Item Search

NameAudit NamePluginCategory
1.4.5 Set 'logging trap informational'CIS Cisco IOS XR 7.x v1.0.1 L1Cisco

AUDIT AND ACCOUNTABILITY

1.151 WN22-DC-000050CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IIWindows

IDENTIFICATION AND AUTHENTICATION

2.2.5 Set 'logging trap informational'CIS Cisco IOS XE 16.x v2.2.0 L1Cisco

AUDIT AND ACCOUNTABILITY

2.2.5 Set 'logging trap informational'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

AUDIT AND ACCOUNTABILITY

3.2.1.18 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iOS 12 v1.0.0 Institution Owned L1MDM

ACCESS CONTROL

3.2.1.20 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

ACCESS CONTROL

3.2.1.21 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

ACCESS CONTROL

3.2.1.22 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iOS 18 v2.0.0 L1 Institution OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.1.22 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iOS 26 v1.0.0 L1 Institution OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.1.23 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.1.23 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.1.23 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iPadOS 18 v2.0.0 L1 Institutionally OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.1.23 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'AirWatch - CIS Apple iPadOS 17 Institutionally Owned L1MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.3.16 tcp_tcpsecureCIS IBM AIX 7.1 L1 v2.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.4 Ensure that the MIN_DATA_RETENTION_TIME_IN_DAYS account parameter is set to 7 or higherCIS Snowflake Foundations v2.0.0 L2Snowflake

AUDIT AND ACCOUNTABILITY, CONTINGENCY PLANNING, SYSTEM AND INFORMATION INTEGRITY

4.5.4 Ensure default user umask is 027 or more restrictiveCIS Ubuntu Linux 18.04 LTS v2.2.0 L1 WorkstationUnix

ACCESS CONTROL, MEDIA PROTECTION

4.5.4 Ensure default user umask is 027 or more restrictiveCIS Ubuntu Linux 18.04 LTS v2.2.0 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

4.5.17 Ensure tcp_tcpsecure is configuredCIS IBM AIX 7 v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

5.5.1.7 Ensure password expiration is 60 Day maximum for new usersCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

7.1 Set Password Expiration Parameters on Active Accounts - MAXWEEKS = 13CIS Solaris 11.2 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

18.10.43.13.4 (L1) Ensure 'Trigger a quick scan after X days without any scans' is set to 'Enabled: 7'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 NGWindows

SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.4 (L1) Ensure 'Trigger a quick scan after X days without any scans' is set to 'Enabled: 7'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MSWindows

SYSTEM AND INFORMATION INTEGRITY

90.15 Ensure 'Deny Remote Desktop Services Log On' to include 'Guests, Local account'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

90.17 Ensure 'Deny Remote Desktop Services Log On' to include 'Guests, Local account'CIS Microsoft Intune for Windows 11 v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

CIS_CentOS_Linux_7_v4.0.0_L2_Workstation.audit from CIS CentOS Linux 7 Benchmark v4.0.0CIS CentOS Linux 7 v4.0.0 L2 WorkstationUnix
DISA_STIG_Microsoft_Windows_2012_Server_DNS_v2r7.audit from DISA Microsoft Windows 2012 Server Domain Name System v2r7 STIGDISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows
DTBI425 - Java permissions must be disallowed (Local Machine zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI430 - Java permissions must be disallowed (Locked Down Local Machine zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI430-IE11 - Java permissions must be disallowed (Locked Down Local Machine zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI435 - Java permissions must be disallowed (Locked Down Intranet zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI435-IE11 - Java permissions must be disallowed (Locked Down Intranet zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI440 - Java permissions must be disallowed (Locked Down Trusted Sites zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI440-IE11 - Java permissions must be disallowed (Locked Down Trusted Sites zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI445 - Java permissions must be disallowed (Locked Down Internet zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI450-IE11 - Java permissions must be disallowed (Locked Down Restricted Sites zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

JRE8-WN-000060 - Oracle JRE 8 must default to the most secure built-in setting - deployment.security.levelDISA STIG Oracle JRE 8 Windows v2r1Windows

CONFIGURATION MANAGEMENT

JRE8-WN-000110 - Oracle JRE 8 must prevent the download of prohibited mobile code - deployment.security.blacklist.check.lockedDISA STIG Oracle JRE 8 Windows v2r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

JRE8-WN-000170 - Oracle JRE 8 must prompt the user for action prior to executing mobile code - deployment.insecure.jres.lockedDISA STIG Oracle JRE 8 Windows v2r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-DM-000147 - The Juniper SRX Services Gateway must securely configure SSHv2 FIPS 140-2/140-3 validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of maintenance and diagnostic communications for nonlocal maintenance sessions - MAC algorithms to protect the integrity of maintenance and diagnostic communications.DISA Juniper SRX Services Gateway NDM v3r3Juniper

MAINTENANCE

KNOX-07-013100 - The Samsung Android 7 with Knox must implement the management setting: Disable Manual Date Time Changes.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-013100 - The Samsung Android 7 with Knox must implement the management setting: Disable Manual Date Time Changes.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

VCEM-80-000152 - The vCenter ESX Agent Manager service must enable "ENFORCE_ENCODING_IN_GET_WRITER".DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2Unix

CONFIGURATION MANAGEMENT

WBLC-01-000009 - Oracle WebLogic must utilize cryptography to protect the confidentiality of remote access management sessions - Unsecure Listen PortOracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

ACCESS CONTROL

WBLC-06-000191 - Oracle WebLogic must employ strong identification and authentication techniques when establishing nonlocal maintenance and diagnostic sessions - SSL Listen PortOracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

MAINTENANCE

WBLC-08-000211 - Oracle WebLogic must establish a trusted communications path between the user and organization-defined security functions within the information system - SSL Listen PortOracle WebLogic Server 12c Linux v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-08-000231 - Oracle WebLogic must protect the confidentiality of applications and leverage transmission protection mechanisms, such as TLS and SSL VPN, when deploying applications - AdminServer SSL Listen PortOracle WebLogic Server 12c Linux v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-08-000239 - Oracle WebLogic must employ approved cryptographic mechanisms when transmitting sensitive data - Listen PortOracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-08-000239 - Oracle WebLogic must employ approved cryptographic mechanisms when transmitting sensitive data - Listen PortOracle WebLogic Server 12c Windows v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-DC-000050 - Windows Server 2025 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less.DISA Microsoft Windows Server 2025 STIG v1r3Windows

IDENTIFICATION AND AUTHENTICATION

WN25-SO-000050 - Windows Server 2025 must force audit policy subcategory settings to override audit policy category settings.DISA Microsoft Windows Server 2025 STIG v1r3Windows

AUDIT AND ACCOUNTABILITY