CIS Checklist Documentation

Is there a repository containing more detailed documentation for the CIS Checklists?

For example, a coverage matrix which maps the CIS requirements to the actual SCM fixlets – we need to be able to verify that each item is covered and/or address any gaps in coverage with either custom fixlets or manual intervention.

The title of SCM fixlet is the same as the one of CIS rule, so you can find which CIS rule corresponds to which SCM fixlet by its title.
Basically, for CIS benchmarks, the SCM fixlets covers the “Scored” rules in a benchmark.

CIS benchmark documentations are available from https://benchmarks.cisecurity.org/downloads/

You can also check the “Source ID” column. You can, normally, put those into Google and you’ll get some kind of site detailing the requirements for the standard.

Are you saying that, for all CIS Checklists, there is 100% coverage for the scored items in the corresponding CIS Benchmark?