Book an Appointment

IT Security Audits with a Clear Benchmark

How technical security audits and compliance audits work together – from Active Directory to M365, firewalls and architecture, assessed against CIS Benchmarks, vendor baselines and BSI IT-Grundschutz.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

3established reference frameworks: CIS Benchmarks, vendor baselines, BSI IT-Grundschutz
100+CIS Benchmark guides for over 25 product families
111modules in the IT-Grundschutz Compendium (Edition 2023), across ten layers
2profiles in most CIS Benchmarks: Level 1 baseline hardening, Level 2 higher protection needs

An IT security audit answers a simple question with a rigorous methodology: does the actual state of your systems match what policies, standards and your own security concept prescribe? Unlike a penetration test, which demonstrates the exploitability of individual vulnerabilities, an audit systematically assesses configurations, permissions and architecture decisions against a defined benchmark. Three reference frameworks have become established for this purpose: the CIS Benchmarks, vendor security baselines and the modules of the BSI IT-Grundschutz Compendium. This article puts technical audits and compliance audits into context, describes typical formats and approaches, and offers guidance on a sensible audit cycle.

The Essentials at a Glance

Six topic blocks — tap to expand.

Typical Audit Formats

Four focused formats from practice – tap a tab for the audit focus.

Identity system
  • Examines permission and delegation structures, privileged accounts and groups, trust relationships and the hardening of domain controllers.
  • As the central identity system, AD is a prime attack target.
Privileged accountsDelegationTrust relationshipsDomain controllers

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Center for Internet Security · 2026

CIS Benchmarks

More than 100 consensus-based, vendor-neutral configuration guides with Level 1/Level 2 profiles serving as the assessment basis for technical audits; continuously updated.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2023

IT-Grundschutz-Kompendium, Edition 2023

111 modules across ten layers, including APP.2.2 Active Directory Domain Services and NET.3.2 Firewall as requirement catalogs for system-level audits.

NIST · 2009

Guidelines on Firewalls and Firewall Policy (NIST SP 800-41 Rev. 1)

Foundational publication on firewall technologies and firewall policies with recommendations on selection, configuration, testing and operation; status final.

Microsoft (Security Baselines Blog) · 2026

Security baseline for Windows Server 2025, version 2602

Example of continuously maintained vendor baselines that can be compared against existing group policies using the Security Compliance Toolkit.

ISO / DIN · 2018

DIN EN ISO 19011:2018 – Leitfaden zur Auditierung von Managementsystemen

Methodological framework for audit principles, audit programs and auditor competence, on which technical security audits also rely.

Want to know where your systems really stand?

In a no-obligation initial consultation, we determine which audit format and which benchmark fit your environment.