Modular CIS hardening scripts for Debian 11, 12, and 13
- Stars1.1k
- Forks174
- Open Issues17
Other
- Shell

About debian-cis
debian-cis is a set of modular security hardening scripts for Debian 11, 12, and 13. It lets system administrators apply CIS Benchmark recommendations to Debian hosts and bring them in line with PCI-DSS requirements.
Each check is its own script with a matching configuration file, so you enable, disable, or tune individual controls instead of running an all-or-nothing pass. You can add your own scripts to the same framework, and hardening can be skipped inside Docker where it does not apply.
It is developed by OVHcloud and used to harden the company's own PCI-DSS infrastructure, which keeps the checks battle-tested against a real audited environment. The scripts are open under the Apache 2.0 license.
Key features
- Modular CIS hardening scripts, one per control
- Targets Debian 11, 12, and 13
- Enable, disable, or tune each check via config
- Add and run your own custom hardening scripts
- Skips hardening inside Docker where unneeded
Details
- First released
- 2016
- Platforms
- Linux
- Deployment
- self-hostable
- License
- Apache 2.0
- Security standard
- CIS Benchmark recommendations
- Focus
- Debian hardening for PCI-DSS
