Item Search

NameAudit NamePluginCategory
1.1.5 (L1) Ensure 'Password must meet complexity requirements' is set to 'Enabled'CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

1.1.6 Ensure 'Relax minimum password length limits' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

1.1.6 Ensure 'Relax minimum password length limits' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

1.3.4 Ensure 'Minimum Lowercase Letters' is greater than or equal to 1CIS Palo Alto Firewall 11 v1.2.0 L1Palo_Alto

IDENTIFICATION AND AUTHENTICATION

1.3.8 Ensure 'New Password Differs By Characters' is greater than or equal to 3CIS Palo Alto Firewall 11 v1.2.0 L1Palo_Alto

IDENTIFICATION AND AUTHENTICATION

1.5 Ensure minimum password length is set to 14 characters or moreCIS Snowflake Foundations v2.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION

2.3.1.2 Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

2.3.17.1 Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

2.3.17.1 Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

IDENTIFICATION AND AUTHENTICATION

2.4.2 Ensure 'Require alphanumeric value' is set to 'Enabled'MobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L2MDM

IDENTIFICATION AND AUTHENTICATION

2.5.1 Ensure Users' Accounts Do Not Have a Password HintCIS Apple macOS 14.0 Sonoma Cloud-tailored v1.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

2.9 Require Current Password for Password ResetCIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L2 MySQL RDBMS MySQLDBMySQLDB

IDENTIFICATION AND AUTHENTICATION

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'AirWatch - CIS Apple iOS 17 Institution Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

4.1.6 Ensure 'Stolen Device Protection' Is EnabledAirWatch - CIS Apple iOS 17 v1.1.0 End User Owned L2MDM

IDENTIFICATION AND AUTHENTICATION

4.10 Ensure all accounts that can log in have passwordsCIS PostgreSQL 17 v1.1.0 L1 Database PostgreSQLDBPostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

5.2.2 Ensure Password Minimum Length Is ConfiguredCIS Apple macOS 15.0 Sequoia v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.2.3 Ensure Complex Password Must Contain Alphabetic Characters Is ConfiguredCIS Apple macOS 13.0 Ventura Cloud-tailored v1.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.3 Ensure Complex Password Must Contain Alphabetic Characters Is ConfiguredCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.3.2 Ensure custom banned passwords lists are usedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.3 Ensure password protection is enabled for on-prem Active DirectoryCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.3 Ensure password protection is enabled for on-prem Active DirectoryCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.5 Ensure Complex Password Must Contain Special Character Is ConfiguredCIS Apple macOS 14.0 Sonoma Cloud-tailored v1.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.6 Ensure Complex Password Must Contain Uppercase and Lowercase Characters Is ConfiguredCIS Apple macOS 12.0 Monterey v4.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.6 Ensure Complex Password Must Contain Uppercase and Lowercase Characters Is ConfiguredCIS Apple macOS 15.0 Sequoia Cloud-tailored v1.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.8 Ensure Password History Is ConfiguredCIS Apple macOS 15.0 Sequoia Cloud-tailored v1.0.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure password creation requirements are configured - dcreditCIS SUSE Linux Enterprise Server 11 L1 v2.1.1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.2.4.1 Ensure pam_unix does not include nullokCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - 'lcredit'CIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - 'ocredit'CIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - retryCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.3 Ensure password expiration warning days is configuredCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure all users last password change date is in the pastCIS SUSE Linux Enterprise Server 11 L1 v2.1.1Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure all users last password change date is in the pastCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure all users last password change date is in the pastCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.6 Ensure all users last password change date is in the pastCIS SUSE Linux Enterprise 12 v3.2.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.5.1.2 Ensure password expiration is 365 days or less - usersCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.5.1.3 Ensure password expiration warning days is 7 or more - login.defsCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.5.1.3 Ensure password expiration warning days is 7 or more - usersCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.5.1.3 Ensure password expiration warning days is 7 or more - usersCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.5.1.4 Ensure inactive password lock is 30 days or less - useraddCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.6 Ensure password complexity is configuredCIS PostgreSQL 17 v1.1.0 L1 Database PostgreSQLDBPostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

6.2 Ensure the uniqueness of CHAP authentication secrets for iSCSI trafficCIS VMware ESXi 6.7 v1.3.0 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

6.2.1 Ensure accounts in /etc/passwd use shadowed passwordsCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure /etc/shadow password fields are not emptyCIS SUSE Linux Enterprise 12 v3.2.1 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

6.3.5 Limit Password Reuse - password sufficient pam_unix.o <existing options> remember=5CIS Red Hat Enterprise Linux 5 L1 v2.2.1Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Ensure Passwords are Set for All MySQL AccountsCIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L1 MySQL RDBMS MySQLDBMySQLDB

IDENTIFICATION AND AUTHENTICATION

7.5 Ensure Password Complexity Policies are in PlaceCIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L1 MySQL RDBMS on Linux MySQLDBMySQLDB

IDENTIFICATION AND AUTHENTICATION

18.9.26.4 Ensure 'Password Settings: Password Complexity' is set to 'Enabled: Large letters + small letters + numbers + specials' or higherCIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

49.29 Ensure 'User Account Control: Use Admin Approval Mode' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

107.4 Ensure 'Password Length' is set to 'Configured: 15 or more'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION