Item Search

NameAudit NamePluginCategory
1.1.1.4 Ensure overlay kernel module is not availableCIS Amazon Linux 2 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS AlmaLinux OS 8 v4.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Debian Linux 12 v2.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Ubuntu Linux 24.04 LTS v2.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Linux Mint 22 v1.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Oracle Linux 10 v1.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Oracle Linux 8 v4.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Rocky Linux 10 v1.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Rocky Linux 10 v1.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Rocky Linux 8 v3.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Red Hat Enterprise Linux 8 v4.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS AlmaLinux OS 10 v1.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Ubuntu Linux 24.04 LTS v2.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Ubuntu Linux 22.04 LTS v3.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Rocky Linux 8 v3.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Debian Linux 13 v1.1.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Ubuntu Linux 20.04 LTS v3.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure overlay kernel module is not availableCIS Ubuntu Linux 20.04 LTS v3.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.1.7 Ensure overlay kernel module is not availableCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

1.7 Ensure MariaDB is Run Under a Sandbox EnvironmentCIS MariaDB 10.6 Database L2 v1.1.0MySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.7.7 Do not admit containers with dangerous capabilitiesCIS Kubernetes 1.13 Benchmark v1.4.1 L2Unix

CONFIGURATION MANAGEMENT

1.7.7 Do not admit containers with dangerous capabilitiesCIS Kubernetes 1.11 Benchmark v1.3.0 L2Unix

CONFIGURATION MANAGEMENT

4.1 Create CIS Audit ClassCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

4.4 Defend against Denial of Service AttacksCIS ISC BIND 9.0/9.5 v2.0.0Unix
5.1.1 Enable Artifact Analysis scanning for Artifact Registry container imagesCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2GCP

RISK ASSESSMENT

5.1.1 Enable Artifact Analysis scanning for Artifact Registry container imagesCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

RISK ASSESSMENT

5.2 Ensure PostgreSQL is Bound to an IP AddressCIS PostgreSQL 16 v1.1.0 L1 OS Linux PostgreSQLDBPostgreSQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

5.2 Ensure PostgreSQL is Bound to an IP AddressCIS PostgreSQL 15 v1.2.0 L1 OS Linux PostgreSQLDBPostgreSQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

5.2 Ensure PostgreSQL is Bound to an IP AddressCIS PostgreSQL 17 v1.1.0 L1 Database PostgreSQLDBPostgreSQLDB

CONFIGURATION MANAGEMENT

5.2 Ensure PostgreSQL is Bound to an IP AddressCIS PostgreSQL 14 DB v 1.3.0PostgreSQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

5.2 Ensure PostgreSQL is Bound to an IP AddressCIS PostgreSQL 13 v1.3.0 L1 Database PostgreSQLDBPostgreSQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

5.2 Ensure PostgreSQL is Bound to an IP AddressCIS PostgreSQL 18 v1.0.0 L1 Database PostgreSQLDBPostgreSQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

5.2.7 Minimize the admission of containers with the NET_RAW capabilityCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

CONFIGURATION MANAGEMENT

5.2.7 Minimize the admission of containers with the NET_RAW capabilityCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

CONFIGURATION MANAGEMENT

5.2.8 Minimize the admission of containers with the NET_RAW capabilityCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

CONFIGURATION MANAGEMENT

5.2.8 Minimize the admission of containers with the NET_RAW capabilityCIS Kubernetes v2.0.1 L1 Master NodeUnix

CONFIGURATION MANAGEMENT

5.2.8 Minimize the admission of containers with the NET_RAW capabilityCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

CONFIGURATION MANAGEMENT

5.7.2 Ensure that the seccomp profile is set to docker/default in your pod definitionsCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

CIS_Aliyun_Linux_2_L1_v1.0.0.audit from CIS Aliyun Linux 2 Benchmark v1.0.0CIS Aliyun Linux 2 L1 v1.0.0Unix
CIS_Aliyun_Linux_2_L2_v1.0.0.audit from CIS Aliyun Linux 2 Benchmark v1.0.0CIS Aliyun Linux 2 L2 v1.0.0Unix
DKER-EE-001000 - The Docker Enterprise Per User Limit Login Session Control in the Universal Control Plane (UCP) Admin Settings must be set to an organization-defined value for all accounts and/or account types.DISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix

ACCESS CONTROL

DKER-EE-001990 - Only required ports must be open on the containers in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002490 - The Lifetime Minutes and Renewal Threshold Minutes Login Session Controls must be set to 10 and 0 respectively in Docker Enterprise - lifetime_minutesDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

DKER-EE-002490 - The Lifetime Minutes and Renewal Threshold Minutes Login Session Controls must be set to 10 and 0 respectively in Docker Enterprise - renewal_threshold_minutesDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

DKER-EE-999999 - The version of Docker Enterprise Edition running on the system must be a supported version.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

SYSTEM AND INFORMATION INTEGRITY