Book an Appointment

IT Security Audits with a Clear Benchmark

How technical security audits and compliance audits work together – from Active Directory to M365, firewalls and architecture, assessed against CIS Benchmarks, vendor baselines and BSI IT-Grundschutz.

An IT security audit answers a simple question with a rigorous methodology: does the actual state of your systems match what policies, standards and your own security concept prescribe? Unlike a penetration test, which demonstrates the exploitability of individual vulnerabilities, an audit systematically assesses configurations, permissions and architecture decisions against a defined benchmark. Three reference frameworks have become established for this purpose: the CIS Benchmarks, vendor security baselines and the modules of the BSI IT-Grundschutz Compendium. This article puts technical audits and compliance audits into context, describes typical formats and approaches, and offers guidance on a sensible audit cycle.

The Essentials at a Glance

01

Technical Audits vs. Compliance Audits

Compliance audits verify whether a management system meets defined requirements – for example internal audits under ISO/IEC 27001 (Clause 9.2) or certification and surveillance audits by accredited bodies. Technical security audits operate one level deeper: they measure the actual state of specific systems – configurations, permissions, rule sets – against a technical benchmark such as a CIS Benchmark or an IT-Grundschutz module. The two perspectives complement each other: the compliance audit demonstrates a working process, the technical audit the actual level of hardening. A certificate alone therefore says little about the configuration quality of individual systems – and vice versa.

02

Typical Formats: AD, M365, Firewall, Architecture

In practice, focused formats have become established. An Active Directory security audit examines permission and delegation structures, privileged accounts and groups, trust relationships and the hardening of domain controllers – as the central identity system, AD is a prime attack target. An M365/cloud configuration audit assesses tenant settings, identity and access policies, logging and external sharing against catalogs such as the CIS Microsoft 365 Foundations Benchmark. A firewall rule base review checks the rule set for overly broad permissions, orphaned and redundant rules as well as the change process; an architecture review takes a broader view of network segmentation, zoning concepts and administrative access paths.

03

Benchmarks I: CIS Benchmarks and Vendor Baselines

The CIS Benchmarks published by the Center for Internet Security are consensus-based, vendor-neutral configuration guidelines – more than 100 guides for over 25 product families, from operating systems and cloud platforms to network components. Each recommendation specifies the secure target value along with audit and remediation steps; most benchmarks are divided into two profiles: Level 1 for baseline hardening with minimal operational impact, Level 2 for higher protection needs. In addition, vendors maintain their own baselines: Microsoft publishes continuously updated Security Baselines for Windows, Windows Server and other products, which can be compared against existing group policies using the Security Compliance Toolkit. For audits, one rule applies: benchmark, version and profile must be stated explicitly in the report – otherwise the results are not reproducible.

04

Benchmarks II: BSI IT-Grundschutz Modules

The BSI's IT-Grundschutz Compendium (Edition 2023) contains 111 modules across ten layers and defines basic and standard requirements per module as well as requirements for increased protection needs. Particularly relevant for technical audits are system-level modules such as APP.2.2 Active Directory Domain Services – fully revised for the 2023 edition – or NET.3.2 Firewall. Compared with the detailed configuration settings of the CIS Benchmarks, IT-Grundschutz modules are more abstract, but they also cover organizational and operational aspects and can be linked directly to an ISMS based on the BSI standards or ISO/IEC 27001. The BSI is currently evolving IT-Grundschutz into a fully process-oriented, digital body of rules whose requirements can also be evaluated by machine; according to the BSI, the Compendium remains applicable during the multi-year transition period.

05

Approach and Reporting

Methodologically, security audits follow ISO 19011, the guideline for auditing management systems: defined audit objectives and criteria, a planned audit program and evidence-based findings. The typical process: scoping (systems, benchmark, protection needs), data collection via configuration exports, read-only tool access, interviews and document review, followed by comparison against the benchmark and an assessment of each deviation in context – not every deviation is a risk if compensating controls are in place. The report separates a management summary with the overall picture and top risks from the technical section, in which each finding is documented with evidence, risk assessment and a concrete recommendation. What matters most is prioritization by actual risk rather than by mere checklist compliance.

06

A Sensible Audit Cycle

There is no universally binding audit rhythm for technical audits – the cycle should be defined on a risk basis. A proven practice is to audit critical systems such as Active Directory, central firewalls and cloud tenants annually, and additionally after significant changes (migrations, new platforms, mergers). At the compliance level, ISO/IEC 27001 requires internal audits at planned intervals (Clause 9.2); certificates run on a three-year cycle with annual surveillance audits. Since CIS Benchmarks and vendor baselines are updated continuously and configurations drift during operation, many organizations complement point-in-time audits with continuous, tool-based configuration monitoring.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Center for Internet Security · 2026

CIS Benchmarks

More than 100 consensus-based, vendor-neutral configuration guides with Level 1/Level 2 profiles serving as the assessment basis for technical audits; continuously updated.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2023

IT-Grundschutz-Kompendium, Edition 2023

111 modules across ten layers, including APP.2.2 Active Directory Domain Services and NET.3.2 Firewall as requirement catalogs for system-level audits.

NIST · 2009

Guidelines on Firewalls and Firewall Policy (NIST SP 800-41 Rev. 1)

Foundational publication on firewall technologies and firewall policies with recommendations on selection, configuration, testing and operation; status final.

Microsoft (Security Baselines Blog) · 2026

Security baseline for Windows Server 2025, version 2602

Example of continuously maintained vendor baselines that can be compared against existing group policies using the Security Compliance Toolkit.

ISO / DIN · 2018

DIN EN ISO 19011:2018 – Leitfaden zur Auditierung von Managementsystemen

Methodological framework for audit principles, audit programs and auditor competence, on which technical security audits also rely.

Want to know where your systems really stand?

In a no-obligation initial consultation, we determine which audit format and which benchmark fit your environment.