Workstations are the primary beachhead for phishing campaigns and drive-by malware. Riptide Cybersecurity’s CIS Desktop Auditing brings your employee workstations into strict compliance with CIS Windows 10/11 and CIS macOS Benchmarks.
Desktop Audit Scope
We perform full-spectrum endpoint posture audits across:
- Windows 11 & Windows 10 Enterprise / Pro Workstations (Intune, GPO, and hybrid-joined fleets).
- macOS Fleets: Sonoma, Ventura, and Monterey systems managed via Jamf, Kandji, or Microsoft Intune.
- Disk & Storage Encryption: BitLocker / FileVault 2 configuration, TPM 2.0 validation, PIN requirements, and key escrow governance.
- Application Whitelisting & Execution Control: AppLocker and Windows Defender Application Control (WDAC) policy verification.
- Attack Surface Reduction (ASR): Microsoft Defender ASR rule validation to block office macros, obfuscated scripts, and credential stealing from LSASS.
- Local Privilege & Account Hygiene: Eliminating local administrator rights, enforcing LAPS (Local Administrator Password Solution), and screen lock timeouts.
Benefits & Results
- Reduced Attack Surface: Neutralizes 90%+ of common commodity malware vectors before execution.
- Auditor-Ready Reports: Evidence packages structured for SOC 2, HIPAA, CMMC, and cyber insurance renewal audits.
- MDM Baseline Templates: Ready-to-import Microsoft Intune configuration profiles and Jamf payloads.