Item Search

NameAudit NamePluginCategory
1.1.11 Ensure that the admission control plugin AlwaysPullImages is setCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

ACCESS CONTROL

1.6.2.4 Ensure SETroubleshoot is not installedCIS Distribution Independent Linux Server L2 v2.0.0Unix

ACCESS CONTROL

1.6.3.2 Ensure all AppArmor Profiles are enforcing - 0 processes are unconfirmedCIS Distribution Independent Linux Workstation L2 v2.0.0Unix

ACCESS CONTROL

2.3 Ensure 'Cross DB Ownership Chaining' Server Configuration Option is set to '0'CIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

ACCESS CONTROL

2.7 Set Group Read-Only for BIND Files and Non-Runtime Directories - directoriesCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

ACCESS CONTROL

2.7 Set Group Read-Only for BIND Files and Non-Runtime Directories - filesCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

ACCESS CONTROL

2.8 Set Other Permissions Read-Only for All BIND Directories and Files - directoriesCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'apache account is configured'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd services are running as apache user'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd.conf Group = apache'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

ACCESS CONTROL

3.2.1 Ensure that the Anonymous Auth is Not Enabled DraftCIS Google Kubernetes Engine (GKE) v1.7.0 L1Unix

ACCESS CONTROL

3.2.1.1 Ensure 'Allow screenshots and screen recording' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L2MDM

ACCESS CONTROL

3.2.1.21 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

ACCESS CONTROL

3.4 Ensure that each role for each MongoDB database is needed and grants only the necessary privilegesCIS MongoDB 4 L1 DB v1.0.0MongoDB

ACCESS CONTROL

3.5 Ensure the Group Is Set Correctly on Apache Directories and FilesCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.8 Ensure only the default permissions specified by Microsoft are granted to the public server roleCIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

ACCESS CONTROL

3.8 Ensure only the default permissions specified by Microsoft are granted to the public server roleCIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

ACCESS CONTROL

3.8 Ensure the Lock File Is Secured - 'LockFile permissions'CIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

3.9 Ensure the Pid File Is SecuredCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.9 Ensure the Pid File Is SecuredCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

3.9 Secure the Pid File - 'PidFile directory'CIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

3.11 Ensure Group Write Access for the Apache Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

3.12 Ensure Group Write Access for the Document Root Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf Deny = from allCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf Deny = from allCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf no Deny directives exist'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf Order = Deny,AllowCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf Require all deniedCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

4.2 Ensure Appropriate Access to Web Content Is Allowed - 'httpd.conf Deny is configured'CIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

4.2 Ensure Appropriate Access to Web Content Is Allowed - 'No Order/Deny/Allow'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

4.4 Ensure OverRide Is Disabled for All DirectoriesCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

4.4 Restrict Access to All Key Files - group root/namedCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

ACCESS CONTROL

4.4 Restrict Access to All Key Files - permissionsCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

ACCESS CONTROL

5.1.3 Ensure permissions on /etc/cron.hourly are configuredCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.1.4 Ensure permissions on /etc/cron.daily are configuredCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.1.4 Ensure permissions on /etc/cron.daily are configuredCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.1.7 Ensure permissions on /etc/cron.d are configuredCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

5.1.8 Ensure cron is restricted to authorized users - cron.allowCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

5.1.8 Ensure cron is restricted to authorized users - cron.denyCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

5.1.9 Ensure at is restricted to authorized users - at.denyCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.2.1 Ensure permissions on /etc/ssh/sshd_config are configuredCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

5.2.1 Ensure permissions on /etc/ssh/sshd_config are configuredCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.2.2 Ensure permissions on SSH private host key files are configuredCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.1.13 Audit SUID executablesCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.6 Ensure users' dot files are not group or world writableCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.9 Ensure users own their home directoriesCIS Debian 9 Server L1 v1.0.1Unix

ACCESS CONTROL

6.2.9 Ensure users own their home directoriesCIS Debian 9 Workstation L1 v1.0.1Unix

ACCESS CONTROL

6.2.10 Ensure users' dot files are not group or world writableCIS Debian 9 Workstation L1 v1.0.1Unix

ACCESS CONTROL

11.2 Ensure Apache Processes Run in the httpd_t Confined ContextCIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix

ACCESS CONTROL