Item Search

NameAudit NamePluginCategory
1.1.2 Ensure that the API server pod specification file ownership is set to root:rootCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

1.1.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.1.14 Ensure that the default administrative credential file ownership is set to root:rootCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

1.1.18 Ensure that the controller-manager.conf file ownership is set to root:rootCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

3.5 Ensure the SQL Server's MSSQL Service Account is Not an AdministratorCIS Microsoft SQL Server 2025 v1.0.0 L1 Database Engine WindowsWindows

ACCESS CONTROL

3.5 Ensure the SQL Server's MSSQL Service Account is Not an AdministratorCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine WindowsWindows

ACCESS CONTROL

3.6 Ensure the SQL Server's SQLAgent Service Account is Not an AdministratorCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS WindowsWindows

ACCESS CONTROL

3.6 Ensure the SQL Server's SQLAgent Service Account is Not an AdministratorCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.7 Ensure the SQL Server's Full-Text Service Account is Not an AdministratorCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.7 Ensure the SQL Server's Full-Text Service Account is Not an AdministratorCIS Microsoft SQL Server 2025 v1.0.0 L1 Database Engine WindowsWindows

ACCESS CONTROL

3.14 Ensure 'Control Server' permission is not grantedCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

4.1.1 Ensure the cluster-admin ClusterRole is only used when requiredCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

ACCESS CONTROL

4.1.6 Avoid granting cluster admin level access through the system:masters groupCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

ACCESS CONTROL

4.1.8 Ensure that the client certificate authorities file ownership is set to root:rootCIS Kubernetes v2.0.1 L1 Worker NodeUnix

ACCESS CONTROL

4.1.9 Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictiveCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

4.2 Ensure sudo is configured correctlyCIS PostgreSQL 17 v1.1.0 L1 OS Linux UnixUnix

ACCESS CONTROL

4.3.1 Ensure sudo is installedCIS CentOS Linux 7 v4.0.0 L1 ServerUnix

ACCESS CONTROL

4.3.2 Ensure sudo commands use ptyCIS Amazon Linux 2023 v1.0.0 L1 ServerUnix

ACCESS CONTROL

4.8 Ensure the set_user extension is installedCIS PostgreSQL 13 v1.3.0 L1 Database PostgreSQLDBPostgreSQLDB

ACCESS CONTROL

5.2 Ensure Options for the Web Root Directory Are RestrictedCIS Apache HTTP Server 2.4 v2.3.0 L2Unix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Rocky Linux 8 v3.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Rocky Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.1 Privilege escalation: sudoCIS IBM AIX 7.1 L2 v2.1.0Unix

ACCESS CONTROL

5.2.6 Ensure sudo authentication timeout is configured correctlyCIS Oracle Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.2.6 Ensure sudo authentication timeout is configured correctlyCIS Red Hat Enterprise Linux 9 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.6 Ensure sudo timestamp_timeout is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.6 Minimize the admission of containers with allowPrivilegeEscalationCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

5.3 Ensure 'PROCESS' is Not Granted to Non-Administrative UsersCIS Oracle MySQL Community Server 9.7 v1.0.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

5.3.1 Ensure that Azure Admin Accounts Are Not Used for Daily OperationsCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

5.3.2 Ensure sudo commands use ptyCIS CentOS Linux 8 Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.3.4 Ensure users must provide password for escalationCIS CentOS Linux 8 Server L2 v2.0.0Unix

ACCESS CONTROL

5.3.5 Ensure re-authentication for privilege escalation is not disabled globallyCIS CentOS Linux 8 Server L1 v2.0.0Unix

ACCESS CONTROL

5.3.6 Ensure 'Tenant Creator' Role Assignments are Periodically ReviewedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

5.5 Ensure the 'root' Account Is DisabledCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

ACCESS CONTROL

5.5 Ensure the "root" Account Is DisabledCIS Apple macOS 12.0 Monterey v4.0.0 L1Unix

ACCESS CONTROL

5.6 Adding authorised users in cron.allowCIS IBM AIX 7.1 L1 v2.1.0Unix

ACCESS CONTROL

9.7 Verify No UID 0 Accounts Exist Other than rootCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL

10.2 Restrict access to the web administration applicationCIS Apache Tomcat 10 L1 v1.1.0 MiddlewareUnix

ACCESS CONTROL

10.2 Restrict access to the web administration applicationCIS Apache Tomcat 9 L1 v1.2.0 MiddlewareUnix

ACCESS CONTROL

10.3 Restrict manager applicationCIS Apache Tomcat 11 v1.0.0 L2Unix

ACCESS CONTROL

10.3 Restrict manager applicationCIS Apache Tomcat 9 L2 v1.2.0Unix

ACCESS CONTROL

10.13 Do not run applications as privilegedCIS Apache Tomcat 9 L1 v1.2.0Unix

ACCESS CONTROL

10.17 Setting Security Lifecycle Listener - check for config componentCIS Apache Tomcat 9 L1 v1.2.0Unix

ACCESS CONTROL

10.17 Setting Security Lifecycle Listener - check for config componentCIS Apache Tomcat 9 L1 v1.2.0 MiddlewareUnix

ACCESS CONTROL

10.17 Setting Security Lifecycle Listener - check for umask uncommented in startupCIS Apache Tomcat 9 L1 v1.2.0 MiddlewareUnix

ACCESS CONTROL

18.9.90.2 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DCWindows

ACCESS CONTROL