Policy Compliance Library Updates, July 2026

Vaishali Kulkarni

Qualys’ library of built-in policies makes it easy to comply with the widely adopted security standards and regulations. The platform offers a broad range of policies, including many that have been certified by the Center for Internet Security (CIS), as well as security guidelines and industry best practices from operating system and application vendors. 

Qualys’ Certification Page on the CIS website has also been updated.  

CIS Benchmark Policies

Center for Internet Security (CIS) Benchmark policies are technical guidelines for organizations to improve their cybersecurity posture by aligning with recommended secure configurations. By leveraging industry best practices, these guidelines help reduce the risk of cyberattacks, such as data breaches.

DISA STIG Policies

STIG stands for Security Technical Implementation Guide, which is a set of cybersecurity guidelines published by the Defense Information Systems Agency (DISA). These guidelines equip organizations with the necessary tools to adhere to rules, regulations, best practices, and federal laws, facilitating compliance and bolstering cybersecurity measures.

CIS STIG Policies

CIS STIG Benchmarks are secure configuration guidelines released by the Center for Internet Security (CIS) and derived directly from DISA Security Technical Implementation Guides (STIGs). They are functionally equivalent to DISA STIGs and differ only in formatting and presentation, not in security controls or remediation guidance.

Qualys Policies

Qualys oversees the discovery and resolution of technical issues while implementing robust policy frameworks. Researchers within Qualys actively identify cybersecurity misconfigurations and enact technical policies to fortify systems and safeguard against potential threats.

Safeguard Computer Security Evaluation Matrix (SCSEM)

It typically comprises a structured set of criteria, guidelines, and metrics designed to measure various aspects of security, such as confidentiality, integrity, availability, and compliance.

Compliance Standards

Compliance standards are regulatory frameworks that safeguard sensitive data and help ensure privacy and security. They offer guidelines and best practices for organizations to achieve compliance and mitigate risks in handling sensitive information.

New Policies/Mandates 

Listed below are the number of policies and mandates deployed in July 2026: 

CIS Benchmark Policies 6
DISA STIG Policy 6
CIS STIG Benchmark23
Industry Best Practices Policy 5
New Supported Mandates0
Deprecated Mandates0

Listed below are the newly published policies and mandates:  

CIS Benchmark Policies CIS Benchmark for IBM DB2 11.x, v1.2.0

CIS Benchmark for IBM DB2 12.1, v1.0.0

CIS Benchmark for Microsoft SQL Server 2022, v1.3.0

CIS Microsoft Windows Server 2019 Benchmark v5.0.0

CIS SUSE Linux Enterprise 16 Benchmark, v1.0.0

CIS Microsoft SQL Server 2019 Benchmark, v1.6.0
DISA STIG PoliciesDISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2022 DC, V2R8

DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2022 MS, V2R8

DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2019 DC, V3R8

DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2019 MS, V3R8

DISA MariaDB Enterprise 10.x STIG – Ver 2, Rel 5

DISA STIG for IIS 10.0 Site Ver 2, Rel5
CIS STIG BenchmarkCIS Benchmark for Oracle Linux 7 STIG, v1.0.0

CIS Benchmark for Cisco IOS XE Switch L2S STIG, v1.0.0

CIS Benchmark for Juniper Router RTR STIG, v1.0.0

CIS Benchmark for Juniper SRX SG NDM STIG, v1.0.0

CIS Benchmark for Cisco IOS XR Router RTR STIG, v1.0.0

CIS Benchmark for Microsoft Exchange 2016 Edge Transport Server STIG, v1.0.0

CIS Benchmark for Palo Alto Networks NDM STIG, v1.0.0

CIS Benchmark for Palo Alto Networks IDPS STIG, v1.0.0

CIS Benchmark for Palo Alto Networks ALG STIG, v1.0.0

CIS Benchmark for Cisco IOS XE Switch NDM STIG, v1.1.0

CIS Benchmark for Cisco IOS XE Router NDM STIG, v1.0.0

CIS Benchmark for Cisco IOS XE Switch RTR STIG, v1.1.0

CIS Benchmark for Red Hat Enterprise Linux 10 STIG, v1.0.0

CIS Benchmark for Microsoft SQL Server 2022 Instance STIG, v1.0.0

CIS Microsoft Windows Server 2016 STIG Benchmark, v4.0.0

CIS Juniper Router NDM STIG Benchmark, v1.0.0

CIS Kubernetes STIG Benchmark, v1.1.0

CIS Cisco IOS XR Router NDM STIG Benchmark, v1.1.0

CIS Cisco IOS XE Router RTR STIG Benchmark, v1.1.0

CIS Amazon Linux 2023 STIG Benchmark, v1.0.0

CIS MariaDB Enterprise 10.x STIG Benchmark, v1.1.0

CIS Cisco NX OS Switch RTR STIG Benchmark, v1.1.0

CIS Cisco NX OS Switch NDM STIG Benchmark, v1.1.0
Industry and Best Practices Policies Security Configuration and Compliance Policy for FreeBSD 15.x

Security Configuration and Compliance Policy for Verint Financial Compliance

Security Configuration & Compliance Policy for Extreme Networks VOSS 9.x (OCA)

Security Configuration and Compliance Policy for Skype for Business Server 2015

Security Configuration and Compliance Policy for Tomcat v11 for Windows
New Supported MandatesNA
Deprecated mandatesNA

Policy Updates 

We have updated your Policy Library. The following policies and mandates have been re-released as part of our customer CRM.

Policy Update  
CIS IBM AIX 7 Benchmark, v1.1.0Re-release for CIS IBM AIX 7 Benchmark, v1.1.0, to update the regular expression for the CID 16681 and 1128.
CIS Benchmark for Red Hat Enterprise Linux 8, v4.0.0Re-release for CIS Benchmark for Red Hat Enterprise Linux 8, v4.0.0, to update the regular expression for the CID 10866.
CIS Benchmark for Ubuntu Linux 20.04 LTS, v3.0.0Re-release for CIS Benchmark for Ubuntu Linux 20.04 LTS, v3.0.0, to update the regular expression for the CID 19619 and 22262.
CIS Benchmark for Rocky Linux 8, v3.0.0Re-release for CIS Benchmark for Rocky Linux 8, v3.0.0, to update the regular expression for the CID 28649.
CIS Benchmark for Oracle Linux 8, v4.0.0Re-release for CIS Benchmark for Oracle Linux 8, v4.0.0, to replace CID 30325 with CID 31640.
CIS Benchmark for Red Hat Enterprise Linux 10, v1.0.1Re-release for CIS Benchmark for Red Hat Enterprise Linux 10, v1.0.1, to update the regular expression for the CID 29388, 10666, and CID 29387.
CIS Benchmark for SUSE Linux Enterprise 15.x, v2.0.1Re-release for CIS Benchmark for SUSE Linux Enterprise 15.x, v2.0.1, to add CID 9339 and CID 9340 in the policy.
CIS Benchmark for PostgreSQL 17, v1.0.0Re-release for CIS Benchmark for PostgreSQL 17, v1.0.0, to correct the reference for CID 27414.
DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 9, V2R7 Re-release for DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 9, V2R7, to add the CID 32393 and 32394.
CIS Ubuntu Linux 24 v1.0.0Re-release for CIS Ubuntu Linux 24 v1.0.0, to update the regular expression for CID 17154 and CID 17155.
CIS Red Hat Enterprise Linux 10 v1.0.1  Re-release for CIS Red Hat Enterprise Linux 10 v1.0.1, to update the regular expression for CID 29387.
Red Hat Enterprise Linux 10Re-release for Red Hat Enterprise Linux 10, to update the cover page of the policy
Red Hat Enterprise Linux 9Re-release for Red Hat Enterprise Linux 9, to update the cover page of the policy
Red Hat Enterprise Linux 8Re-release for Red Hat Enterprise Linux 8, to update the cover page of the policy
Rocky Linux 9Re-release for Rocky Linux 9, to update the cover page of the policy
CIS Benchmark for Amazon Linux 2023, v1.0.0Re-release for CIS Benchmark for Amazon Linux 2023, v1.0.0, to tick the NL Value for the CID 9985
CIS Benchmark for Microsoft Defender Antivirus, v1.0.0Re-release for CIS Benchmark for Microsoft Defender Antivirus, v1.0.0, to remove the technologies from policies.
CIS Benchmark for Oracle Database 19c, v2.0.0  Re-release for CIS Benchmark for Oracle Database 19c, v2.0.0, to change the regular expression for 30390
CIS Benchmark for Red Hat Enterprise Linux 7 v4.0.0Re-release for CIS Benchmark for Red Hat Enterprise Linux 7 v4.0.0, to add CID 29216
CIS Benchmark for PostgreSQL 12, v1.1.0Re-release for CIS Benchmark for PostgreSQL 12, v1.1.0, to make the correction in the CID 27414, 14175
CIS Benchmark for PostgreSQL 13, v1.3.0Re-release for CIS Benchmark for PostgreSQL 13, v1.3.0, to make the correction in the CID 27414, 14175
CIS Benchmark for PostgreSQL 14, v1.3.0Re-release for CIS Benchmark for PostgreSQL 14, v1.3.0, to make the correction in the CID 27414, 14175
CIS Benchmark for PostgreSQL 15, v1.2.0Re-release for CIS Benchmark for PostgreSQL 15, v1.2.0, to make the correction in the CID 27414, 14175
CIS Benchmark for PostgreSQL 16, v1.1.0Re-release for CIS Benchmark for PostgreSQL 16, v1.1.0, to make the correction in the CID 27414, 14175
CIS Benchmark for PostgreSQL 17, v1.0.0Re-release for CIS Benchmark for PostgreSQL 17, v1.0.0, to make the correction in the CID 27414, 14175
CIS Benchmark for Oracle MySQL Enterprise Edition 8.4, v1.1.0Re-release for CIS Benchmark for Oracle MySQL Enterprise Edition 8.4, v1.1.0, to change the regular expression for CID 9413
CIS Benchmark for Oracle MySQL Community Server 8.4, v1.1.0Re-release for CIS Benchmark for Oracle MySQL Community Server 8.4, v1.1.0, to change the regular expression for CID 9413
CIS Benchmark for AIX 7 v1.1.0  CIS Benchmark for AIX 7 v1.1.0, to correct the regular expression in the policy for the CID 3957


Updates to the Fixed Values Checkbox Controls

The following controls have been updated for ‘Fixed Values’ checkbox.

ControlsDescription
27004, 27006, 27007, 9924, 6918, 7389, 8261, 11272, 11344, 11491, 27898, 14432, 27899, 6920, 27012, 11488, 11489, 11490, 16340, 16363, 16367, 27014, 27015, 26646, 27013, 11346, 18976, 9908Added ‘Not Applicable (Instance-Level Database)‘ fixed value for MS SQL Server.

This allows customers to enable and pass control when a setting is intentionally not evaluated at the instance-level database. This occurs when the setting is not applicable at that level.
29169Adding Auto download, Notify for install and Notify for restart’ fixed value for Windows server.

This allows customers to enable and pass the control when the system is configured to automatically download updates.
11212Adding ‘Not Configured / Key Not Found’ fixed value for Windows & Windows Server.

This allows customers to enable and pass the control when the corresponding registry key does not exist.

Deprecated Policies

  • CIS Microsoft SQL Server 2022 Benchmark, v1.2.0
  • DISA STIG for Microsoft Windows Server 2022 DC,V2R7
  • DISA STIG for Microsoft Windows Server 2022 MS,V2R7
  • CIS Benchmark for IBM DB2 11.x, v1.1.0
  • CIS Benchmark for Microsoft Windows Server 2019, v4.0.0
  • DISA Security Technical Implementation Guide (STIG) for IIS 10 Site, V2R15
  • CIS Benchmark for MariaDB Enterprise 10.x STIG, v1.0.0 [Manual]
  • CIS Benchmark for Microsoft SQL Server 2019, v1.6.0
  • DISA Security Technical Implementation Guide (STIG) for MariaDB Enterprise 10.x, V2R4

Proposed Upcoming Policies

  We plan to release the following policies and updates next month:

  • DISA Security Technical Implementation Guide (STIG) for IBM WebSphere Traditional V9.x, V2R1
  • CIS Red Hat Enterprise Linux 8 STIG Benchmark, v2.0.0
  • CIS SUSE Linux Enterprise Server 15 STIG Benchmark, v1.0.0
  • CIS Oracle Linux 8 STIG Benchmark, v1.0.0
  • CIS Solaris 11 SPARC STIG Benchmark, v1.0.0
  • CIS Apple macOS 15 (Sequoia) STIG Benchmark, v1.0.0
  • CIS Solaris 11 X86 STIG Benchmark, v1.0.0
  • CIS IBM z/OS RACF STIG Benchmark, v1.0.0
  • DISA STIG BIND 9.x – Ver 3, Rel 1
  • CIS Wind River eLxr 12 Benchmark, v1.1.0
  • CIS IBM AIX 7 Benchmark v1.2.0
  • DISA STIG Red Hat Enterprise Linux 9 STIG – Ver 2, Rel 9
  • MacOS – DISA Security Technical Implementation Guide (STIG) for Mozilla FireFox, V6R7
  • DISA Security Technical Implementation Guide (STIG) for Apple macOS 26 (Tahoe) STIG – Ver 1, Rel 2
  • DISA Security Technical Implementation Guide (STIG) for Cloud Linux AlmaLinux OS 9 STIG – Ver 1, Rel 5
  • DISA Security Technical Implementation Guide (STIG) for Oracle Linux 9 STIG – Ver 1, Rel 4
  • CIS Amazon Linux 2 Benchmark, v4.0.0
  • CIS Benchmark for Microsoft Intune Office Enterprise v1.1.0
  • CIS Debian Linux 12 Benchmark, v2.0.0
  • CIS Ubuntu Linux 24.04 LTS Benchmark, v2.0.0
  • CIS Apache Tomcat Application Server 9 STIG Benchmark, v1.0.0
  • CIS Apple macOS 14.0 Sonoma Benchmark, v3.1.0
  • CIS Apple macOS 26 Tahoe Benchmark, v1.1.0
  • CIS Apple macOS 15.0 Sequoia Benchmark, v2.1.0
  • DISA STIG for Microsoft Windows 11 – Ver 2, Rel 8
  • DISA STIG for Red Hat Enterprise Linux 7 – Ver 3, Rel 15
  • CIS Microsoft Intune for Windows 11 Benchmark, v5.0.0
  • CIS Microsoft Intune for Windows 10 Benchmark, v5.0.0
  • CIS Google Chrome Group Policy Benchmark, v1.0.0
  • CIS Cloud Linux AlmaLinux OS 9 STIG Benchmark, v1.0.0
  • CIS Apple macOS 26 Tahoe STIG Benchmark, v1.0.0
  • Security Configuration and Compliance Policy for OpenSuSE 16
  • DISA STIG Amazon Linux 2023 STIG – Ver 1, Rel 4

Learn More 

Discover how Qualys Enterprise TruRiskTM Platform can help you reduce cyber risk and improve business outcomes through precise remediation activities. Learn more about it here

Additional Information 

Feel free to contact your Technical Account Manager (TAM) or Qualys Technical Support if you have any questions. 

What’s More:

  • Find all policy library updates here
  • Check out Qualys’ updated Certification Page at CIS here.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *