FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mhemambika
Staff
Staff
Article Id 381539
Description This article describes checking the CISecurity site for the CIS Benchmark for FortiGate.
Scope Above FortiGate v7.4.x.
Solution It is recommended to check the CISecurity site for the CIS Benchmark for Fortinet, as it includes all the necessary settings and recommendations to maintain compliance. A free account with CIS is required to access the PDFs.

 

In this case, it is advisable to download and review the CIS FortiGate v7.0.x Benchmark v1.3.0. This version was created for v7.2.6, as stated in the document's Overview on Page 6:

This document provides prescriptive guidance for establishing a secure configuration posture for Fortinet FortiGate devices running  v7.2.0 or above. The guide was tested against v7.2.6.

 

Alternatively, the older CIS FortiGate v7.0.x Benchmark v1.2.0 could be used, as it was written and was tested with v7.0.10. v7.0 will reach full End of Support on 2025-09-30. It is advisable to plan for an upgrade to v7.2 or later.

 

The oldest CIS FortiGate Benchmark v1.1.0 was written and tested with v6.4. As v6.4 reached End of Engineering Support on 2023-03-31 and full End of Support on 2024-09-30, meaning no further support will be provided by the Fortinet development team.

As a final note, v7.4.1 updates the Security Rating licensed service to check the FortiGate against CIS Compliance standards: Support CIS compliance standards within security ratings 7.4.1. An automatic scoring is performed against the device configuration with the defined CIS standards, resulting in passed/failed results. However, the device would need an active internet connection to perform the compliance checks.