Item Search

NameAudit NamePluginCategory
1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Windows Server 2012 MS L1 v3.0.0Windows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BLWindows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

2.1.2 Ensure that Network Security Groups are Configured for Databricks SubnetsCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1.4 Ensure that Users and Groups are Synced from Microsoft Entra ID to Azure DatabricksCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

2.1.5 Ensure that Unity Catalog is Configured for Azure DatabricksCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

2.1.7 Ensure that Diagnostic Log Delivery is Configured for Azure DatabricksCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

2.2.4.7.2.3.1 (L1) Ensure 'Always open untrusted database files in Protected View' is set to 'Enabled'CIS Microsoft Intune for Office v1.1.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum SizeCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum Size - all_maxCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum Size - ttlCIS Apple macOS 10.14 v2.0.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum Size - ttlCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.5.1.2 Ensure password expiration is 365 days or lessCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION

4.5.1.2 Ensure password expiration is 365 days or lessCIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION

5.3.1 Ensure that Azure Admin Accounts Are Not Used for Daily OperationsCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

5.3.6 Ensure 'Tenant Creator' Role Assignments are Periodically ReviewedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

5.3.7 Ensure All Non-privileged Role Assignments are Periodically ReviewedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.4 Ensure that No Custom Subscription Administrator Roles ExistCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.4.1.1 Ensure password expiration is 365 days or less - login.defsCIS Distribution Independent Linux Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.1 Ensure password expiration is 365 days or less - login.defsCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.1 Ensure password expiration is 365 days or less - login.defsCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.1 Ensure password expiration is 365 days or less - usersCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.1.1.4 Ensure that Logging for Azure Key Vault is 'Enabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.5 Ensure that Activity Log Alert Exists for Create or Update Security SolutionCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.2.11 Ensure that an Activity Log Alert Exists for Service HealthCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

AUDIT AND ACCOUNTABILITY

7.11 Ensure Subnets Are Associated with Network Security GroupsCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.13 Ensure 'HTTP2' is Set to 'Enabled' on Azure Application GatewayCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SYSTEM AND SERVICES ACQUISITION

8.3.2 Ensure that the Expiration Date is set for All Keys in Key Vaults using access policies (legacy)CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

9.1.2 Ensure 'SMB protocol version' is Set to 'SMB 3.1.1' or Higher for SMB file sharesCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

9.1.3 Ensure 'SMB channel encryption' is Set to 'AES-256-GCM' or Higher for SMB file sharesCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

9.2.1 Ensure That Soft Delete for Blobs on Azure Blob Storage Storage Accounts is EnabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONTINGENCY PLANNING

9.2.2 Ensure that Soft Delete for Containers on Azure Blob Storage Storage Accounts is EnabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONTINGENCY PLANNING

9.3.1.1 Ensure That 'Enable key rotation reminders' is Enabled for Each Storage AccountCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

9.3.1.2 Ensure That Storage Account Access keys are Periodically RegeneratedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MAINTENANCE

9.3.2.2 Ensure that 'Public Network Access' is 'Disabled' for Storage AccountsCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

9.3.3.1 Ensure that 'Default to Microsoft Entra authorization in the Azure portal' is Set to 'Enabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

9.3.6 Ensure the 'Minimum TLS version' for Storage Accounts is Set to 'Version 1.2'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

CIS_DC_SERVER_2012_R2_Level_2_v3.0.0.audit from CIS Microsoft Windows Server 2012 R2 BenchmarkCIS Windows Server 2012 R2 DC L2 v3.0.0Windows
CIS_Microsoft_Exchange_2019_Mailbox_Server_STIG_v1.0.0_CAT_I.audit from CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IWindows
CIS_Microsoft_Exchange_Server_2016_Level_1_CAS_v1.0.0.audit from CIS Microsoft Exchange Server 2016 v1.0.0 BenchmarkCIS Microsoft Exchange Server 2016 CAS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

CIS_Microsoft_Intune_for_Office_v1.1.0_L2.audit from CIS Microsoft Intune for Office Benchmark v1.1.0CIS Microsoft Intune for Office v1.1.0 L2Windows
CIS_Microsoft_Office_PowerPoint_2013_v1.0.1_Level_1.audit from CIS Microsoft Office PowerPoint 2013 Benchmark v1.0.1CIS Microsoft Office PowerPoint 2013 v1.0.1Windows
CIS_Microsoft_Windows_11_Stand-alone_v5.0.0_L1_BL.audit from CIS Microsoft Windows 11 Stand-alone 5.0.0CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows
CIS_MS_Office 2016_v1.1.0.audit from CIS Microsoft Office 2016 Benchmark v1.1.0CIS Microsoft Office 2016 v1.1.0Windows
CIS_MS_SERVER_2012_R2_Level_1_v3.0.0.audit from CIS Microsoft Windows Server 2012 R2 BenchmarkCIS Windows Server 2012 R2 MS L1 v3.0.0Windows
MS.EXO.13.1v1 - Mailbox auditing SHALL be enabled.CISA SCuBA Microsoft 365 Exchange Online v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, IDENTIFICATION AND AUTHENTICATION, INCIDENT RESPONSE, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

MS.EXO.16.2v1 - The alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system.CISA SCuBA Microsoft 365 Exchange Online v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY