1.4.4 Set IP address for 'logging host' | CIS Cisco IOS XR 7.x v1.0.0 L1 | Cisco | AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY |
2.1 Ensure That Cloud Audit Logging Is Configured Properly | CIS Google Cloud Platform v3.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
2.1.11 Ensure the spoofed domains report is reviewed weekly | CIS Microsoft 365 Foundations E5 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
2.1.12 Ensure the 'Restricted entities' report is reviewed weekly | CIS Microsoft 365 Foundations E3 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
2.1.13 Ensure all security threats in the Threat protection status report are reviewed at least weekly | CIS Microsoft 365 Foundations E3 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
2.2.1 Ensure Firewall Is Enabled | CIS Apple macOS 13.0 Ventura v2.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, INCIDENT RESPONSE, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
2.2.1 Ensure Firewall Is Enabled | CIS Apple macOS 14.0 Sonoma v1.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, INCIDENT RESPONSE, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
2.2.4 Set IP address for 'logging host' | CIS Cisco IOS 16 L1 v2.0.0 | Cisco | AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY |
2.2.4 Set IP address for 'logging host' | CIS Cisco IOS 17 L1 v2.0.0 | Cisco | AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY |
2.3.1 Ensure the Account Provisioning Activity report is reviewed at least weekly | CIS Microsoft 365 Foundations E3 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
2.3.2 Ensure non-global administrator role group assignments are reviewed at least weekly | CIS Microsoft 365 Foundations E3 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
2.5.2.1 Ensure Firewall Is Enabled | CIS Apple macOS 12.0 Monterey v3.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, INCIDENT RESPONSE, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
2.5.2.1 Ensure Firewall Is Enabled | CIS Apple macOS 10.15 Catalina v3.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, INCIDENT RESPONSE, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
2.5.2.1 Ensure Firewall Is Enabled | CIS Apple macOS 11.0 Big Sur v4.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, INCIDENT RESPONSE, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
2.5.2.2 Ensure Firewall Is Enabled | CIS Apple macOS 10.14 v2.0.0 L1 | Unix | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, INCIDENT RESPONSE, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
2.12 Ensure That Cloud DNS Logging Is Enabled for All VPC Networks | CIS Google Cloud Platform v3.0.0 L1 | GCP | AUDIT AND ACCOUNTABILITY |
2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated every 20 minutes or less on weekday 8a-5p' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated hourly on weekday 6p-7a' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
2.12.8 - Miscellaneous Config - enable sar accounting - 'activity reports are generated hourly on weekends' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
2.12.8 - Miscellaneous Config - enable sar accounting - 'daily summaries are being prepared' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
3.1.2 Ensure user role group changes are reviewed at least weekly | CIS Microsoft 365 Foundations E3 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
3.2 Ensure CloudTrail log file validation is enabled | CIS Amazon Web Services Foundations L2 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
3.7 Ensure proxies pass source IP information | CIS NGINX Benchmark v2.0.1 L1 Proxy | Unix | AUDIT AND ACCOUNTABILITY |
3.7 Ensure proxies pass source IP information | CIS NGINX Benchmark v2.0.1 L1 Loadbalancer | Unix | AUDIT AND ACCOUNTABILITY |
3.7 Ensure proxies pass source IP information - X-Real-IP | CIS NGINX Benchmark v2.0.1 L1 Loadbalancer | Unix | AUDIT AND ACCOUNTABILITY |
3.7 Ensure proxies pass source IP information - X-Real-IP | CIS NGINX Benchmark v2.0.1 L1 Proxy | Unix | AUDIT AND ACCOUNTABILITY |
4.1 Ensure unauthorized API calls are monitored | CIS Amazon Web Services Foundations L2 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.2 Ensure management console sign-in without MFA is monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.3 Ensure usage of 'root' account is monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.4 Ensure IAM policy changes are monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.5 Ensure CloudTrail configuration changes are monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.6 Ensure AWS Management Console authentication failures are monitored | CIS Amazon Web Services Foundations L2 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.7 Ensure disabling or scheduled deletion of customer created CMKs is monitored | CIS Amazon Web Services Foundations L2 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.8 Ensure S3 bucket policy changes are monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.9 Ensure AWS Config configuration changes are monitored | CIS Amazon Web Services Foundations L2 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.10 Ensure security group changes are monitored | CIS Amazon Web Services Foundations L2 3.0.0 | amazon_aws | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
4.11 Ensure Network Access Control Lists (NACL) changes are monitored | CIS Amazon Web Services Foundations L2 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.12 Ensure changes to network gateways are monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.13 Ensure route table changes are monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.14 Ensure VPC changes are monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
4.15 Ensure AWS Organizations changes are monitored | CIS Amazon Web Services Foundations L1 3.0.0 | amazon_aws | AUDIT AND ACCOUNTABILITY |
5.1.5.1 Ensure the Application Usage report is reviewed at least weekly | CIS Microsoft 365 Foundations E3 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
5.2.4.2 Ensure the self-service password reset activity report is reviewed at least weekly | CIS Microsoft 365 Foundations E3 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
5.2.6.1 Ensure the Azure AD 'Risky sign-ins' report is reviewed at least weekly | CIS Microsoft 365 Foundations E5 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
6.4.1 Ensure mail forwarding rules are reviewed at least weekly | CIS Microsoft 365 Foundations E3 L1 v3.0.0 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
PCI 10.6 - Security log review - sar accounting - 'activity reports are generated every 20 minutes or less on weekday 8a-5p' | PCI DSS 2.0/3.0 - AIX | Unix | AUDIT AND ACCOUNTABILITY |
PCI 10.6 - Security log review - sar accounting - 'activity reports are generated hourly on weekday 6p-7a' | PCI DSS 2.0/3.0 - AIX | Unix | AUDIT AND ACCOUNTABILITY |
PCI 10.6 - Security log review - sar accounting - 'activity reports are generated hourly on weekends' | PCI DSS 2.0/3.0 - AIX | Unix | AUDIT AND ACCOUNTABILITY |
PCI 10.6 - Security log review - sar accounting - 'daily summaries are being prepared' | PCI DSS 2.0/3.0 - AIX | Unix | AUDIT AND ACCOUNTABILITY |
SHPT-00-000405 - To support audit review, analysis, and reporting, SharePoint must integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities. | DISA STIG SharePoint 2010 v1r9 | Windows | AUDIT AND ACCOUNTABILITY |