Item Search

NameAudit NamePluginCategory
2.9 Ensure Dbcreator and Securityadmin roles are only used as neededCIS Microsoft SharePoint 2016 DB v1.1.0MS_SQLDB

ACCESS CONTROL

2.9 Isolate BIND with chroot'ed SubdirectoryCIS BIND DNS v3.0.1 Authoritative Name ServerUnix

ACCESS CONTROL

3.1 Set a nondeterministic Shutdown command valueCIS Apache Tomcat 8 L1 v1.1.0Unix

ACCESS CONTROL

3.1.3 Require explicit authorization for catalogingCIS IBM DB2 v10 v1.1.0 Windows OS Level 2Windows

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/at.allow'CIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/cron.deny'CIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

5.4 Ensure privileged containers are not usedCIS Docker Community Edition v1.1.0 L1 DockerUnix

ACCESS CONTROL

5.5 Ensure root login is restricted to system consoleCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

5.6 Ensure access to the su command is restrictedCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

6.1.13 Audit SUID executablesCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

ACCESS CONTROL

6.1.13 Audit SUID executablesCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

6.2.5 Ensure root is the only UID 0 accountCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

6.9 Restrict at/cron To Authorized Users - should pass if /etc/cron.d/at.deny does not exist.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.10.5.9 Ensure REST Connection Limit is SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.13 Restrict at/cron to Authorized Users - /etc/cron.d/at.allow permsCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

6.13 Restrict at/cron to Authorized Users - /etc/cron.d/at.allow permsCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

6.13 Restrict at/cron to Authorized Users - /etc/cron.d/at.allow permsCIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL

6.13 Restrict at/cron to Authorized Users - /etc/cron.d/at.denyCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

6.13 Restrict at/cron to Authorized Users - /etc/cron.d/cron.allow permsCIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL

7.1 Establish an administrator groupCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS WindowsWindows

ACCESS CONTROL

7.3 Secure SYSMAINT AuthorityCIS IBM DB2 v10 v1.1.0 Windows OS Level 2Windows

ACCESS CONTROL

7.4 Establish a system monitoring groupCIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS WindowsWindows

ACCESS CONTROL

9.1.8 Restrict at/cron to Authorized Users - /etc/at.allowCIS Debian Linux 7 L1 v1.0.0Unix

ACCESS CONTROL

9.1.8 Restrict at/cron to Authorized Users - /etc/cron.denyCIS Debian Linux 7 L1 v1.0.0Unix

ACCESS CONTROL

Allow user control over installsMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Always install with elevated privilegesMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

Big Sur - Require Administrator Password to Modify System-Wide PreferencesNIST macOS Big Sur v1.4.0 - 800-53r4 HighUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Big Sur - Require Administrator Password to Modify System-Wide PreferencesNIST macOS Big Sur v1.4.0 - 800-53r5 ModerateUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Catalina - Require Administrator Password to Modify System-Wide PreferencesNIST macOS Catalina v1.5.0 - 800-53r5 HighUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Disallow WinRM from storing RunAs credentialsMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Enable local admin password managementMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

Ensure access to the su command is restricted - pam_wheel.soTenable Cisco Firepower Management Center OS Best Practices AuditUnix

ACCESS CONTROL

Ensure core dumps are restricted - limits.confTenable Cisco Firepower Management Center OS Best Practices AuditUnix

ACCESS CONTROL

Ensure core dumps are restricted - sysctlTenable Cisco Firepower Management Center OS Best Practices AuditUnix

ACCESS CONTROL

Ensure noexec option set on /var/tmp partitionTenable Cisco Firepower Management Center OS Best Practices AuditUnix

ACCESS CONTROL

Enumerate administrator accounts on elevationMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts and sharesMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Network security: Allow LocalSystem NULL session fallbackMSCT Windows Server 2019 DC v1.0.0Windows

ACCESS CONTROL

Turn on convenience PIN sign-inMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

User Account Control: Admin Approval Mode for the Built-in Administrator accountMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Admin Approval Mode for the Built-in Administrator accountMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop.MSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Behavior of the elevation prompt for administrators in Admin Approval ModeMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Behavior of the elevation prompt for standard usersMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Only elevate UIAccess applications that are installed in secure locationsMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

User Account Control: Run all administrators in Admin Approval ModeMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL