Item Search

NameAudit NamePluginCategory
1.1.5.1 Ensure 'Enable Automatic Updates' is set to 'Enabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.5.2 Ensure 'Hide option to enable or disable updates' is set to 'Enabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.2.4.7.2.11 Ensure 'Require that application add-ins are signed by Trusted Publisher' is set to 'Enabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

2.2.26 Ensure 'Deny log on as a service' to include 'No one' (STIG DC only)CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG DCWindows

ACCESS CONTROL

2.2.27 Ensure 'Deny log on as a service' to include 'Enterprise Admins Group and Domain Admins Group' (STIG MS only)CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG MSWindows

ACCESS CONTROL

2.2.29 Ensure 'Deny log on as a service' to include 'No one' (STIG DC only)CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG DCWindows

ACCESS CONTROL

2.2.30 Ensure 'Deny log on as a service' to include 'Enterprise Admins Group and Domain Admins Group' (STIG MS only)CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG MSWindows

ACCESS CONTROL

2.3.14.1 Ensure 'System cryptography: Force strong key protection for user keys stored on the computer' is set to 'User must enter a password each time they use a key'CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG MSWindows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.14.1 Ensure 'System cryptography: Force strong key protection for user keys stored on the computer' is set to 'User must enter a password each time they use a key'CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG DCWindows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.14.1 Ensure 'System cryptography: Force strong key protection for user keys stored on the computer' is set to 'User must enter a password each time they use a key' (STIG only)CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG MSWindows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.19.5 (L1) Ensure 'Prevent users from changing permissions on rights managed content' is set to 'Disabled'CIS Microsoft Intune for Office v1.1.0 L1Windows

ACCESS CONTROL, MEDIA PROTECTION

2.3.27.8 (L1) Ensure 'Control how Office handles form-based sign-in prompts' is set to 'Enabled: Block all prompts'CIS Microsoft Intune for Office v1.1.0 L1Windows

CONFIGURATION MANAGEMENT

2.3.39.2 (L1) Ensure 'Automatically receive small updates to improve reliability' is set to 'Disabled'CIS Microsoft Intune for Office v1.1.0 L1Windows

CONFIGURATION MANAGEMENT

2.17.1 Ensure 'Prevent Users From Changing Permissions on Rights Managed Content' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

ACCESS CONTROL

2.25.5 Ensure 'Protect Document Metadata for Rights Managed Office Open XML Files' is set to EnabledCIS Microsoft Office 2016 v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.1 Set 'Automatically receive small updates to improve reliability' to 'Disabled'CIS MS Office Outlook 2010 v1.0.0Windows

CONFIGURATION MANAGEMENT

5.6 Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Windows 7 Workstation Level 1 v3.2.0Windows

CONFIGURATION MANAGEMENT

5.6 Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT

5.7 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT

5.8 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

5.9 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

5.9 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

5.9 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NGWindows

CONFIGURATION MANAGEMENT

5.9 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

5.9 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

5.9 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

CONFIGURATION MANAGEMENT

20.7 Ensure 'Active Directory Group Policy objects have proper access control permissions' (STIG DC only)CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG DCWindows

ACCESS CONTROL

20.7 Ensure 'Active Directory Group Policy objects have proper access control permissions' (STIG DC only)CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG DCWindows

ACCESS CONTROL

20.29 Ensure 'FTP servers are configured to prevent access to the system drive' (STIG only)CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG DCWindows

ACCESS CONTROL

20.29 Ensure 'FTP servers are configured to prevent access to the system drive' (STIG only)CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG MSWindows

ACCESS CONTROL

22.9 (L1) Ensure 'ASR: Block all Office applications from creating child processes' is set to 'Audit' or higherCIS Microsoft Intune for Windows 10 v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

22.9 (L1) Ensure 'ASR: Block all Office applications from creating child processes' is set to 'Audit' or higherCIS Microsoft Intune for Windows 11 v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

22.13 (L1) Ensure 'ASR: Block execution of potentially obfuscated scripts' is set to 'Audit' or higherCIS Microsoft Intune for Windows 10 v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

22.13 (L1) Ensure 'ASR: Block execution of potentially obfuscated scripts' is set to 'Audit' or higherCIS Microsoft Intune for Windows 11 v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO119 - Configuration for file validation must be enforced.DISA STIG Microsoft Word 2013 v1r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO119 - Configuration for file validation must be enforced.DISA STIG Microsoft PowerPoint 2013 v1r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO119 - Configuration for file validation must be enforced.DISA STIG Microsoft Excel 2013 v1r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO170 - InfoPath - InfoPath 2003 forms as email forms in InfoPath 2010 must be disallowed.DISA STIG Office 2010 InfoPath v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO178 - Office System - Upload of document templates to Office Online must be prevented.DISA STIG Office System 2010 v1r13Windows

CONFIGURATION MANAGEMENT

DTOO204 - External Signature Services Menu for Office must be suppressed.DISA STIG Microsoft Office System 2013 v2r2Windows

CONFIGURATION MANAGEMENT

DTOO208 - Office client polling of SharePoint servers published links must be disabled.DISA STIG Microsoft Office System 2013 v2r2Windows

ACCESS CONTROL

DTOO307 - Office System - Office Live Workspace Integration must be off.DISA STIG Office System 2010 v1r13Windows

CONFIGURATION MANAGEMENT

VCUI-67-000027 - vSphere UI log files must be moved to a permanent repository in accordance with site policy - accessDISA STIG VMware vSphere 6.7 UI Tomcat v1r3Unix

AUDIT AND ACCOUNTABILITY

WN11-00-000160 - The Server Message Block (SMB) v1 protocol must be disabled on the system.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-UR-000085 - The 'Deny log on locally' user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.DISA Microsoft Windows 11 STIG v2r4Windows

ACCESS CONTROL

WN12-00-000180 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB client - LanManWorkstationDISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WPAW-00-001060 - Device Guard Code Integrity Policy must be used on the Windows PAW to restrict applications that can run on the system (Device Guard User Mode Code Integrity).DISA MS Windows Privileged Access Workstation v3r2Windows

CONFIGURATION MANAGEMENT

WPAW-00-001400 - PAWs used to manage Active Directory must only allow groups specifically designated to manage Active Directory, such as Enterprise and Domain Admins and members of the local Administrators group, to log on locally.DISA MS Windows Privileged Access Workstation v3r2Windows

CONFIGURATION MANAGEMENT

WPAW-00-001500 - In a Windows PAW, administrator accounts used for maintaining the PAW must be separate from administrative accounts used to manage high-value IT resources.DISA MS Windows Privileged Access Workstation v3r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WPAW-00-001800 - If several Windows PAWs are set up in virtual machines (VMs) on a host server, the host server must only contain PAW VMs. If the PAW is hosted, the hosting system must be separated either physically or logically from other servers. The server is restricted to only PAW hosting functions - VMs on a host server, the host server must only contain PAW VMs.DISA MS Windows Privileged Access Workstation v3r2Windows

CONFIGURATION MANAGEMENT