Item Search

NameAudit NamePluginCategory
1.2.9 - System account lockdown - 'bin login=false rlogin=false'CIS AIX 5.3/6.1 L2 v1.1.0Unix

ACCESS CONTROL

1.2.9 - System account lockdown - 'daemon login=false rlogin=false'CIS AIX 5.3/6.1 L2 v1.1.0Unix

ACCESS CONTROL

1.2.9 - System account lockdown - 'lpd login=false rlogin=false'CIS AIX 5.3/6.1 L2 v1.1.0Unix

ACCESS CONTROL

1.2.9 - System account lockdown - 'nobody login=false rlogin=false'CIS AIX 5.3/6.1 L2 v1.1.0Unix

ACCESS CONTROL

1.2.9 - System account lockdown - 'uucp login=false rlogin=false'CIS AIX 5.3/6.1 L2 v1.1.0Unix

ACCESS CONTROL

1.03 Windows Oracle Domain Account - 'Use Restricted Service Account (RSA)'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows

ACCESS CONTROL

1.3.3 Ensure that the --use-service-account-credentials argument is set to trueCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

1.3.3 Ensure that the --use-service-account-credentials argument is set to trueCIS Kubernetes v1.11.1 L1 Master NodeUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

1.5 Configure 'Do not allow users to enable or disable add-ons'CIS IE 10 v1.1.0Windows

ACCESS CONTROL

1.05 Windows Oracle Domain Global Group - 'Create a global group for the RSA and make it the RSA's primary group'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows

ACCESS CONTROL

2.2 Give the BIND User Account an Invalid ShellCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

ACCESS CONTROL

2.2 Give the BIND User Account an Invalid ShellCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

ACCESS CONTROL

2.3.10.5 Ensure 'Network access: Let Everyone permissions apply to anonymous users' is set to 'Disabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.7.1 Ensure 'Notification Settings' are configured for all 'Managed Apps'AirWatch - CIS Apple iOS 13 and iPadOS 13 v1.0.0 End User Owned L1MDM

ACCESS CONTROL

2.7.5 - SNMP - disable Readwrite community - 'no communities have readWrite set'CIS AIX 5.3/6.1 L2 v1.1.0Unix

ACCESS CONTROL

2.16.3 - General permissions management - world writable files - 'no world writable directories exist'CIS AIX 5.3/6.1 L2 v1.1.0Unix

ACCESS CONTROL

3.1 Configure 'Prevent deleting websites that the user has visited'CIS IE 10 v1.1.0Windows

ACCESS CONTROL

3.2 Configure 'Prevent Deleting Cookies'CIS IE 10 v1.1.0Windows

ACCESS CONTROL

3.5 Configure 'Prevent Deleting Temporary Internet Files'CIS IE 10 v1.1.0Windows

ACCESS CONTROL

3.6 Review Superuser/Admin Roles - dbAdminAnyDatabaseCIS MongoDB 3.2 Database Audit L2 v1.0.0MongoDB

ACCESS CONTROL

3.6 Review Superuser/Admin Roles - dbOwnerCIS MongoDB 3.2 Database Audit L2 v1.0.0MongoDB

ACCESS CONTROL

3.6 Review Superuser/Admin Roles - readWriteAnyDatabaseCIS MongoDB 3.2 Database Audit L2 v1.0.0MongoDB

ACCESS CONTROL

3.11 Block non-privileged mountd requestsCIS FreeBSD v1.0.5Unix

ACCESS CONTROL

4.01 init.ora - '_trace_file_public = FALSE'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows

ACCESS CONTROL

4.01 init.ora - '_trace_files_public = FALSE'CIS v1.1.0 Oracle 11g OS L1Unix

ACCESS CONTROL

4.2 Ensure All Sample Data And Users Have Been RemovedCIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

ACCESS CONTROL

4.2 Ensure All Sample Data And Users Have Been RemovedCIS Oracle Server 18c DB Unified Auditing v1.1.0OracleDB

ACCESS CONTROL

4.4 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end-user owned devicesMobileIron - CIS Apple iOS 13 and iPadOS 13 v1.0.0 End User Owned L1MDM

ACCESS CONTROL

4.4 Ensure 'Find My iPhone/iPad' is set to 'Enabled' on end-user owned devicesMobileIron - CIS Apple iOS 14 and iPadOS 14 v1.0.0 End User Owned L1MDM

ACCESS CONTROL

4.12 init.ora - 'sql92_security = TRUE'CIS v1.1.0 Oracle 11g OS L2Unix

ACCESS CONTROL

4.12 init.ora - 'sql92_security = TRUE'CIS v1.1.0 Oracle 11g OS Windows Level 2Windows

ACCESS CONTROL

5.5 Ensure the Default CGI Content printenv Script Is RemovedCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

5.6 Ensure the Default CGI Content test-cgi Script Is RemovedCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

5.6 Ensure the Default CGI Content test-cgi Script Is RemovedCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

5.6 Set 'Disable changing certificate settings' to 'Enabled'CIS IE 10 v1.1.0Windows

ACCESS CONTROL

6.4 Find world writable filesCIS FreeBSD v1.0.5Unix

ACCESS CONTROL

7.1 Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zoneCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

ACCESS CONTROL

8.1.31 Set 'Software channel permissions' to 'Enabled:High safety'CIS IE 10 v1.1.0Windows

ACCESS CONTROL

8.3.33 Set 'Software channel permissions' to 'Enabled:High safety'CIS IE 10 v1.1.0Windows

ACCESS CONTROL

9.1.1 (L1) Ensure guest user access is restrictedCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

9.1.8 (L1) Ensure enabling of external data sharing is restrictedCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

14.12 Screening router - 'Implement to restrict access to database host'CIS v1.1.0 Oracle 11g OS Windows Level 2Windows

ACCESS CONTROL

18.9.7.1.2 (L1) Ensure 'Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL, MEDIA PROTECTION

Enables or disables Windows Game Recording and BroadcastingMSCT Windows 11 v23H2 v1.0.0Windows

ACCESS CONTROL, CONFIGURATION MANAGEMENT

FireEye - AAA LDAP binding user should not be an adminTNS FireEyeFireEye

ACCESS CONTROL

Network access: Let Everyone permissions apply to anonymous usersMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Network access: Restrict anonymous access to Named Pipes and SharesMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Network access: Restrict anonymous access to Named Pipes and SharesMSCT Windows Server 1903 DC v1.19.9Windows

ACCESS CONTROL

Network access: Restrict anonymous access to Named Pipes and SharesMSCT Windows Server v2004 DC v1.0.0Windows

ACCESS CONTROL

Network access: Restrict anonymous access to Named Pipes and SharesMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL