Item Search

NameAudit NamePluginCategory
1.1 Ensure the Pre-Installation Planning Checklist Has Been ImplementedCIS Apache HTTP Server 2.4 v2.3.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

1.7 Ensure MySQL is Run Under a Sandbox EnvironmentCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.1 Backup Policy in PlaceCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS UnixUnix

CONTINGENCY PLANNING

2.1.2 Verify Backups are GoodCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS UnixUnix

CONTINGENCY PLANNING

2.1.3 Secure Backup CredentialsCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS UnixUnix

ACCESS CONTROL, CONTINGENCY PLANNING, MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1.4 Point-in-Time RecoveryCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

CONTINGENCY PLANNING

2.3.10.4 Ensure 'Network access: Do not allow storage of passwords and credentials for network authentication' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L2 MSWindows

IDENTIFICATION AND AUTHENTICATION

2.3.10.4 Ensure 'Network access: Do not allow storage of passwords and credentials for network authentication' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

IDENTIFICATION AND AUTHENTICATION

2.3.10.4 Ensure 'Network access: Do not allow storage of passwords and credentials for network authentication' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

2.8 Ensure Password Resets Require Strong PasswordsCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

IDENTIFICATION AND AUTHENTICATION

2.10 Use Dual Passwords to Enable Higher Frequency Password RotationCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

IDENTIFICATION AND AUTHENTICATION

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.14 Ensure MySQL is Bound to an IP AddressCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

2.16 Require Client-Side Certificates (X.509)CIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.18 Implement Connection Delays to Limit Failed Login AttemptsCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

4.4 Harden Usage for 'local_infile' on MySQL ClientsCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

CONFIGURATION MANAGEMENT

4.6 Ensure Symbolic Links are DisabledCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

4.9 Ensure 'sql_mode' Contains 'STRICT_ALL_TABLES'CIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

4.10 Use MySQL TDE for At-Rest Data EncryptionCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.2 Ensure 'FILE' is Not Granted to Non-Administrative UsersCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

5.3 Ensure 'PROCESS' is Not Granted to Non-Administrative UsersCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

5.3.3.2.3 Ensure password complexity is configuredCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.5 Ensure 'SHUTDOWN' is Not Granted to Non-Administrative UsersCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

5.6 Ensure 'CREATE USER' is Not Granted to Non-Administrative UsersCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

5.7 Ensure 'GRANT OPTION' is Not Granted to Non-Administrative UsersCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

5.8 Ensure 'REPLICATION SLAVE' is Not Granted to Non-Administrative UsersCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL, MEDIA PROTECTION

5.11 Ensure Proper Use Of 'SET_ANY_DEFINER'CIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

5.12 Ensure Proper Use Of ALLOW_NONEXISTENT_DEFINERCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

6.1 Ensure 'log_error' is configured correctlyCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

AUDIT AND ACCOUNTABILITY

6.2 Ensure Log Files are Stored on a Non-System PartitionCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

AUDIT AND ACCOUNTABILITY

6.3 Ensure 'log_error_verbosity' is Set to '2'CIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

AUDIT AND ACCOUNTABILITY

7.7 Ensure No Anonymous Accounts ExistCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

8.1 Ensure 'require_secure_transport' is Set to 'ON'CIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.3 Set Maximum Connection Limits for Server and per UserCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

9.1 Ensure Replication Traffic is SecuredCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

9.2 Ensure 'SOURCE_SSL_VERIFY_SERVER_CERT' is Set to 'YES' or '1'CIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

CONFIGURATION MANAGEMENT

9.4 Ensure 'super_priv' is Not Set to 'Y' for Replication UsersCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

18.9.11.2.1 (BL) Ensure 'Allow enhanced PINs for startup' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.11.2.2 Ensure 'Choose how BitLocker-protected operating system drives can be recovered' is set to 'Enabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.11.2.2 Ensure 'Choose how BitLocker-protected operating system drives can be recovered' is set to 'Enabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.11.2.3 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

ACCESS CONTROL, CONTINGENCY PLANNING

18.9.11.2.7 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Save BitLocker recovery information to AD DS for operating system drives' is set to 'Enabled: True'CIS Windows 7 Workstation Bitlocker v3.2.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.11.2.16 Ensure 'Require additional authentication at startup: Configure TPM startup key and PIN:' is set to 'Enabled: Do not allow startup key and PIN with TPM'CIS Windows 7 Workstation Bitlocker v3.2.0Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.10.9.1.8 (L1) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.1.8 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Configure storage of BitLocker recovery information to AD DS' is set to 'Enabled: Backup recovery passwords and key packages'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages'CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

MEDIA PROTECTION

18.10.90.1 (L2) Ensure 'Allow Remote Shell Access' is set to 'Disabled'CIS Windows Server 2012 DC L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.10.91.1 Ensure 'Allow Remote Shell Access' is set to 'Disabled'CIS Microsoft Windows Server 2019 v5.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

19.1.3.1 (L1) Ensure 'Enable screen saver' is set to 'Enabled'CIS Windows Server 2012 R2 MS L1 v3.0.0Windows

ACCESS CONTROL

19.1.3.2 (L1) Ensure 'Force specific screen saver: Screen saver executable name' is set to 'Enabled: scrnsave.scr'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

ACCESS CONTROL