Item Search

NameAudit NamePluginCategory
2.5 (L1) Host must only run binaries delivered via signed VIBCIS VMware ESXi 8.0 v1.2.0 L1VMware

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

5.1.2 Ensure Apple Mobile File Integrity (AMFI) Is EnabledCIS Apple macOS 12.0 Monterey Cloud-tailored v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.2 Ensure Apple Mobile File Integrity (AMFI) Is EnabledCIS Apple macOS 13.0 Ventura Cloud-tailored v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.3 Ensure Apple Mobile File Integrity (AMFI) Is EnabledCIS Apple macOS 12.0 Monterey v4.0.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.3 Ensure Apple Mobile File Integrity (AMFI) Is EnabledCIS Apple macOS 13.0 Ventura v3.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.3 Ensure Apple Mobile File Integrity (AMFI) Is EnabledCIS Apple macOS 14.0 Sonoma v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.3 Ensure Apple Mobile File Integrity (AMFI) Is EnabledCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.3 Ensure Apple Mobile File Integrity (AMFI) Is EnabledCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.3 Ensure Apple Mobile File Integrity Is EnabledCIS Apple macOS 10.14 v2.0.0 L1Unix

CONFIGURATION MANAGEMENT

5.1.4 Ensure Library Validation Is EnabledCIS Apple macOS 10.14 v2.0.0 L1Unix

CONFIGURATION MANAGEMENT

6.13 Ensure that 'User consent for applications' is set to 'Allow user consent for apps from verified publishers, for selected permissions'CIS Microsoft Azure Foundations v4.0.0 L2microsoft_azure

CONFIGURATION MANAGEMENT

6.14 Ensure that 'Users can register applications' is set to 'No'CIS Microsoft Azure Foundations v4.0.0 L1microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT

20.3 (L1) Ensure 'Microsoft Internet Explorer is not installed on the system'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

ALMA-09-025980 - AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.DISA CloudLinux AlmaLinux OS 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

ALMA-09-027850 - AlmaLinux OS 9 must mount /var with the nodev option.DISA CloudLinux AlmaLinux OS 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

DTOO210 - The opening of pre-release versions of file formats new to Excel 2013 through the Compatibility Pack for Office 2013 and Excel 2013 Converter must be blocked.DISA STIG Microsoft Excel 2013 v1r8Windows

CONFIGURATION MANAGEMENT

DTOO210 - The opening of pre-release versions of file formats new to PowerPoint 2013 through the Compatibility Pack for Office 2013 and PowerPoint 2013 Converter must be blocked.DISA STIG Microsoft PowerPoint 2013 v1r7Windows

CONFIGURATION MANAGEMENT

GEN002420 - Removable media, remote file systems, and any file system that does not contain approved setuid files must be mounted with the 'nosuid' option - /etc/vfstabDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN002420 - Removable media, remote file systems, and any file system that does not contain approved setuid files must be mounted with the 'nosuid' option - /etc/vfstabDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN002420 - Removable media, remote file systems, and any file system that does not contain approved setuid files must be mounted with the 'nosuid' option - zfs getDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GOOG-12-006600 - Google Android 12 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

HONW-13-006600 - Honeywell Android 13 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Honeywell Android 13 COBO v1r1MDM

CONFIGURATION MANAGEMENT

HONW-13-006600 - Honeywell Android 13 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Honeywell Android 13 COPE v1r1MDM

CONFIGURATION MANAGEMENT

HONW-13-006600 - Honeywell Android 13 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Honeywell Android 13 COPE v1r1MDM

CONFIGURATION MANAGEMENT

MSFT-11-001000 - Microsoft Android 11 must be configured to enforce an application installation policy by specifying an application allow list that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Microsoft Android 11 COPE v1r2MDM

CONFIGURATION MANAGEMENT

OL08-00-040121 - OL 8 must mount "/dev/shm" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r5Unix

CONFIGURATION MANAGEMENT

OL08-00-040129 - OL 8 must mount "/var/log/audit" with the "nodev" option.DISA Oracle Linux 8 STIG v2r5Unix

CONFIGURATION MANAGEMENT

OL08-00-040130 - OL 8 must mount "/var/log/audit" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r5Unix

CONFIGURATION MANAGEMENT

OL08-00-040131 - OL 8 must mount "/var/log/audit" with the "noexec" option.DISA Oracle Linux 8 STIG v2r5Unix

CONFIGURATION MANAGEMENT

OL08-00-040133 - OL 8 must mount "/var/tmp" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r5Unix

CONFIGURATION MANAGEMENT

OL08-00-040134 - OL 8 must mount "/var/tmp" with the "noexec" option.DISA Oracle Linux 8 STIG v2r5Unix

CONFIGURATION MANAGEMENT

OL09-00-002050 - OL 9 must mount /tmp with the nodev option.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

OL09-00-002052 - OL 9 must mount /tmp with the nosuid option.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

OL09-00-002061 - OL 9 must mount /var/log with the nodev option.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

OL09-00-002062 - OL 9 must mount /var/log with the noexec option.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

OL09-00-002064 - OL 9 must mount /var/log/audit with the nodev option.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

OL09-00-002067 - OL 9 must mount /var/tmp with the nodev option.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

OL09-00-002068 - OL 9 must mount /var/tmp with the noexec option.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

OL09-00-002069 - OL 9 must mount /var/tmp with the nosuid option.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

OL09-00-002070 - OL 9 must prevent device files from being interpreted on file systems that contain user home directories.DISA Oracle Linux 9 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-08-040127 - RHEL 8 must mount /var/log with the nosuid option.DISA Red Hat Enterprise Linux 8 STIG v2r3Unix

CONFIGURATION MANAGEMENT

RHEL-08-040128 - RHEL 8 must mount /var/log with the noexec option.DISA Red Hat Enterprise Linux 8 STIG v2r3Unix

CONFIGURATION MANAGEMENT

RHEL-08-040133 - RHEL 8 must mount /var/tmp with the nosuid option.DISA Red Hat Enterprise Linux 8 STIG v2r3Unix

CONFIGURATION MANAGEMENT

RHEL-09-231045 - RHEL 9 must prevent device files from being interpreted on file systems that contain user home directories.DISA Red Hat Enterprise Linux 9 STIG v2r4Unix

CONFIGURATION MANAGEMENT

RHEL-09-231130 - RHEL 9 must mount /tmp with the noexec option.DISA Red Hat Enterprise Linux 9 STIG v2r4Unix

CONFIGURATION MANAGEMENT

RHEL-09-231140 - RHEL 9 must mount /var with the nodev option.DISA Red Hat Enterprise Linux 9 STIG v2r4Unix

CONFIGURATION MANAGEMENT

RHEL-09-231180 - RHEL 9 must mount /var/tmp with the noexec option.DISA Red Hat Enterprise Linux 9 STIG v2r4Unix

CONFIGURATION MANAGEMENT

RHEL-09-231185 - RHEL 9 must mount /var/tmp with the nosuid option.DISA Red Hat Enterprise Linux 9 STIG v2r4Unix

CONFIGURATION MANAGEMENT

WN11-CC-000185 - The default autorun behavior must be configured to prevent autorun commands.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN22-CC-000210 - Windows Server 2022 Autoplay must be turned off for nonvolume devices.DISA Microsoft Windows Server 2022 STIG v2r4Windows

CONFIGURATION MANAGEMENT