Configuration Assessment
What it is
Configuration Assessment evaluates endpoint security settings against compliance frameworks — primarily CIS benchmarks for Windows 10 and Windows 11. It compares what the agent reports against expected secure values and flags misconfigurations.
Highlights
- Framework-driven — rules loaded from compliance frameworks (CIS and others) with control IDs and expected values.
- Pass / Fail / N/A outcomes — each control validated and recorded with a clear status.
- Misconfiguration findings — failed controls become tracked findings with severity, remediation steps, and a risk score.
- OS-aware — automatically selects the correct CIS variant based on detected operating system.
- Lifecycle management — findings marked Active or Inactive as configuration state changes.
Misconfiguration risk score
Each failed control receives a risk score based on:
| Input | Effect |
|---|---|
| Severity | Critical, High, Medium, or Low — weighted differently |
| Exposure | Internet-facing assets score higher than internal |
| Asset type | Production assets score higher than standard |
Passed controls receive a risk score of zero.
Why it matters
Many breaches exploit misconfigured systems rather than unpatched software. This module closes the gap between vulnerability management and security hardening.
In the application
- Compliance — framework-level control results across assets
- Asset detail → Configuration tab — per-endpoint policy results