Revision 1.2Aug 7, 2026
Functional Update
- 4.1 Ensure legacy TLS protocols are disabled
- 4.4 Ensure Federal Information Processing Standard (FIPS) is enabled
- 5.2 Ensure that audit filters are configured properly
- 5.3 Ensure that logging captures as much information as possible
- 5.4 Ensure that new entries are appended to the end of the log file
- 6.2 Ensure that operating system resource limits are set for MongoDB
- 6.3 Ensure that server-side scripting is disabled if not needed
Informational Update
- 4.1 Ensure legacy TLS protocols are disabled
- 4.4 Ensure Federal Information Processing Standard (FIPS) is enabled
- 5.2 Ensure that audit filters are configured properly
- 5.3 Ensure that logging captures as much information as possible
- 5.4 Ensure that new entries are appended to the end of the log file
- 6.2 Ensure that operating system resource limits are set for MongoDB
- 6.3 Ensure that server-side scripting is disabled if not needed
Miscellaneous
- Metadata updated.
- Platform check updated.
- References updated.
- Variables updated.
Added
- 2.3 Ensure authentication is enabled in the sharded cluster
- 4.5 Ensure Encryption of Data at Rest
- CIS_MongoDB_5_v1.2.0_L2_Unix.audit from CIS MongoDB 5 v1.2.0
Removed
- 2.3 Ensure authentication is enabled in the sharded cluster - CAFile
- 2.3 Ensure authentication is enabled in the sharded cluster - PEMKeyFile
- 2.3 Ensure authentication is enabled in the sharded cluster - authenticationMechanisms
- 2.3 Ensure authentication is enabled in the sharded cluster - clusterAuthMode
- 2.3 Ensure authentication is enabled in the sharded cluster - clusterFile
- 4.5 Ensure Encryption of Data at Rest - enableEncryption
- 4.5 Ensure Encryption of Data at Rest - encryptionKeyFile
- CIS_MongoDB_5_Benchmark_Level_2_OS_Linux_v1.2.0.audit from CIS MongoDB 5 Benchmark