Item Search

NameAudit NamePluginCategory
1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1Windows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 NGWindows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

2.1.1 Ensure that Azure Databricks is deployed in a customer-managed virtual network (VNet)CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1.6 Ensure that Usage is Restricted and Expiry is Enforced for Databricks Personal Access TokensCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

2.1.9 Ensure 'No Public IP' is Set to 'Enabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

2.1.10 Ensure 'Allow Public Network Access' is set to 'Disabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

5.3.2 Ensure that Guest Users are Reviewed on a Regular BasisCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

5.3.3 Ensure That Use of the 'User Access Administrator' Role is RestrictedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.3.4 Ensure that All 'Privileged' Role Assignments are Periodically ReviewedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.4.1.1 Ensure password expiration is 365 days or less - usersCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.1 Ensure password expiration is 365 days or less - usersCIS Distribution Independent Linux Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.7 Ensure there are between 2 and 3 Subscription OwnersCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

6.1.1.1 Ensure that a 'Diagnostic Setting' Exists for Subscription Activity LogsCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.1.2 Ensure Diagnostic Setting Captures Appropriate CategoriesCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.1 Ensure that Activity Log Alert Exists for Create Policy AssignmentCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.2 Ensure that Activity Log Alert exists for Delete Policy AssignmentCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.4 Ensure that Activity Log Alert Exists for Delete Network Security GroupCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.6 Ensure that Activity Log Alert Exists for Delete Security SolutionCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.7 Ensure that Activity Log Alert Exists for Create or Update SQL Server Firewall RuleCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.8 Ensure that Activity Log Alert Exists for Delete SQL Server Firewall RuleCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.9 Ensure that Activity Log Alert Exists for Create or Update Public IP Address ruleCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.10 Ensure that Activity Log Alert Exists for Delete Public IP Address ruleCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.4 Ensure that Azure Monitor Resource Logging is Enabled for All Services that Support itCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

7.1 Ensure that RDP Access from the Internet is Evaluated and RestrictedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Ensure that SSH Access from the Internet is Evaluated and RestrictedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.4 Ensure that HTTP(S) Access from the Internet is Evaluated and RestrictedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.12 Ensure the SSL Policy's 'Min protocol version' is Set to 'TLSv1_2' or Higher on Azure Application GatewayCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.1.10 Ensure that Microsoft Defender for Cloud is Configured to Check VM Operating Systems for UpdatesCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

8.1.11 Ensure that non-deprecated Microsoft Cloud Security Benchmark policies are not set to 'Disabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

8.1.13 Ensure 'Additional email addresses' is Configured with a Security Contact EmailCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

INCIDENT RESPONSE

8.1.14 Ensure that 'Notify about alerts with the following severity (or higher)' is EnabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

8.1.15 Ensure that 'Notify about attack paths with the following risk level (or higher)' is EnabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

8.3.1 Ensure that the Expiration Date is Set for all Keys in Key Vaults using RBACCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

8.3.3 Ensure that the Expiration Date is set for All Secrets in Key Vaults using RBACCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

8.3.4 Ensure that the Expiration Date is set for All Secrets in Key Vaults using access policies (legacy)CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

8.3.5 Ensure 'Purge protection' is Set to 'Enabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONTINGENCY PLANNING

8.3.7 Ensure Public Network Access is DisabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

8.3.11 Ensure Certificate 'Validity Period (in months)' is Less Than or Equal to '12'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONFIGURATION MANAGEMENT, MAINTENANCE

9.1.1 Ensure Soft Delete for Azure File Shares is EnabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONTINGENCY PLANNING

9.3.1.3 Ensure 'Allow storage account key access' for Azure Storage Accounts is 'Disabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

9.3.2.3 Ensure Default Network Access Rule for Storage Accounts is Set to DenyCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

9.3.4 Ensure that 'Secure transfer required' is Set to 'Enabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

9.3.7 Ensure 'Cross Tenant Replication' is Not EnabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

9.3.8 Ensure that 'Allow Blob Anonymous Access' is Set to 'Disabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

9.3.9 Ensure Azure Resource Manager Delete Locks are Applied to Azure Storage AccountsCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

18.9.5.4 Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

18.9.5.6 Ensure 'Turn On Virtualization Based Security: Secure Launch Configuration' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

MSCT_Microsoft_365_Apps_for_Enterprise_2206_v1.0.0.audit from MSCT Microsoft 365 Apps for Enterprise 2206 FINAL BaselineMSCT Microsoft 365 Apps for Enterprise 2206 v1.0.0Windows