- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Checkpoint Hardening Benchmark
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint Hardening Benchmark
Hello,
Is there any standard Benchmark followed for hardening of Checkpoint Devices ? Like its there for Cisco - CIS 4.1.0
Thanks
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The CIS Community just published v1.1.0 based on R80.10. Look for it under Network Devices.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maybe you are interested in these documents: R77 Gaia Hardening Guide and sk106597: Best Practices - Rulebase Construction and Optimization
But in general, hardening is an ongoing process for CP GAiA OS and SW/HW products with Jumbo HFs playing a major role !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I looked for one this morning - the most up to date one I found was from 2007 https://www.cisecurity.org/wp-content/uploads/2017/04/CIS_Checkpoint_Benchmark_v1.0.pdf
Maybe it would be good to write a more up to date one?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are hardening guides available for latest versions, for example: https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80_30_Gaia_Hardening/Default.htm

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The CIS Community just published v1.1.0 based on R80.10. Look for it under Network Devices.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's a community effort so depends upon backing by community members. If we get more members in that group, then could probably be done. For anyone interested, there's a signup link on the CIS Benchmarks FAQ page.
This is also a route to download the current Check Point Benchmark. Notice the link isn't currently working......
"In order to download a CIS Benchmark from Workbench, you will need to join the CIS WorkBench community for that particular benchmark. To join a community, simply login to CIS WorkBench (registration is free), select the "Communities" tab on the top menu bar and select your community of interest. Upon navigating to the community dashboard, select "Join"."
