broad, leaving a fair amount of discretion in how things are accomplished. The critical controls are more specific, but still allow a fair amount of leeway in what solutions are deployed and how the end goal is accomplished. The CIS benchmarks are very specific, giving you the exact commands and configuration changes needed to accomplish your goal.
I hope that with the journey we've taken in this chapter, you have a good idea of how these various sets of guidance approaches can be combined in your organization to better secure...