Item Search

NameAudit NamePluginCategory
1.2 Ensure that Corporate Login Credentials are UsedCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL

1.2.2.4 Ensure record active speaker, gallery view and shared screen separately is set to enabledCIS Zoom L2 v1.0.0Zoom

CONFIGURATION MANAGEMENT

1.2.3.2 Ensure display participants' names in the recording is set to enabledCIS Zoom L1 v1.0.0Zoom

CONFIGURATION MANAGEMENT

1.2.4.3 Ensure host can pause/stop the auto recording in the cloud is set to enabledCIS Zoom L2 v1.0.0Zoom

CONFIGURATION MANAGEMENT

1.7.2 Ensure 'Select cloud protection level' is set to Enabled: Moderate blocking level' or higherCIS Microsoft Defender Antivirus v1.0.0 L1 ServerWindows

SYSTEM AND INFORMATION INTEGRITY

1.13 Ensure API Keys Only Exist for Active ServicesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

1.15 Ensure API Keys Are Restricted to Only APIs That Application Needs AccessCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

2.5.1.1 Ensure External Intelligence Extensions Is DisabledCIS Apple macOS 15.0 Sequoia v2.1.0 L1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.7.1 iCloud configurationCIS Apple macOS 10.12 L2 v1.2.0Unix

ACCESS CONTROL

3.10 Ensure that VPC Flow Logs is Enabled for Every Subnet in a VPC NetworkCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

4.1 Ensure That Instances Are Not Configured To Use the Default Service AccountCIS Google Cloud Platform Foundation v5.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 15.0 Sequoia Cloud-tailored v1.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 15.0 Sequoia v2.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 12.0 Monterey Cloud-tailored v1.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 13.0 Ventura Cloud-tailored v1.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 26 Tahoe v1.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 12.0 Monterey v4.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 14.0 Sonoma Cloud-tailored v1.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 13.0 Ventura v4.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.4 Ensure http server is not runningCIS Apple OSX 10.9 L1 v1.3.0Unix

CONFIGURATION MANAGEMENT

5.2.1 Use custom least privilege service accounts for GKE node poolsCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

IDENTIFICATION AND AUTHENTICATION

6.1.1 Ensure EBS volume encryption is enabled in all regionsCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.7 Ensure 'contained database authentication' Database Flag for Cloud SQL SQL Server Instance Is Set to 'off'CIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

6.4 Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSLCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.1.3.4 Ensure that 'Agentless scanning for machines' Component Status is Set to 'On'CIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

RISK ASSESSMENT

8.1.6.1 Ensure That Microsoft Defender for App Services Is Set To 'On'CIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION

8.1.8.1 Ensure That Microsoft Defender for Key Vault Is Set To 'On'CIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

RISK ASSESSMENT

8.1.11 Ensure that non-deprecated Microsoft Cloud Security Benchmark policies are not set to 'Disabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.9.14.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DCWindows

CONFIGURATION MANAGEMENT

18.9.14.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled'CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.9.14.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled'CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DCWindows

CONFIGURATION MANAGEMENT

18.9.14.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.10.13.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 DCWindows

ACCESS CONTROL

18.10.13.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

ACCESS CONTROL

18.10.13.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MSWindows

ACCESS CONTROL

33.4 Ensure 'Disable Consumer Account State Content' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v5.0.0 L1Windows

ACCESS CONTROL

54.1 Ensure 'Allow Message Sync' is set to 'message sync is not allowed and cannot be changed by the user.'CIS Microsoft Intune for Windows 11 v5.0.0 L2Windows

CONFIGURATION MANAGEMENT

AADC-CN-000295 - The Adobe Acrobat Pro DC Continuous Send and Track plugin for Outlook must be disabled.DISA STIG Adobe Acrobat Pro DC Continuous Track v2r1Windows

CONFIGURATION MANAGEMENT

AIOS-12-004100 - Apple iOS must not allow backup to remote systems (iCloud).MobileIron - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-12-004100 - Apple iOS must not allow backup to remote systems (iCloud).AirWatch - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-004100 - Apple iOS/iPadOS must not allow backup to remote systems (iCloud).AirWatch - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-004100 - Apple iOS/iPadOS must not allow backup to remote systems (iCloud).MobileIron - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-26-007400 - Apple iOS/iPadOS 26 allow list must be configured to not include applications with the following characteristicsMobileIron - DISA Apple iOS/iPadOS 26 v1r3MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-26-007400 - Apple iOS/iPadOS 26 allow list must be configured to not include applications with the following characteristicsAirWatch - DISA Apple iOS/iPadOS 26 v1r3MDM

IDENTIFICATION AND AUTHENTICATION

AOSX-14-002035 - The macOS system must be configured to disable the Cloud Setup services.DISA STIG Apple Mac OSX 10.14 v2r6Unix

CONFIGURATION MANAGEMENT

AOSX-15-002035 - The macOS system must be configured to disable the Cloud Setup services.DISA STIG Apple Mac OSX 10.15 v1r10Unix

CONFIGURATION MANAGEMENT

APPL-11-002035 - The macOS system must be configured to disable the Cloud Setup services.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

ARDC-CL-000055 - Adobe Reader DC must disable the Adobe Send and Track plugin for Outlook.DISA STIG Adobe Acrobat Reader DC Classic Track v2r1Windows

CONFIGURATION MANAGEMENT

ARDC-CN-000055 - Adobe Reader DC must disable the Adobe Send and Track plugin for Outlook.DISA STIG Adobe Acrobat Reader DC Continuous Track v2r1Windows

CONFIGURATION MANAGEMENT