NIST maintains the National Checklist Repository, which is a publicly available resource that contains information on a variety of security configuration checklists for specific IT products or categories of IT products. A security configuration checklist (also called a lockdown, hardening guide, or benchmark) is a series of instructions or procedures for configuring an IT product to a particular operational environment, for verifying that the product has been configured properly, and/or for identifying unauthorized changes to the product. The IT product may be commercial, open source, government-off-the-shelf (GOTS), etc.To facilitate development of security configuration checklists for IT products and to make checklists more organized and usable, NIST established the National Checklist Program.
For more information regarding the Security Configuration Checklists for Commercial IT Products (now part of the National Checklist Repository), please visit the Computer Security Resource Center (CSRC).