Policy Compliance Library Updates, August 2026
Qualys’ library of built-in policies makes it easy to comply with the widely adopted security standards and regulations. The platform offers a broad range of policies, including many that have been certified by the Center for Internet Security (CIS), as well as security guidelines and industry best practices from operating system and application vendors.
Qualys’ Certification Page on the CIS website has also been updated.
CIS Benchmark Policies
Center for Internet Security (CIS) Benchmark policies are technical guidelines for organizations to improve their cybersecurity posture by aligning with recommended secure configurations. By leveraging industry best practices, these guidelines help reduce the risk of cyberattacks, such as data breaches.
DISA STIG Policies
STIG stands for Security Technical Implementation Guide, which is a set of cybersecurity guidelines published by the Defense Information Systems Agency (DISA). These guidelines equip organizations with the necessary tools to adhere to rules, regulations, best practices, and federal laws, facilitating compliance and bolstering cybersecurity measures.
CIS STIG Policies
CIS STIG Benchmarks are secure configuration guidelines released by the Center for Internet Security (CIS) and derived directly from DISA Security Technical Implementation Guides (STIGs). They are functionally equivalent to DISA STIGs and differ only in formatting and presentation, not in security controls or remediation guidance.
Qualys Policies
Qualys oversees the discovery and resolution of technical issues while implementing robust policy frameworks. Researchers within Qualys actively identify cybersecurity misconfiguration and enact technical policies to fortify systems and safeguard against potential threats.
Safeguard Computer Security Evaluation Matrix (SCSEM)
It typically comprises a structured set of criteria, guidelines, and metrics designed to measure various aspects of security, such as confidentiality, integrity, availability, and compliance.
Compliance Standards
Compliance standards are regulatory frameworks that safeguard sensitive data and help ensure privacy and security. They offer guidelines and best practices for organizations to achieve compliance and mitigate risks in handling sensitive information.
New Policies/Mandates
Listed below are the number of policies and mandates deployed in August 2026:
| CIS Benchmark Policies | 10 |
| DISA STIG Policy | 6 |
| CIS STIG Benchmark | 2 |
| Industry Best Practices Policy | 5 |
| New Supported Mandates | 0 |
| Deprecated Mandates | 0 |
Listed below are the newly published policies and mandates:
| CIS Benchmark Policies | CIS Benchmark for Microsoft Windows Server 2025, v2.0.0, Next-generation Windows Security Profile Policy CIS Benchmark for Microsoft Windows Server 2025 Stand-alone, v1.0.0, Next-generation Windows Security Profile Policy CIS Benchmark for Microsoft Windows Server 2022, v5.0.0, Next-generation Windows Security Profile Policy CIS Benchmark for Microsoft Windows Server 2022 Stand-alone, v2.0.0, Next-generation Windows Security Profile Policy CIS Microsoft SQL Server 2025 Benchmark, v1.0.0 Note: Application Version 10.39.3.0 or later is required to generate scan results. CIS Amazon Linux 2 Benchmark, v4.0.0 CIS Microsoft Intune for Windows 11 Benchmark, v5.0.0 CIS Microsoft Intune for Windows 10 Benchmark, v5.0.0 CIS Microsoft Windows 11 Enterprise Benchmark, v5.1.0 CIS Microsoft Windows Server 2022 Benchmark, v5.1.0 |
| DISA STIG Policies | DISA Security Technical Implementation Guide (STIG) for Microsoft Windows 11, V2R8 DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2019 DC, V3R8 DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2019 MS, V3R8 DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 8, V2R8 DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 9, V2R9 DISA Security Technical Implementation Guide (STIG) for Amazon Linux 2023, V1R4 |
| CIS STIG Benchmark | CIS Benchmark for Apache Tomcat Application Server 9 STIG, v1.0.0 CIS Benchmark for IBM z/OS Security Server RACF STIG, v1.0.0 |
| Industry and Best Practices Policies | Security Configuration and Compliance Policy for OpenSuSE 16 Safeguard Computer Security Evaluation Matrix for Apache Tomcat 9.x Safeguard Computer Security Evaluation Matrix for Apache Tomcat 10.x Safeguard Computer Security Evaluation Matrix for MS IIS 10.x Safeguard Computer Security Evaluation Matrix for Oracle Enterprise Linux 9 |
| New Supported Mandates | NA |
| Deprecated mandates | NA |
Policy Updates
We have updated your Policy Library. The following policies and mandates have been re-released as part of our customer CRM.
| Policy | Update |
| CIS Benchmark for IBM DB2 11.x, v1.2.0 | Re-release for CIS Benchmark for IBM DB2 11.x, v1.2.0, to add Control 10186 and map it to control reference 8.1.7 (SVCENAME). |
| CIS Benchmark for IBM DB2 12.1, v1.0.0 | Re-release for CIS Benchmark for IBM DB2 12.1, v1.0.0, to add Control 10186 and map it to control reference 8.1.7 (SVCENAME). |
| CIS Benchmark for Bottlerocket Benchmark, v1.0.0 | Re-release for CIS Benchmark for Bottlerocket Benchmark, v1.0.0, to update the regular expression for the CID 14401 and CID 14402. |
| CIS Benchmark for Red Hat Enterprise Linux 9, v2.0.0 | Re-release for CIS Benchmark for Red Hat Enterprise Linux 9, v2.0.0, to enable the NL (No List) value for the CIDs 29162, 29164, and 29165. |
| Security Configuration and Compliance Policy for Verint Financial Compliance | Re-release for Security Configuration and Compliance Policy for Verint Financial Compliance, to add the NL Value 3 for the CID 26979 (SNMP Version 3). |
| CIS Benchmark for Alma Linux OS 9, v2.0.0 | Re-release for CIS Benchmark for Alma Linux OS 9, v2.0.0, to update the cover page of the policy. |
| CIS Benchmark for Oracle Linux 8, v4.0.0 | Re-release for CIS Benchmark for Oracle Linux 8, v4.0.0, to update the cover page of the policy. |
| CIS Benchmark for Oracle Linux 7, v4.0.0 | Re-release for CIS Benchmark for Oracle Linux 7, v4.0.0, to update the cover page of the policy. |
| CIS Benchmark for Rocky Linux 8, v3.0.0 | Re-release for Rocky Linux 8, to update the cover page of the policy. |
| CIS Benchmark for Microsoft Windows Server 2019, v5.0.0 | Re-release for CIS Benchmark for Microsoft Windows Server 2019, v5.0.0, to change the control reference numbers for CID 8249, CID 8250, CID 8252, and CID 8253. |
| CIS Benchmark for IBM z/OS with RACF, v1.0.0 | Re-release for CIS Benchmark for IBM z/OS with RACF, v1.0.0, to add support for the ‘IBM z/OS RACF 3.x’ technology. |
| CIS Benchmark for Ubuntu Linux 16.04 LTS, v2.0.0 | Re-release for CIS Benchmark for Ubuntu Linux 16.04 LTS, v2.0.0, to update the cardinality for the CID 13376. |
| Oracle Enterprise Linux 10 | Re-release for Oracle Enterprise Linux 10, to update the cover page of the policy. |
| Oracle Enterprise Linux 9 | Re-release for Oracle Enterprise Linux 9, to update the cover page of the policy. |
| Amazon Linux 2023 | Re-release for Amazon Linux 2023, to update the cover page of the policy. |
| Rocky Linux 10 | Re-release for Rocky Linux 10, to update the cover page of the policy. |
| AlmaLinux 10 | Re-release for AlmaLinux 10, to update the cover page of the policy. |
| SUSE Linux Enterprise Server 12 | Re-release for SUSE Linux Enterprise Server 12, to update the cover page of the policy. |
| Ubuntu Linux 24 | Re-release for Ubuntu Linux 24, to update the cover page of the policy. |
| Ubuntu Linux 22 | Re-release for Ubuntu Linux 22, to update the cover page of the policy. |
| CentOS Linux 7 | Re-release for CentOS Linux 7, to update the cover page of the policy. |
| CIS Benchmark for Microsoft SQL Server 2022, v1.3.0 | Re-release for CIS Benchmark for Microsoft SQL Server 2022, v1.3.0, to replace: CID 18053 with new CID 32539 CID 7389 with CID 32610. |
| CIS Benchmark for Check Point Firewall, v1.1.0 | Re-release for CIS Benchmark for Check Point Firewall, v1.1.0, for scratch review. |
| CIS Benchmark for F5 Networks, v1.0.0 | Re-release for CIS Benchmark for F5 Networks, v1.0.0, for scratch review. |
| CIS Macos 26 v1.0.0 | Re-release for CIS Macos 26 v1.0.0, to replace in the policy: CID 24066 with CID 32522 CID 22738 with CID 32519 CID 18111 with CID 32517 CID 22740 with CID 32521 CID 22739 with CID 32520 CID 19924 with CID 32518 |
| Security Configuration and Compliance Policy for Citrix Netscaler | Re-release for Security Configuration and Compliance Policy for Citrix Netscaler for scratch review. |
Deprecated Policies
- CIS Benchmark for Amazon Linux 2, v3.0.0
- CIS Microsoft Intune for Windows 11 Benchmark, v4.0.0
- CIS Microsoft Intune for Windows 10 Benchmark, v4.0.0
- CIS Microsoft Windows 11 Enterprise Benchmark, v5.0.0
- CIS Microsoft Windows Server 2022 Benchmark, v5.0.0
- DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2019, V3R7
- DISA Security Technical Implementation Guide (STIG) for Microsoft Windows 11, V2R7
- DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 8, V2R6
- DISA Security Technical Implementation Guide (STIG) for Amazon Linux 2023, V1R2
- DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 9, V2R7
Proposed Upcoming Policies
We plan to release the following policies and updates next month:
- CIS IBM AIX 7 Benchmark v1.2.0
- CIS Apple macOS 14.0 Sonoma Benchmark, v3.1.0
- CIS Apple macOS 26 Tahoe Benchmark, v1.1.0
- CIS Apple macOS 15.0 Sequoia Benchmark, v2.1.0
- DISA STIG for Red Hat Enterprise Linux 7 – Ver 3, Rel 15
- DISA STIG for Solaris 11 SPARC – Ver 3, Rel 5
- CIS Google Chrome Group Policy Benchmark, v1.0.0
- CIS Microsoft Windows Server 2025 Benchmark, v2.1.0
- CIS PostgreSQL 17 Benchmark, v1.1.0
- CIS Google Chrome Group Policy Benchmark, v1.1.0
- Safeguard Computer Security Evaluation Checkpoint Firewall
- Safeguard Computer Security Evaluation Docker
- Safeguard Computer Security Evaluation Kubernetes
- Safeguard Computer Security Evaluation Red Hat OpenShift
- Safeguard Computer Security Evaluation MySQL 5.7
- Safeguard Computer Security Evaluation MySQL 8.0
- Security Configuration and Compliance Policy for Opengear 25.x
Learn More
Discover how Qualys Enterprise TruRiskTM Platform can help you reduce cyber risk and improve business outcomes through precise remediation activities. Learn more about it here.
Additional Information
Feel free to contact your Technical Account Manager (TAM) or Qualys Technical Support if you have any questions.