Hacker News new | ask | show | jobs
by onlinejk 1821 days ago
I'll parse my concurrence to @LinuxBender's suggestion: Go with the CIS benchmarks[1^] vs. the NIST, at least initially.

The former is written in "common engineering language," while the latter uses a lot of governmentish/ pseudo-legalese that often raises more questions than it answers (IMHO).

[1]: https://www.cisecurity.org/blog/cis-benchmarks-june-2021-upd...