Item Search

NameAudit NamePluginCategory
1.7.2 Ensure 'Select cloud protection level' is set to Enabled: Moderate blocking level' or higherCIS Microsoft Defender Antivirus v1.0.0 L1 WorkstationWindows

SYSTEM AND INFORMATION INTEGRITY

1.8 Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or FewerCIS Google Cloud Platform Foundation v5.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

1.134 (L2) Ensure 'Text prediction enabled by default' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

2.6.1.2 Audit iCloud DriveCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.1.3 Audit iCloud DriveCIS Apple macOS 10.14 v2.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.8 Ensure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.81 (L1) Ensure 'Disable synchronization of data with Google' is set to 'Enabled'CIS Google Chrome Group Policy v1.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

3.4 Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSECCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.5 Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSECCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.7 (L1) Ensure 'Disable synchronization of data with Google' is set to 'Enabled'CIS Google Chrome L1 v3.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

4.2 Ensure HTTP Server Is DisabledCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.4 Ensure HTTP Server Is DisabledCIS Apple macOS 10.14 v2.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.4 Ensure http server is not runningCIS Apple macOS 10.13 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

4.5 Ensure ftp server is not runningCIS Apple OSX 10.9 L1 v1.3.0Unix

CONFIGURATION MANAGEMENT

5.4.4 Ensure clusters are created with Private NodesCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.1.2.1 Ensure Microsoft Defender for APIs is Set to 'On'CIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, RISK ASSESSMENT

8.1.10 Ensure that Microsoft Defender for Cloud is Configured to Check VM Operating Systems for UpdatesCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

18.9.47.4.1 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Microsoft Windows Server 2008 R2 Domain Controller Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.9.47.4.1 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Microsoft Windows Server 2008 Domain Controller Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.9.47.4.1 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Microsoft Windows Server 2008 R2 Member Server Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.9.47.4.1 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Microsoft Windows Server 2008 Member Server Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.10.29.2 Ensure 'Turn off account-based insights, recent, favorite, and recommended files in File Explorer' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2Windows

CONFIGURATION MANAGEMENT

18.10.29.2 Ensure 'Turn off account-based insights, recent, favorite, and recommended files in File Explorer' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.0.1 L2Windows

CONFIGURATION MANAGEMENT

18.10.29.2 Ensure 'Turn off account-based insights, recent, favorite, and recommended files in File Explorer' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

18.10.42.5.2 (L1) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.43.5.2 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Windows Server 2012 MS L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.10.43.5.2 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Windows Server 2012 DC L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.10.43.5.2 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Windows Server 2012 R2 DC L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.10.43.5.2 (L2) Ensure 'Join Microsoft MAPS' is set to 'Disabled'CIS Windows Server 2012 R2 MS L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

AIOS-18-015400 - Apple iOS/iPadOS 18 must disable ChatGPT and other external AI app connections in Apple Intelligence.MobileIron - DISA Apple iOS/iPadOS 18 v2r3MDM

CONFIGURATION MANAGEMENT

AIOS-18-015400 - Apple iOS/iPadOS 18 must disable ChatGPT and other external AI app connections in Apple Intelligence.AirWatch - DISA Apple iOS/iPadOS 18 v2r3MDM

CONFIGURATION MANAGEMENT

AIOS-26-015400 - Apple iOS/iPadOS 26 must disable ChatGPT connection for Apple Intelligence.MobileIron - DISA Apple iOS/iPadOS 26 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-26-015400 - Apple iOS/iPadOS 26 must disable ChatGPT connection for Apple Intelligence.AirWatch - DISA Apple iOS/iPadOS 26 v1r3MDM

CONFIGURATION MANAGEMENT

AOSX-14-002037 - The macOS system must be configured to disable the Cloud Storage Setup services.DISA STIG Apple Mac OSX 10.14 v2r6Unix

CONFIGURATION MANAGEMENT

AOSX-15-002037 - The macOS system must be configured to disable the Cloud Storage Setup services.DISA STIG Apple Mac OSX 10.15 v1r10Unix

CONFIGURATION MANAGEMENT

APPL-11-002037 - The macOS system must be configured to disable the Cloud Storage Setup services.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002037 - The macOS system must be configured to disable the Cloud Storage Setup services.DISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-12-002037 - The macOS system must be configured to disable the Cloud Storage Setup services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

Ensure that multi-factor authentication is enabled for all accountsTenable Best Practices RackSpace v2.0.0Rackspace

IDENTIFICATION AND AUTHENTICATION

GOOG-13-008500 - Google Android 13 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Google Android 13 COPE STIG v2r3MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-14-008500 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Google Android 14 COBO STIG v2r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-14-008500 - Google Android 14 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-15-008500 - Google Android 15 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Google Android 15 COBO STIG v1r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-15-008500 - Google Android 15 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Google Android 15 COPE STIG v1r5MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-16-008500 - Google Android 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Google Android 16 COBO STIG v1r3MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-16-008500 - Google Android 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Google Android 16 COPE STIG v1r3MDM

SYSTEM AND COMMUNICATIONS PROTECTION

HONW-09-003700 - The Honeywell Mobility Edge Android Pie device must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Honeywell Android 9.x COPE v1r2MDM

ACCESS CONTROL

PANW-IP-000047 - The Palo Alto Networks security platform must generate a log record when unauthorized network services are detected.DISA Palo Alto Networks IDPS STIG v3r2Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

SYMP-AG-000620 - Symantec ProxySG providing content filtering must generate a log record when access attempts to unauthorized websites and/or services are detected.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

SYSTEM AND INFORMATION INTEGRITY

ZEBR-11-003700 - Zebra Android 11 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Zebra Android 11 COBO STIG v1r4MDM

ACCESS CONTROL