• Tenable
  • Audits
  • Settings
    Links
    Tenable Cloud Tenable Community & Support Tenable University
    Theme
  • Tenable
  • Plugins
  • Overview
  • Plugins Pipeline
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • LCE Families
  • Tenable OT Security Families
  • About Plugin Families
  • Release Notes
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
    • Links
    • Tenable Cloud
    • Tenable Community & Support
    • Tenable University
    • Settings
    • Theme
Detections
  • Plugins
  • Overview
  • Plugins Pipeline
  • Release Notes
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • LCE Families
  • Tenable OT Security Families
  • About Plugin Families
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
Analytics
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
  1. Audits
  2. CIS NGINX Benchmark v1.0.0 L2 Proxy
  1. Audits

CIS NGINX Benchmark v1.0.0 L2 Proxy

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS NGINX Benchmark v1.0.0 L2 Proxy

Updated: 5/2/2023

Authority: Operating Systems and Applications

Plugin: Unix

Revision: 1.11

Estimated Item Count: 14

Audit Items

  • Items
  • Changelog
DescriptionCategories
1.1.2 Ensure NGINX is installed from source
2.1.1 Ensure only required modules are installed
2.1.2 Ensure HTTP WebDAV module is not installed
2.1.3 Ensure modules with gzip functionality are disabled
3.5 Ensure error logs are sent to a remote syslog server
3.6 Ensure access logs are sent to a remote syslog server
4.1.9 Ensure HTTP Public Key Pinning is enabled
4.1.11 Ensure the upstream traffic server certificate is trusted
4.1.12 Ensure your domain is preloaded
4.1.13 Ensure session resumption is disabled to enable perfect forward security
5.1.1 Ensure allow and deny filters limit access to specific IP addresses
5.2.4 Ensure the number of connections per IP address is limited
5.2.5 Ensure rate limits by IP address are set
CIS_NGINX_Level_2_Proxy_v1.0.0.audit from CIS NGINX Benchmark v1.0.0
  • Go to Page:
  • Page 1 of 1
  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2025 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance