Item Search

NameAudit NamePluginCategory
1.5.5 Ensure that the --peer-client-cert-auth argument is set to trueCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

ACCESS CONTROL

1.6.1.2 Ensure SELinux is not disabled in bootloader configuration - enforcing=0CIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

1.6.1.2 Ensure SELinux is not disabled in bootloader configuration - selinux=0CIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

1.6.2.3 Ensure SELinux policy is configuredCIS Distribution Independent Linux Server L2 v2.0.0Unix

ACCESS CONTROL

1.6.2.3 Ensure SELinux policy is configuredCIS Distribution Independent Linux Workstation L2 v2.0.0Unix

ACCESS CONTROL

1.6.2.4 Ensure SETroubleshoot is not installedCIS Distribution Independent Linux Server L2 v2.0.0Unix

ACCESS CONTROL

1.7.5 Ensure permissions on /etc/issue are configuredCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

1.7.6 Ensure permissions on /etc/issue.net are configuredCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

2.2.1.8 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 v1.0.0 End User Owned L1MDM

ACCESS CONTROL

2.2.1.9 Ensure 'Allow Handoff' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 v1.0.0 End User Owned L2MDM

ACCESS CONTROL

2.3 Ensure 'Cross DB Ownership Chaining' Server Configuration Option is set to '0'CIS SQL Server 2008 R2 DB Engine L1 v1.7.0MS_SQLDB

ACCESS CONTROL

2.6.1 Ensure 'Allow user to move messages from this account' is set to 'Disabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 v1.0.0 End User Owned L1MDM

ACCESS CONTROL

2.7 Set Group Read-Only for BIND Files and Non-Runtime Directories - filesCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

ACCESS CONTROL

2.8 Set Other Permissions Read-Only for All BIND Directories and Files - filesCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

ACCESS CONTROL

2.10 Ensure 'Trustworthy' Database Property is set to 'Off'CIS SQL Server 2008 R2 DB Engine L1 v1.7.0MS_SQLDB

ACCESS CONTROL

3.2.1.1 Ensure 'Allow screenshots and screen recording' is set to 'Disabled'AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L2MDM

ACCESS CONTROL

3.2.1.19 Ensure 'Allow documents from managed sources in unmanaged destinations' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

ACCESS CONTROL

3.2.1.20 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

ACCESS CONTROL

3.2.1.22 Ensure 'Require Touch ID / Face ID authentication before AutoFill' is set to 'Enabled'AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

ACCESS CONTROL

3.2.1.22 Ensure 'Require Touch ID / Face ID authentication before AutoFill' is set to 'Enabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

ACCESS CONTROL

3.2.1.24 Ensure 'Force Apple Watch wrist detection' is set to 'Enabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

ACCESS CONTROL

3.3.1 Ensure 'Managed Safari Web Domains' is `Configured`AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

ACCESS CONTROL

3.4.4 Ensure permissions on /etc/hosts.allow are configuredCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

3.6.1 Ensure 'Allow user to move messages from this account' is set to 'Disabled'AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

ACCESS CONTROL

3.6.2 Ensure 'Allow Mail Drop' is set to 'Disabled'AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L2MDM

ACCESS CONTROL

3.8 Ensure only the default permissions specified by Microsoft are granted to the public server roleCIS SQL Server 2014 Database L1 DB v1.5.0MS_SQLDB

ACCESS CONTROL

3.9 Ensure Windows BUILTIN groups are not SQL LoginsCIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

ACCESS CONTROL

3.10 Ensure Windows local groups are not SQL LoginsCIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

ACCESS CONTROL

3.10 Ensure Windows local groups are not SQL LoginsCIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

ACCESS CONTROL

4.2.2 Ensure permissions on all logfiles are configuredCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

4.4 Restrict Access to All Key Files - user root/namedCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

ACCESS CONTROL

5.1.1.1 Ensure 'EXECUTE' is revoked from 'PUBLIC' on 'Network' PackagesCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

5.1.2 Ensure permissions on /etc/crontab are configuredCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

5.1.3 Ensure permissions on /etc/cron.hourly are configuredCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.1.8 Ensure cron is restricted to authorized users - cron.denyCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

5.2.2 Ensure permissions on SSH private host key files are configuredCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.2.3 Ensure permissions on SSH public host key files are configuredCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

5.2.10 Minimize the admission of Windows HostProcess ContainersCIS Kubernetes v2.0.1 L1 Master NodeUnix

SYSTEM AND SERVICES ACQUISITION

5.2.11 Ensure SSH PermitUserEnvironment is disabledCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

5.2.11 Ensure SSH PermitUserEnvironment is disabledCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.1.11 Ensure no unowned files or directories existCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

6.1.11 Ensure no unowned files or directories existCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.1.12 Ensure no ungrouped files or directories existCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.1.13 Audit SUID executablesCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.1.14 Audit SGID executablesCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.5 Ensure users' home directories permissions are 750 or more restrictiveCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.7 Ensure no users have .netrc filesCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.2.9 Ensure users own their home directoriesCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.10 Ensure users' dot files are not group or world writableCIS Debian 9 Workstation L1 v1.0.1Unix

ACCESS CONTROL

19.7.26.1 (L1) Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

ACCESS CONTROL