Item Search

NameAudit NamePluginCategory
1.1.7 Ensure separate partition exists for /var/tmpCIS Amazon Linux v2.1.0 L2Unix

CONFIGURATION MANAGEMENT

1.5 Configure DB2 to use non-standard ports - Port 523CIS IBM DB2 v10 v1.1.0 Linux OS Level 2Unix

CONFIGURATION MANAGEMENT

1.21.1 (L1) Ensure 'Specifies whether to allow websites to make requests to more-private network endpoints' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.59 (L1) Ensure 'Clear browsing data when Microsoft Edge closes' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.69 (L1) Ensure 'Configure the list of types that are excluded from synchronization' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.108 (L2) Ensure 'Enforce Bing SafeSearch' is set to 'Enabled: Configure moderate search restrictions in Bing'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.118 (L1) Ensure 'Restrict exposure of local IP address by WebRTC' is set to 'Enabled: Allow public interface over http default route. This doesn't expose the local IP address'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

2.1.1.1.1 Set the 'hostname'CIS Cisco IOS 12 L1 v4.0.0Cisco

CONFIGURATION MANAGEMENT

2.2 Set Search Provider Update BehaviorCIS Mozilla Firefox 102 ESR Linux L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.6 Ensure Update-related UI Components are DisplayedCIS Mozilla Firefox 38 ESR Linux L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3 Verify that docker.socket file ownership is set to root:rootCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.3 Verify that docker.socket file ownership is set to root:rootCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.3 Verify that docker.socket file ownership is set to root:rootCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.4 Enable Warning For "Phishy" URLsCIS Mozilla Firefox 38 ESR Linux L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.4 Verify that docker.socket file permissions are set to 644 or more restrictiveCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.6.1.13 Ignore user-provided environment variablesCIS IBM AIX 7.1 L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

3.7 Verify that registry certificate file ownership is set to root:rootCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.7 Verify that registry certificate file ownership is set to root:rootCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.8 Set 'Enable OOF messages to remote domains' to 'None'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

CONFIGURATION MANAGEMENT

3.9 Verify that TLS CA certificate file ownership is set to root:rootCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.10 Verify that TLS CA certificate file permissions are set to 444 or more restrictiveCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.17 Verify that daemon.json file ownership is set to root:rootCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.17 Verify that daemon.json file ownership is set to root:rootCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.19 Verify that /etc/default/docker file ownership is set to root:rootCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.1.13 Ensure a Secure Connect Procedure is Used (CONNECT_PROC)CIS IBM DB2 11 v1.1.0 Windows OS Level 1Windows

CONFIGURATION MANAGEMENT

4.2 Enable 'Show Wi-Fi status in menu bar' - Show Wi-Fi status in menu barCIS Apple macOS 10.12 L1 v1.2.0Unix

CONFIGURATION MANAGEMENT

4.2.13 Ensure that a limit is set on pod PIDsCIS Kubernetes v1.10.0 L1 WorkerUnix

CONFIGURATION MANAGEMENT

5.1 Block Pop-up WindowsCIS Mozilla Firefox 102 ESR Linux L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.1 Use secure RealmsCIS Apache Tomcat 7 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

5.1.1 Ensure cron daemon is enabledCIS SUSE Linux Enterprise Server 11 L1 v2.1.1Unix

CONFIGURATION MANAGEMENT

5.4.1 Prefer using secrets as files over secrets as environment variablesCIS Kubernetes v1.10.0 L2 MasterUnix

CONFIGURATION MANAGEMENT

5.4.2 Consider external secret storageCIS Kubernetes v1.10.0 L2 MasterUnix

CONFIGURATION MANAGEMENT

5.7 Do not map privileged ports within containersCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

5.26 Check container health at runtimeCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

6.2 Ensure that MongoDB uses a non-default portCIS MongoDB L1 Windows Audit v1.0.0Windows

CONFIGURATION MANAGEMENT

6.11 Enable Tracking Protection - privacy.donottrackheader.enabledCIS Mozilla Firefox 102 ESR Linux L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

7.1 Ensure that key file permissions are set correctlyCIS MongoDB L1 Unix Audit v1.0.0Unix

CONFIGURATION MANAGEMENT

7.2 Ensure that database file permissions are set correctlyCIS MongoDB L1 Unix Audit v1.0.0Unix

CONFIGURATION MANAGEMENT

7.6 Ensure that port groups are not configured to VLAN 4095 except for Virtual Guest Tagging (VGT)CIS VMware ESXi 5.5 v1.2.0 Level 1VMware

CONFIGURATION MANAGEMENT

8.2.2 Ensure the rsyslog Service is activated - run level 4CIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

8.2.2 Ensure the rsyslog Service is activated - run level 5CIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

8.2.10 Turn Off ALLOW_KEY_INSERT_WITHOUT_KEYSTORE_BACKUPCIS IBM DB2 11 v1.1.0 Database Level 2IBM_DB2DB

CONFIGURATION MANAGEMENT

9.1.1 Enable cron Daemon - cron run level 5CIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

10.6 Enable strict servlet ComplianceCIS Apache Tomcat 7 L1 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

10.7 Turn off session facade recyclingCIS Apache Tomcat 7 L1 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

18.7.11 Ensure 'Point and Print Restrictions: When updating drivers for an existing connection' is set to 'Enabled: Show warning and elevation prompt'CIS Microsoft Windows Server 2016 STIG v3.0.0 L1 Domain ControllerWindows

CONFIGURATION MANAGEMENT

Allow unconfigured sites to be reloaded in Internet Explorer modeMSCT Edge v98 v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure Edge TyposquattingCheckerMSCT Edge v124 v1.0.0Windows

CONFIGURATION MANAGEMENT

Enable browser legacy extension point blockingMSCT Edge v124 v1.0.0Windows

CONFIGURATION MANAGEMENT

Enhance images enabledMSCT Edge v124 v1.0.0Windows

CONFIGURATION MANAGEMENT