Item Search

NameAudit NamePluginCategory
1.1 Ensure 'Web content' is on non-system partitionCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL

1.3 Ensure 'directory browsing' is set to disabledCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

1.3 Ensure 'directory browsing' is set to disabledCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

1.4 Ensure 'application pool identity' is configured for all application poolsCIS IIS 7 L1 v1.8.0Windows

ACCESS CONTROL

1.4 Ensure that the underlying Internet Information Services (IIS) Authentication module is set to use Kerberos as its Auth ProviderCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.4 Ensure that the underlying Internet Information Services (IIS) Authentication module is set to use Kerberos as its Authentication ProviderCIS Microsoft SharePoint 2019 OS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL

1.31 IIST-SI-000241CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.42 IIST-SI-000263CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.57 EX19-MB-000198CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.57 VCSA-80-000294CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT IIVMware

CONFIGURATION MANAGEMENT

2.2.4 Ensure 'Adjust memory quotas for a process' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.6 Ensure 'Adjust memory quotas for a process' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.6 Ensure 'Adjust memory quotas for a process' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.6 Ensure 'Adjust memory quotas for a process' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.6 Ensure 'Adjust memory quotas for a process' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.23 (L1) Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

IDENTIFICATION AND AUTHENTICATION

2.2.23 Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

IDENTIFICATION AND AUTHENTICATION

2.2.36 (L1) Ensure 'Replace a process level token' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

IDENTIFICATION AND AUTHENTICATION

2.2.36 Ensure 'Replace a process level token' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.36 Ensure 'Replace a process level token' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

3.3 Ensure Custom Error Messages are not Off - ApplicationsCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

3.3 Ensure Custom Error Messages are not Off - DefaultCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely - ApplicationsCIS IIS 7 L1 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely - DefaultCIS IIS 7 L1 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

4.1 Ensure 'maxAllowedContentLength' is configured - ApplicationsCIS IIS 10 v1.2.1 Level 2Windows

SYSTEM AND SERVICES ACQUISITION

4.1 Ensure 'maxAllowedContentLength' is configured - DefaultCIS IIS 10 v1.2.1 Level 2Windows

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure 'maxURL request filter' is configured - ApplicationsCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

5.1 Ensure Default IIS web log location is movedCIS IIS 10 v1.2.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

5.1 Ensure Default IIS web log location is movedCIS IIS 8.0 v1.5.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

5.1 Ensure Default IIS web log location is movedCIS IIS 7 L1 v1.8.0Windows

AUDIT AND ACCOUNTABILITY

90.17 Ensure 'Generate Security Audits' is set to 'LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

90.19 Ensure 'Generate Security Audits' is set to 'LOCAL SERVICE, NETWORK SERVICE, RESTRICTED SERVICES\PrintSpoolerService'CIS Microsoft Intune for Windows 11 v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

EP11-00-013000 - The EDB Postgres Advanced Server must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.EDB PostgreSQL Advanced Server v11 DB Audit v2r4PostgreSQLDB

AUDIT AND ACCOUNTABILITY

EX16-MB-000600 - Exchange services must be documented and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX19-MB-000198 - Exchange services must be documented, and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

CONFIGURATION MANAGEMENT

IIST-SI-000215 - Mappings to unused and vulnerable scripts on the IIS 10.0 website must be removed.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

CONFIGURATION MANAGEMENT

IIST-SI-000241 - The IIS 10.0 website must only accept client certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs).DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000241 - The IIS 10.0 website must only accept client certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs).DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000151 - The IIS 10.0 web server must be tuned to handle the operational requirements of the hosted application.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000153 - An IIS 10.0 web server must maintain the confidentiality of controlled information during transmission through the use of an approved Transport Layer Security (TLS) version.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS)DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS).DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IISW-SI-000236 - The IIS 8.5 websites connectionTimeout setting must be explicitly configured to disconnect an idle session.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SV-000151 - The IIS 8.5 web server must be tuned to handle the operational requirements of the hosted application.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SP13-00-000060 - SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds - ConnectionTimeoutDISA Microsoft SharePoint 2013 STIG v2r4Windows

CONFIGURATION MANAGEMENT

SP13-00-000110 - SharePoint must ensure authentication of both client and server during the entire session. An example of this is SSL Mutual Authentication.DISA Microsoft SharePoint 2013 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

VCSA-70-000077 - The vCenter Server must enable FIPS-validated cryptography.DISA STIG VMware vSphere 7.0 vCenter v1r3VMware

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION