NetBlade
Windows Step 8 of 12 ~25 min Intermediate

Compliance, exceptions and the security score

Use the 17 baseline rules with CIS Controls v8 IG1 references: read the Compliance page, record exceptions honestly, understand the security score.

The To fix list tells you what is wrong today. The Compliance page answers a different question, the one a business owner, an insurer or an auditor asks: does this network keep the basic rules? NetBlade checks 17 baseline rules on every device they apply to, gives each one a CIS Controls reference, and keeps a register of the exceptions you accept. This article explains the rules, how to read the page, how to record exceptions so they stand up to scrutiny, and how the security score is calculated.

Before you start

  • Windows PCs read in depth, for the PC rules (Prepare your Windows PCs).
  • Devices identified or port-scanned, for the network rules (Identify every device in Sites).
  • Familiarity with To fix (Vulnerabilities): the rules are computed from the same findings, so the two pages never disagree about a machine.

1. Know the 17 rules

The rules are grouped in four areas. The CIS column is the CIS Controls v8 safeguard (Implementation Group 1) each rule corresponds to, as NetBlade prints it in the Compliance report.

RuleAreaCIS v8
Antivirus runningDefences10.1
Windows firewall onDefences4.5
System disk encryptedDefences3.6
User Account Control (UAC) onDefences5.4
Secure Boot onDefences4.1
Operating system still supportedUpdates2.2
Updates installed in the last 60 daysUpdates7.3
SMBv1 offAccess4.1
Guest account disabledAccess4.7
At most three local administratorsAccess5.4
No share everyone can write toAccess3.3
PowerShell 2.0 removedAccess4.1
No service with clear-text passwordsNetwork4.6
Remote access not exposedNetwork4.5
SNMP without the factory communityNetwork4.7
Databases not reachable from the networkNetwork4.4
No management interface exposedNetwork4.1

The Windows rules need a Windows read of the PC. «Operating system still supported» needs any read that tells the system. The Network rules need the device’s ports to have been looked at, which identification does.

Note: It is a reference, not a certification. CIS Controls is a trademark of the Center for Internet Security. Say so when you present it to a customer; the report does.

2. Understand the four verdicts

For each device, each rule is one of:

  • kept: the device shows the rule holds;
  • broken: the device shows it does not;
  • accepted exception: broken, and someone decided it is acceptable on this machine;
  • not checkable: the rule applies, but no reading answers it. A Windows PC nobody has credentials for, or a read that could not see that one point.

Devices that cannot be checked count neither for nor against. This is deliberate: a dashboard that counted them as passing would show 100% on a network nobody has looked at.

3. Read the Compliance page

In the menu open Compliance (the page title is Compliance and posture) and press Check again.

The tiles:

  • Compliance with the baseline: the percentage of checks kept, for example «412 of 450 checks kept». Kept includes accepted exceptions. A line below says how many checks were not possible and on how many devices.
  • Average posture: the average security score of the devices that have one, and how many are scored out of the total.
  • Rules broken: how many rules are broken on at least one device, and the most widespread one.

Below, each rule shows a bar with kept, accepted exception, broken and not checkable, grouped by area. Devices in the worst shape lists the devices breaking the most rules, then with the lowest score.

Click a rule to see three lists: Not compliant, Accepted exceptions and Not checkable. Click a device to open its card.

4. Work through broken rules

Start with the rule broken on the most devices: one fix, applied everywhere, moves the percentage most. Each rule comes with advice in the app. Some examples, as NetBlade gives them:

  • SMBv1 off: turn it off with Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol and restart.
  • PowerShell 2.0 removed: Disable-WindowsOptionalFeature -Online -FeatureName MicrosoftWindowsPowerShellV2Root.
  • Guest account disabled: from Computer Management, Local Users and Groups, or Get-LocalUser | Where-Object SID -like '*-501' | Disable-LocalUser.
  • System disk encrypted: turn on BitLocker for the system disk and keep the recovery key in Active Directory or somewhere safe.
  • Updates installed in the last 60 days: check Windows Update or WSUS; it is often a stopped service or a full disk.

Several of these are also available as remote actions, for example «Disable SMBv1 (recommended)» in the Windows features category (Remote actions). After fixing, read the device again with Deep scan, then press Check again.

5. Record exceptions properly

Sometimes a rule is broken for a good reason: a lab PC that must keep SMBv1 for an old instrument, a server that legitimately exposes a database to the application server next to it. For those, record an exception rather than living with a red bar.

  1. Open Security, To fix.
  2. Find the entry for that device and press Accept / reopen. It becomes an accepted exception, here and in Compliance.
  3. Open the device’s card, press Edit…, and write in Notes why it was accepted, who decided, and when to review it. Or add Your own fields such as “Exception reason” and “Review by”.
  4. To see accepted entries again, tick Show accepted on To fix. Pressing Accept / reopen on an accepted entry reopens it.

The Compliance report (Reports) includes a Register of exceptions, so the customer sees exactly what was accepted, on which devices.

Warning: NetBlade does not ask for a reason when you accept, and accepted exceptions count as kept in the compliance percentage. That makes the reason in Notes your responsibility. An exception without a written reason is just a hidden problem, and a customer or auditor will read it that way. Review exceptions at least every quarter.

Note: «System disk encrypted» is judged directly from the BitLocker state and has no entry on To fix, so it cannot be accepted as an exception: it is either kept or broken.

6. Understand the security score

Every device gets a score from 0 to 100, in four bands:

ScoreBand
90 to 100In good shape
70 to 89Worth watching
40 to 69Needs work
below 40At risk

The score starts at 100 and each open finding takes marks off, heaviest first: vulnerabilities being exploited now, then systems out of support, then vulnerabilities likely to be exploited, critical ones, configuration problems, high-severity ones, and other findings. The first few findings of each kind cost full price and further ones cost less, so sixty minor notes cannot sink a device below one with a single flaw being exploited today. On the device card, the score comes with a Why that lists what takes the marks off, with counts.

A device that was never read and has nothing known against it is Not scored: there is nothing to base a number on, and a hundred would be a lie. A site’s score is the average of the devices that have one.

Tip: The fastest way to raise an average score is usually not a fix but coverage. Unread PCs are not scored, and once read they often reveal the problems that matter. Watch the coverage line on the Dashboard.

Check that it worked

  • After fixing and re-reading, the rule’s bar shows more kept and the device drops out of Devices in the worst shape.
  • Accepted exceptions appear under Accepted exceptions in the rule’s detail, and in the Compliance report’s register.
  • Not checkable shrinks as you read more devices.

If something goes wrong

  • «No device checkable yet» on the Dashboard. No device has been read or identified. Read the PCs and run Identify every device.
  • A rule is «not checkable» on a PC that was read. The read could not see that one point, for example BitLocker without an administrator account. Use an administrator credential.
  • The percentage jumped after accepting a few entries. Expected: exceptions count as kept. Make sure each has a written reason.
  • Network rules are not checkable. The devices were never identified or port-scanned. Run Identify every device in Sites.

Next

Stay informed without watching the screen: Alerts that matter.

← All how-to guides Feature guide → The product: NetBlade Windows →