Skip to main content

Configuration Assessment

What it is

Configuration Assessment evaluates endpoint security settings against compliance frameworks — primarily CIS benchmarks for Windows 10 and Windows 11. It compares what the agent reports against expected secure values and flags misconfigurations.

Highlights

  • Framework-driven — rules loaded from compliance frameworks (CIS and others) with control IDs and expected values.
  • Pass / Fail / N/A outcomes — each control validated and recorded with a clear status.
  • Misconfiguration findings — failed controls become tracked findings with severity, remediation steps, and a risk score.
  • OS-aware — automatically selects the correct CIS variant based on detected operating system.
  • Lifecycle management — findings marked Active or Inactive as configuration state changes.

Misconfiguration risk score

Each failed control receives a risk score based on:

InputEffect
SeverityCritical, High, Medium, or Low — weighted differently
ExposureInternet-facing assets score higher than internal
Asset typeProduction assets score higher than standard

Passed controls receive a risk score of zero.

Why it matters

Many breaches exploit misconfigured systems rather than unpatched software. This module closes the gap between vulnerability management and security hardening.

In the application

  • Compliance — framework-level control results across assets
  • Asset detail → Configuration tab — per-endpoint policy results