Created on
03-11-2025
01:58 AM
Edited on
07-15-2025
01:13 AM
By
Anthony_E
Description | This article describes checking the CISecurity site for the CIS Benchmark for FortiGate. |
Scope | Above FortiGate v7.4.x. |
Solution | It is recommended to check the CISecurity site for the CIS Benchmark for Fortinet, as it includes all the necessary settings and recommendations to maintain compliance. A free account with CIS is required to access the PDFs.
In this case, it is advisable to download and review the CIS FortiGate v7.0.x Benchmark v1.3.0. This version was created for v7.2.6, as stated in the document's Overview on Page 6: This document provides prescriptive guidance for establishing a secure configuration posture for Fortinet FortiGate devices running v7.2.0 or above. The guide was tested against v7.2.6.
Alternatively, the older CIS FortiGate v7.0.x Benchmark v1.2.0 could be used, as it was written and was tested with v7.0.10. v7.0 will reach full End of Support on 2025-09-30. It is advisable to plan for an upgrade to v7.2 or later.
The oldest CIS FortiGate Benchmark v1.1.0 was written and tested with v6.4. As v6.4 reached End of Engineering Support on 2023-03-31 and full End of Support on 2024-09-30, meaning no further support will be provided by the Fortinet development team. As a final note, v7.4.1 updates the Security Rating licensed service to check the FortiGate against CIS Compliance standards: Support CIS compliance standards within security ratings 7.4.1. An automatic scoring is performed against the device configuration with the defined CIS standards, resulting in passed/failed results. However, the device would need an active internet connection to perform the compliance checks. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.