It is important to remember that secuity is
not sufficient from the moment CIS 3 is installed.
After install, you must stealth all ports using "stealth ports wizard." In addition, you must set CIS configuration to "proactive security" if you wish to have a high level of security (the other configurations are less secure). You may get more pop up warnings initially when using proactive security, but these will trickle to a minimium after CIS learns your system.
Hopefully, CIS 4 will have an install wizard that will require the user to configure security. With an install wizard, CIS would be configured appropriately from the moment it first starts.
For users with special priviledges, you can see details of this suggestion in the
usability forum.