Item Search

NameAudit NamePluginCategory
1.1 Install Updates, Patches and Additional Security SoftwareCIS Ubuntu 12.04 LTS Benchmark L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.1 - AirWatch - Update firmware to latest versionAirWatch - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.1.1 - MobileIron - Update firmware to latest versionMobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

1.1.1 - MobileIron - Update firmware to latest versionMobileIron - CIS Apple iOS 9 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

1.2 Apply Latest OS PatchesCIS Solaris 10 L1 v5.2Unix
1.68 (L1) Ensure 'Configure the list of names that will bypass the HSTS policy check' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

2.03 Minimal Install - 'Ensure that only the Oracle components necessary to your environment are selected for installation'CIS v1.1.0 Oracle 11g OS L1Unix
2.03 Minimal Install - 'Ensure that only the Oracle components necessary to your environment are selected for installation'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows
4.4 Verify Active Directory group membership for the 'ESX Admins' groupCIS VMware ESXi 5.5 v1.2.0 Level 1VMware

ACCESS CONTROL

4.5 Verify Active Directory group membership for the 'ESX Admins' groupCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

5.13 Ensure Access to Inappropriate File Extensions Is RestrictedCIS Apache HTTP Server 2.4 v2.2.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Enable Extension Block ListCIS Mozilla Firefox 38 ESR Linux L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

7.7 Enable Extension Block ListCIS Mozilla Firefox 102 ESR Windows L1 v1.0.0Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

12.05 Sensitive information in process list on host - 'Avoid or encrypt'CIS v1.1.0 Oracle 11g OS L1Unix
12.05 Sensitive information in process list on host - 'Avoid or encrypt'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows
Big Sur - Must Use Host Based Security SolutionNIST macOS Big Sur v1.4.0 - All ProfilesUnix

SYSTEM AND INFORMATION INTEGRITY

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - '$ORACLE_HOME owner, group and permissions are configured'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0040-ORACLE11 - The DBMS software installation account should be restricted to authorized users - 'Oracle install account is disabled'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

ACCESS CONTROL

DTAVSEL-011 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner maximum scan time must not be less than 45 seconds - default.scanMaxTmoMcAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-011 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner maximum scan time must not be less than 45 seconds - scanMaxTmoMcAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-100 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x must be configured to run a scheduled On-Demand scan at least once a week.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-112 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Demand scanner must be configured to decode MIME encoded files.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

FireEye - A scheduled system backup job is configuredTNS FireEyeFireEye

CONTINGENCY PLANNING

FireEye - AAA lockout settings apply to the 'admin' userTNS FireEyeFireEye

ACCESS CONTROL

FireEye - AAA lockouts delay further attempts for at least 30 secondsTNS FireEyeFireEye

ACCESS CONTROL

FireEye - Binary analysis AV-suite is enabledTNS FireEyeFireEye

SYSTEM AND INFORMATION INTEGRITY

FireEye - CLI commands do not hide any settings from administratorsTNS FireEyeFireEye

CONFIGURATION MANAGEMENT

FireEye - IPMI password needs to be setTNS FireEyeFireEye
FireEye - LDAP requires encryptionTNS FireEyeFireEye

SYSTEM AND COMMUNICATIONS PROTECTION

FireEye - Local logging level includes all errors and warningsTNS FireEyeFireEye

AUDIT AND ACCOUNTABILITY

FireEye - Local logging level is not overridden except by defaultsTNS FireEyeFireEye

AUDIT AND ACCOUNTABILITY

FireEye - Local logging retention configurationTNS FireEyeFireEye

AUDIT AND ACCOUNTABILITY

FireEye - Management interface is only accessible from specific IP rangesTNS FireEyeFireEye

SYSTEM AND COMMUNICATIONS PROTECTION

FireEye - NTP client is synchronizedTNS FireEyeFireEye

AUDIT AND ACCOUNTABILITY

FireEye - NTP client uses a custom serverTNS FireEyeFireEye

AUDIT AND ACCOUNTABILITY

FireEye - SNMP is enabledTNS FireEyeFireEye
FireEye - SNMP v3 uses SHA instead of MD5TNS FireEyeFireEye

ACCESS CONTROL

FireEye - System events are emailed to administratorsTNS FireEyeFireEye

SYSTEM AND INFORMATION INTEGRITY

FireEye - Time zone selectionTNS FireEyeFireEye

CONFIGURATION MANAGEMENT

FireEye - Web users are logged out after 20 minutes of inactivity or lessTNS FireEyeFireEye

ACCESS CONTROL

FireEye - YARA rules are enabledTNS FireEyeFireEye

SECURITY ASSESSMENT AND AUTHORIZATION

GEN000940-ESXI5-000042 - The root accounts executable search path must be the vendor default and must contain only absolute paths.DISA STIG VMWare ESXi Server 5 STIG v2r1VMware

CONFIGURATION MANAGEMENT

GEN000945 - The root account's library search path must be the system default and must contain only absolute paths.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000945 - The root account's library search path must be the system default and must contain only absolute paths.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

List VLANsTNS Citrix HypervisorUnix

CONFIGURATION MANAGEMENT

O112-OS-004600 - Use of the DBMS software installation account must be restricted.DISA STIG Oracle 11.2g v2r5 DatabaseOracleDB

CONFIGURATION MANAGEMENT

vCenter : secure-vco-file-accessVMWare vSphere 5.X Hardening GuideVMware
WDNS-SC-000027 - The Windows 2012 DNS Server must use DNS Notify to prevent denial of service through increase in workload.DISA Microsoft Windows 2012 Server DNS STIG v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-GE-000025 - The system must query the certification authority to determine whether a public key certificate has been revoked before accepting the certificate for authentication purposes.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-GE-000025 - The system must query the certification authority to determine whether a public key certificate has been revoked before accepting the certificate for authentication purposes.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT