Item Search

NameAudit NamePluginCategory
1.2.11 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'CIS Cisco IOS XE 16.x v2.1.0 L1Cisco

ACCESS CONTROL

1.7.4 Ensure GDM screen locks when the user is idleCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

ACCESS CONTROL

1.7.4 Ensure GDM screen locks when the user is idleCIS Debian Linux 11 v2.0.0 L1 ServerUnix

ACCESS CONTROL

1.7.5 Ensure GDM screen locks cannot be overriddenCIS Debian Linux 11 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

1.8.1 Ensure 'console session timeout' is less than or equal to '5' minutesCIS Cisco ASA 9.x Firewall L1 v1.1.0Cisco

ACCESS CONTROL

1.8.4 Ensure GDM screen locks when the user is idleCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL

1.8.4 Ensure GDM screen locks when the user is idleCIS AlmaLinux OS 8 Server L1 v3.0.0Unix

ACCESS CONTROL

1.8.4 Ensure GDM screen locks when the user is idleCIS Oracle Linux 9 v2.0.0 L1 ServerUnix

ACCESS CONTROL

1.8.5 Ensure GDM screen locks cannot be overriddenCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL

1.8.5 Ensure GDM screen locks cannot be overriddenCIS Oracle Linux 8 Workstation L1 v3.0.0Unix

ACCESS CONTROL

1.8.5 Ensure GDM screen locks cannot be overriddenCIS Rocky Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

2.2.1.1 Ensure 'Allow voice dialing while device is locked' is set to 'Disabled'MobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.2.1.1 Ensure 'Allow voice dialing while device is locked' is set to 'Disabled'MobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.2.1.14 Ensure 'Show Control Center in Lock screen' is set to 'Disabled'AirWatch - CIS Apple iOS 17 Benchmark v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.2.1.14 Ensure 'Show Control Center in Lock screen' is set to 'Disabled'AirWatch - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.3.1 Ensure an Inactivity Interval of 20 Minutes Or Less for the Screen Saver Is EnabledCIS Apple macOS 12.0 Monterey v4.0.0 L1Unix

ACCESS CONTROL

2.3.2 Ensure Screen Saver Corners Are Secure - bl-cornerCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

ACCESS CONTROL

2.3.2 Ensure Screen Saver Corners Are Secure - br-cornerCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

ACCESS CONTROL

2.3.2 Ensure Screen Saver Corners Are Secure - tl-cornerCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

ACCESS CONTROL

2.3.7.3 (L1) Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0'CIS Microsoft Windows Server 2019 v3.0.1 L1 DCWindows

ACCESS CONTROL

2.3.7.8 (L1) Ensure 'Interactive logon: Require Domain Controller Authentication to unlock workstation' is set to 'Enabled' (MS only)CIS Microsoft Windows Server 2019 v3.0.1 L1 MSWindows

ACCESS CONTROL

2.3.7.9 (L1) Ensure 'Interactive logon: Smart card removal behavior' is set to 'Lock Workstation' or higherCIS Microsoft Windows Server 2019 v3.0.1 L1 MSWindows

ACCESS CONTROL

2.4.4 Ensure 'Maximum Auto-Lock' is set to '2 minutes' or lessMobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.4.4 Ensure 'Maximum Auto-Lock' is set to '2 minutes' or lessMobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

3.2.1.31 Ensure 'Show Control Center in Lock screen' is set to 'Disabled'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL

3.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL

3.4.6 Ensure 'Maximum number of failed attempts' is set to '6'AirWatch - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL

3.4.6 Ensure 'Maximum number of failed attempts' is set to '6'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL

3.7 (L1) Host must automatically terminate idle DCUI sessionsCIS VMware ESXi 8.0 v1.2.0 L1VMware

ACCESS CONTROL

3.8 (L1) Host must automatically terminate idle shellsCIS VMware ESXi 8.0 v1.2.0 L1VMware

ACCESS CONTROL

3.9.1 Ensure 'If Lost, Return to...' Message is 'Configured'AirWatch - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL

3.9.1 Ensure 'If Lost, Return to...' Message is 'Configured'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL

3.13 (L1) Host must unlock accounts after a specified timeout periodCIS VMware ESXi 8.0 v1.2.0 L1VMware

ACCESS CONTROL

4.4 (L1) Ensure account lockout is set to 15 minutesCIS VMware ESXi 7.0 v1.5.0 L1VMware

ACCESS CONTROL

4.5.10 (L1) Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' is set to 'Enabled: 5 or fewer seconds'CIS Microsoft Intune for Windows 10 v4.0.0 L1Windows

ACCESS CONTROL

5.2.2.4 (L1) Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative usersCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

ACCESS CONTROL

5.3 Ensure the Sudo Timeout Period Is Set to ZeroCIS Apple macOS 15.0 Sequoia Cloud-tailored v1.0.0 L1Unix

ACCESS CONTROL

5.3 Ensure the Sudo Timeout Period Is Set to Zero - timestamp timeoutCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

ACCESS CONTROL

5.4 Ensure a Separate Timestamp Is Enabled for Each User/tty ComboCIS Apple macOS 15.0 Sequoia Cloud-tailored v1.0.0 L1Unix

ACCESS CONTROL

5.4 Ensure the Sudo Timeout Period Is Set to ZeroCIS Apple macOS 14.0 Sonoma v2.0.0 L1Unix

ACCESS CONTROL

5.4 Ensure the Sudo Timeout Period Is Set to ZeroCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

ACCESS CONTROL

5.4.3.2 Ensure default user shell timeout is configuredCIS AlmaLinux OS 9 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.4.3.2 Ensure default user shell timeout is configuredCIS Debian Linux 11 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.4.3.2 Ensure default user shell timeout is configuredCIS Red Hat Enterprise Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.4.3.2 Ensure default user shell timeout is configuredCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.5 Ensure a Separate Timestamp Is Enabled for Each User/tty ComboCIS Apple macOS 14.0 Sonoma v2.0.0 L1Unix

ACCESS CONTROL

5.7 Ensure an Administrator Account Cannot Login to Another User's Active and Locked SessionCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

ACCESS CONTROL

5.11 Ensure Logging Is Enabled for SudoCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

ACCESS CONTROL

18.5.9 (L1) Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires' is set to 'Enabled: 5 or fewer seconds'CIS Microsoft Windows Server 2019 v3.0.1 L1 MSWindows

ACCESS CONTROL

49.8 (L1) Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0'CIS Microsoft Intune for Windows 10 v4.0.0 L1Windows

ACCESS CONTROL