Item Search

NameAudit NamePluginCategory
1.2 Ensure that the SharePoint Central Administration Site is TLS-enabled - HTTPSCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.3.4 (L1) Ensure 'User owned apps and services' is restrictedCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

1.4 Ensure that the underlying Internet Information Services (IIS) Authentication module is set to use Kerberos as its Auth ProviderCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Ensure 'Block File Types' is configured to match the enterprise blacklistCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Ensure the SharePoint farm service account (database access account) is configured with the minimum privileges for the local server.CIS Microsoft SharePoint 2016 OS v1.1.0Windows

ACCESS CONTROL

2.4 Ensure SharePoint provides the ability to prohibit the transfer of unsanctioned information in accordance with security policy.CIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.6 Ensure the SharePoint farm service account (database access account) is configured with the minimum privileges on the SQL server - OwnerCIS Microsoft SharePoint 2016 DB v1.1.0MS_SQLDB

ACCESS CONTROL

2.7 Ensure a separate organizational unit (OU) in Active Directory exists for SharePoint 2016 objects.CIS Microsoft SharePoint 2016 OS v1.1.0Windows
2.8 Ensure the SharePoint Central Administration site is not accessible from Extranet or Internet connectionsCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.10 Ensure that the SharePoint Online Web Part Gallery component is configured with limited accessCIS Microsoft SharePoint 2016 OS v1.1.0Windows

ACCESS CONTROL

3.3 Ensure SharePoint implements security functions as a layered structure minimizing interactions between layers of the design.CIS Microsoft SharePoint 2016 OS v1.1.0Windows
3.5 Ensure that SharePoint specific malware (i.e. anti-virus) protection software is integrated and configured - Attempt to cleanCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

3.5 Ensure that SharePoint specific malware (i.e. anti-virus) protection software is integrated and configured - Scan on uploadCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

3.6 Ensure that SharePoint is configured with 'Strict' browser file handling settingsCIS Microsoft SharePoint 2016 OS v1.1.0Windows

CONFIGURATION MANAGEMENT

3.7 Ensure that SharePoint is set to reject or delay network traffic generated above traffic volume thresholds - connectionTimeoutCIS Microsoft SharePoint 2016 OS v1.1.0Windows

ACCESS CONTROL

3.9 Ensure that SharePoint application servers are protected by a reverse proxyCIS Microsoft SharePoint 2016 OS v1.1.0Windows
3.10 Ensure SharePoint database servers are segregated from application server and placed in a secure zone.CIS Microsoft SharePoint 2016 OS v1.1.0Windows
3.11 Ensure that the SharePoint Central Administration interface is not hosted in the DMZ.CIS Microsoft SharePoint 2016 OS v1.1.0Windows
4.2 Ensure claims-based authentication is used for all web applications and zones of a SharePoint 2016 farmCIS Microsoft SharePoint 2016 OS v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

4.3 Ensure Windows Authentication uses Kerberos and not the NT Lan Manager (NTLM) authentication protocolCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.4 Ensure Anonymous authentication is deniedCIS Microsoft SharePoint 2016 OS v1.1.0Windows

ACCESS CONTROL

5.1 Ensure that auditable events and diagnostic tracking settings within SharePoint is consistent with the organization's security plansCIS Microsoft SharePoint 2016 OS v1.1.0Windows

AUDIT AND ACCOUNTABILITY

5.2 Ensure that remote sessions for accessing security functions and security-relevant information are auditedCIS Microsoft SharePoint 2016 OS v1.1.0Windows
6.1 Ensure that the SQL Server component to SharePoint is set to listen on non-default ports - TCP 1433CIS Microsoft SharePoint 2016 DB v1.1.0MS_SQLDB
6.1 Ensure that the SQL Server component to SharePoint is set to listen on non-default ports - UDP 1434CIS Microsoft SharePoint 2016 DB v1.1.0MS_SQLDB
6.3 Ensure that SharePoint user sessions are terminated upon user logoff and when the idle time limit is exceededCIS Microsoft SharePoint 2016 OS v1.1.0Windows

ACCESS CONTROL

6.4 Set 'Always require users to connect to verify permission' to 'Enabled'CIS MS Office Outlook 2010 v1.0.0Windows

CONFIGURATION MANAGEMENT

6.18 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes'CIS Microsoft Azure Foundations v4.0.0 L2microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

7.3 Ensure compilation or scripting of database pages via the PageParserPaths elements is not allowedCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

17.4.2 Ensure 'Audit Directory Service Access' is set to include 'Success and Failure' (STIG DC only)CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG DCWindows

AUDIT AND ACCOUNTABILITY

18.5.19.2.1 (L2) Disable IPv6 (Ensure TCPIP6 Parameter 'DisabledComponents' is set to '0xff (255)')CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

CONFIGURATION MANAGEMENT, RISK ASSESSMENT

18.5.19.2.1 Disable IPv6 (Ensure TCPIP6 Parameter 'DisabledComponents' is set to '0xff (255)')CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.5.19.2.1 Disable IPv6 (Ensure TCPIP6 Parameter 'DisabledComponents' is set to '0xff (255)')CIS Windows 7 Workstation Level 2 v3.2.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.18.7 (L2) Ensure 'Enable Windows Package Manager command line interfaces' is set to 'Disabled'CIS Microsoft Windows Server 2025 v1.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.10.18.7 (L2) Ensure 'Enable Windows Package Manager command line interfaces' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v4.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

18.10.18.7 (L2) Ensure 'Enable Windows Package Manager command line interfaces' is set to 'Disabled'CIS Microsoft Windows Server 2019 v4.0.0 L2 DCWindows

CONFIGURATION MANAGEMENT

CIS Control 6 (6.2(a)) Activate Audit LoggingCAS Implementation Group 1 Audit FileUnix

AUDIT AND ACCOUNTABILITY

CIS Control 10 (10.1) Ensure Regular Automated BackupsCAS Implementation Group 1 Audit FileUnix

CONTINGENCY PLANNING

CIS_AlmaLinux_OS_9_v2.0.0_L2_Server.audit from CIS AlmaLinux OS 9 Benchmark v2.0.0CIS AlmaLinux OS 9 v2.0.0 L2 ServerUnix
CIS_Amazon_Linux_2023_v1.0.0_L1_Server.audit from CIS Amazon Linux 2023 Benchmark v1.0.0CIS Amazon Linux 2023 Server L1 v1.0.0Unix
CIS_Apache_Cassandra_3.11_v1.0.0_L1_OS_Unix.audit from CIS Apache Cassandra 3.11 Benchmark v1.0.0CIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix
CIS_Apache_Tomcat_9_L1_v1.2.0.audit from CIS Apache Tomcat 9 BenchmarkCIS Apache Tomcat 9 L1 v1.2.0Unix
CIS_Bottlerocket_v1.0.0_L2.audit from CIS Bottlerocket Benchmark Level 2CIS Bottlerocket L2Unix
CIS_CentOS_Linux_7_v4.0.0_L1_Server.audit from CIS CentOS Linux 7 Benchmark v4.0.0CIS CentOS Linux 7 v4.0.0 L1 ServerUnix
CIS_Debian_Linux_11_v2.0.0_L2_Workstation.audit from CIS Debian Linux 11 Benchmark v2.0.0CIS Debian Linux 11 v2.0.0 L2 WorkstationUnix
CIS_IBM_DB2_10_v1.1.0_Level_2_OS_Windows.audit from CIS DB2 10.x Windows OSCIS IBM DB2 v10 v1.1.0 Windows OS Level 2Windows
CIS_MacOS_Safari_Benchmark_v2.0.0_L2.audit from CIS MacOS Safari Benchmark v2.0.0CIS MacOS Safari v2.0.0 L2Unix
CIS_Oracle_Server_19c_v1.2.0_L1_Linux.audit from CIS Oracle Database 19c Benchmark v1.2.0CIS Oracle Server 19c Linux v1.2.0Unix
CIS_Ubuntu_20.04_LTS_v2.0.1_L1_Server.audit from CIS Ubuntu Linux 20.04 LTS BenchmarkCIS Ubuntu Linux 20.04 LTS Server L1 v2.0.1Unix
WNDF-AV-000010 - Microsoft Defender AV must be configured to join Microsoft MAPS.DISA STIG Microsoft Defender Antivirus v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION