Item Search

NameAudit NamePluginCategory
1.9 Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to UsersCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

1.14 Ensure API Keys Are Restricted To Use by Only Specified Hosts and AppsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

2.1.3 Ensure notifications for internal users sending malware is EnabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.10 Ensure That the Log Metric Filter and Alerts Exist for VPC Network ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.12 Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.16 Ensure 'Access Approval' is 'Enabled'CIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

3.7 Ensure That RDP Access Is Restricted From the InternetCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.11 Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher SuitesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.6 Ensure That IP Forwarding Is Not Enabled on InstancesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.8 Ensure Compute Instances Are Launched With Shielded VM EnabledCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND INFORMATION INTEGRITY

4.9 Ensure That Compute Instances Do Not Have Public IP AddressesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

5.4.2 Restrict GKE control plane access with authorized networksCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

6.2.8 Ensure That 'cloudsql.enable_pgaudit' Database Flag for each Cloud Sql Postgresql Instance Is Set to 'on' For Centralized LoggingCIS Google Cloud Platform Foundation v5.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

AIOS-12-004000 - Apple iOS must not allow backup of managed app data to locally connected systems.AirWatch - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-004000 - Apple iOS/iPadOS must not allow backup of managed app data to locally connected systems.MobileIron - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-14-003600 - The mobile operating system must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Apple iOS/iPadOS 14 v1r3MDM

ACCESS CONTROL

AIOS-16-009200 - Apple iOS/iPadOS 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-16-709200 - Apple iOS/iPadOS 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Apple iOS/iPadOS 16 BYOAD v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-17-009200 - Apple iOS/iPadOS 17 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Apple iOS/iPadOS 17 v2r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-17-709200 - Apple iOS/iPadOS 17 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Apple iOS/iPadOS 17 BYOAD v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-18-009200 - Apple iOS/iPadOS 18 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Apple iOS/iPadOS 18 v2r3MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-26-009200 - Apple iOS/iPadOS 26 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS/iPadOS 26 v1r3MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-26-009200 - Apple iOS/iPadOS 26 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Apple iOS/iPadOS 26 v1r3MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-09-001100 - The Google Android Pie whitelist must be configured to not include applications with the following characteristics: - back up MD data to non-DoD cloud servers (including user and application access to cloud backup services); - transmit MD diagnostic data to non-DoD servers; - voice assistant application if available when MD is locked; - voice dialing application if available when MD is locked; - allows synchronization of data or applications between devices associated with user; and - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Google Android 9.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-10-001100 - Google Android 10 whitelist must be configured to not include applications with the following characteristics: - back up MD data to non-DoD cloud servers (including user and application access to cloud backup services); - transmit MD diagnostic data to non-DoD servers; - voice assistant application if available when MD is locked; - voice dialing application if available when MD is locked; - allows synchronization of data or applications between devices associated with user; and - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Google Android 10.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-10-001100 - Google Android 10 whitelist must be configured to not include applications with the following characteristics: - back up MD data to non-DoD cloud servers (including user and application access to cloud backup services); - transmit MD diagnostic data to non-DoD servers; - voice assistant application if available when MD is locked; - voice dialing application if available when MD is locked; - allows synchronization of data or applications between devices associated with user; and - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.MobileIron - DISA Google Android 10.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-11-001100 - Google Android 11 allow list must be configured to not include applications with the following characteristics:AirWatch - DISA Google Android 11 COPE v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-11-001100 - Google Android 11 allow list must be configured to not include applications with the following characteristics:MobileIron - DISA Google Android 11 COPE v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-12-006700 - Google Android 12 allowlist must be configured to not include applications with the following characteristics: 1. Back up mobile device (MD) data to non-DoD cloud servers (including user and application access to cloud backup services);2. Transmit MD diagnostic data to non-DoD servers;3. Voice assistant application if available when MD is locked;4. Voice dialing application if available when MD is locked;5. Allows synchronization of data or applications between devices associated with user; and6. Allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-006700 - Google Android 12 allowlist must be configured to not include applications with the following characteristics: 1. Back up mobile device (MD) data to non-DoD cloud servers (including user and application access to cloud backup services);2. Transmit MD diagnostic data to non-DoD servers;3. Voice assistant application if available when MD is locked;4. Voice dialing application if available when MD is locked;5. Allows synchronization of data or applications between devices associated with user; and6. Allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-006700 - Google Android 12 allowlist must be configured to not include applications with the following characteristics: 1. Back up mobile device (MD) data to non-DoD cloud servers (including user and application access to cloud backup services);2. Transmit MD diagnostic data to non-DoD servers;3. Voice assistant application if available when MD is locked;4. Voice dialing application if available when MD is locked;5. Allows synchronization of data or applications between devices associated with user; and6. Allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.MobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-13-006700 - Google Android 13 allowlist must be configured to not include applications with the following characteristics:AirWatch - DISA Google Android 13 COPE STIG v2r3MDM

CONFIGURATION MANAGEMENT

GOOG-13-706700 - Google Android 13 allowlist must be configured to not include applications with the following characteristics (work profile only):AirWatch - DISA Google Android 13 BYOAD v1r3MDM

CONFIGURATION MANAGEMENT

HONW-09-001100 - The Honeywell Mobility Edge Android Pie device whitelist must be configured to not include applications with the following characteristics:AirWatch - DISA Honeywell Android 9.x COBO v1r2MDM

CONFIGURATION MANAGEMENT

HONW-09-001100 - The Honeywell Mobility Edge Android Pie device whitelist must be configured to not include applications with the following characteristics:AirWatch - DISA Honeywell Android 9.x COPE v1r2MDM

CONFIGURATION MANAGEMENT

HONW-09-001100 - The Honeywell Mobility Edge Android Pie device whitelist must be configured to not include applications with the following characteristics:MobileIron - DISA Honeywell Android 9.x COPE v1r2MDM

CONFIGURATION MANAGEMENT

HONW-13-006700 - Honeywell Android 13 allowlist must be configured to not include applications with the following characteristics:AirWatch - DISA Honeywell Android 13 COBO STIG v1r1MDM

IDENTIFICATION AND AUTHENTICATION

HONW-13-006700 - Honeywell Android 13 allowlist must be configured to not include applications with the following characteristics:MobileIron - DISA Honeywell Android 13 COBO STIG v1r1MDM

IDENTIFICATION AND AUTHENTICATION

HONW-13-006700 - Honeywell Android 13 allowlist must be configured to not include applications with the following characteristics:MobileIron - DISA Honeywell Android 13 COPE STIG v1r1MDM

IDENTIFICATION AND AUTHENTICATION

MOTO-09-001100 - The Motorola Android Pie whitelist must be configured to not include applications with the following characteristics:MobileIron - DISA Motorola Android Pie.x COBO v1r2MDM

CONFIGURATION MANAGEMENT

MOTO-09-001100 - The Motorola Android Pie whitelist must be configured to not include applications with the following characteristics:AirWatch - DISA Motorola Android Pie.x COPE v1r2MDM

CONFIGURATION MANAGEMENT

MOTO-09-001100 - The Motorola Android Pie whitelist must be configured to not include applications with the following characteristics:MobileIron - DISA Motorola Android Pie.x COPE v1r2MDM

CONFIGURATION MANAGEMENT

MOTS-11-001100 - Motorola Solutions Android 11 allow list must be configured to not include applications with the following characteristics:AirWatch - DISA Motorola Solutions Android 11 COBO v1r3MDM

CONFIGURATION MANAGEMENT

MSFT-11-001100 - Microsoft Android 11 allow list must be configured to not include applications with the following characteristics:MobileIron - DISA Microsoft Android 11 COBO v1r2MDM

CONFIGURATION MANAGEMENT

MSFT-11-001100 - Microsoft Android 11 allow list must be configured to not include applications with the following characteristics: - Back up MD data to non-DOD cloud servers (including user and application access to cloud backup services);- Transmit MD diagnostic data to non-DOD servers;- Voice assistant application if available when MD is locked;- Voice dialing application if available when MD is locked;- Allows synchronization of data or applications between devices associated with user; and- Allows unencrypted (or encrypted but not FIPS 140-2/FIPS 140-3 validated) data sharing with other MDs or printers.MobileIron - DISA Microsoft Android 11 COPE v1r2MDM

CONFIGURATION MANAGEMENT

PANW-AG-000112 - The Palo Alto Networks security platform must detect use of network services that have not been authorized or approved by the ISSM and ISSO, at a minimum.DISA Palo Alto Networks ALG STIG v3r4Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

PANW-AG-000113 - The Palo Alto Networks security platform must generate a log record when unauthorized network services are detected.DISA Palo Alto Networks ALG STIG v3r4Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

ZEBR-10-001100 - Zebra Android 10 whitelist must be configured to not include applications with the following characteristics:MobileIron - DISA Zebra Android 10 COPE v1r2MDM

CONFIGURATION MANAGEMENT

ZEBR-10-001100 - Zebra Android 10 whitelist must be configured to not include applications with the following characteristics:AirWatch - DISA Zebra Android 10 COBO v1r2MDM

CONFIGURATION MANAGEMENT

ZEBR-10-001100 - Zebra Android 10 whitelist must be configured to not include applications with the following characteristics:MobileIron - DISA Zebra Android 10 COBO v1r2MDM

CONFIGURATION MANAGEMENT