Item Search

NameAudit NamePluginCategory
1.1.1 Ensure Super Admin Email Address Is Not Tied To A Single UserCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.1.3 Ensure Folders Are Structured By Environment And SensitivityCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.4 Ensure Organization Policies Are Configured For Centralized ConstraintsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL

1.5 Ensure That There Are Only GCP-Managed Service Account Keys for Each Service AccountCIS Google Cloud Platform Foundation v5.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

1.6 Ensure That Service Account Has No Admin PrivilegesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL

1.7 Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project LevelCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

1.9 Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to UsersCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

1.11 Ensure KMS Encryption Keys Are Rotated Within a Period of 90 DaysCIS Google Cloud Platform Foundation v5.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.14 Ensure API Keys Are Restricted To Use by Only Specified Hosts and AppsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

1.16 Ensure API Keys Are Rotated Every 90 DaysCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

2.5 Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/ChangesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

2.10 Ensure That the Log Metric Filter and Alerts Exist for VPC Network ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.12 Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.16 Ensure 'Access Approval' is 'Enabled'CIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

3.6 Ensure That SSH Access Is Restricted From the InternetCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.7 Ensure That RDP Access Is Restricted From the InternetCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.9 Ensure Private Service Connect is Used for Access to Google APIsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

3.11 Ensure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher SuitesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.12 Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are 'Allowed'CIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL

4.3 Ensure "Block Project-Wide SSH Keys" Is Enabled for VM InstancesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.4 Ensure Oslogin Is Enabled for a ProjectCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL

4.5 Ensure FTP server is not runningCIS Apple macOS 10.12 L1 v1.2.0Unix

CONFIGURATION MANAGEMENT

4.6 Ensure That IP Forwarding Is Not Enabled on InstancesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.7 Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)CIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.8 Ensure Compute Instances Are Launched With Shielded VM EnabledCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND INFORMATION INTEGRITY

4.9 Ensure That Compute Instances Do Not Have Public IP AddressesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

4.10 Ensure That App Engine Applications Enforce HTTPS ConnectionsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

4.11 Ensure That Compute Instances Have Confidential Computing EnabledCIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.12 Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All ProjectsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND SERVICES ACQUISITION

5.6.5 Ensure clusters are created with Private NodesCIS Google Kubernetes Engine GKE v1.9.0 L1 GCPGCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.2.8 Ensure That 'cloudsql.enable_pgaudit' Database Flag for each Cloud Sql Postgresql Instance Is Set to 'on' For Centralized LoggingCIS Google Cloud Platform Foundation v5.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

7.1 Ensure That BigQuery Datasets Are Not Anonymously or Publicly AccessibleCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

7.2 Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)CIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Ensure That a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Data SetsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.1.7.3 Ensure That Microsoft Defender for (Managed Instance) Azure SQL Databases Is Set To 'On'CIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION

8.1.7.4 Ensure That Microsoft Defender for SQL Servers on Machines Is Set To 'On'CIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION

8.1.15 Ensure that 'Notify about attack paths with the following risk level (or higher)' is EnabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

DTOO407 - The prompt to save to OneDrive (formerly SkyDrive) must be disabled.DISA STIG Microsoft Office System 2013 v2r2Windows

CONFIGURATION MANAGEMENT

GOOG-12-006700 - Google Android 12 allowlist must be configured to not include applications with the following characteristics: 1. Back up mobile device (MD) data to non-DoD cloud servers (including user and application access to cloud backup services);2. Transmit MD diagnostic data to non-DoD servers;3. Voice assistant application if available when MD is locked;4. Voice dialing application if available when MD is locked;5. Allows synchronization of data or applications between devices associated with user; and6. Allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.MobileIron - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

HONW-13-008500 - Honeywell Android 13 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Honeywell Android 13 COPE STIG v1r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

KNOX-07-004700 - The Samsung must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

ACCESS CONTROL

MOTO-09-001100 - The Motorola Android Pie whitelist must be configured to not include applications with the following characteristics:AirWatch - DISA Motorola Android Pie.x COBO v1r2MDM

CONFIGURATION MANAGEMENT

MOTO-09-003700 - The Motorola Android Pie must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Motorola Android Pie.x COBO v1r2MDM

ACCESS CONTROL

MOTO-09-003700 - The Motorola Android Pie must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Motorola Android Pie.x COPE v1r2MDM

ACCESS CONTROL

MOTS-11-003700 - Motorola Solutions Android 11 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Motorola Solutions Android 11 COBO v1r3MDM

ACCESS CONTROL

MS.EXO.17.3v1 - Audit logs SHALL be maintained for at least the minimum duration dictated by OMB M-21-31 (Appendix C).CISA SCuBA Microsoft 365 Exchange Online v1.5.0microsoft_azure

CONFIGURATION MANAGEMENT

MSFT-11-001100 - Microsoft Android 11 allow list must be configured to not include applications with the following characteristics:AirWatch - DISA Microsoft Android 11 COBO v1r2MDM

CONFIGURATION MANAGEMENT

MSFT-11-003700 - Microsoft Android 11 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Microsoft Android 11 COBO v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

ZEBR-10-003700 - Zebra Android 10 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Zebra Android 10 COPE v1r2MDM

ACCESS CONTROL

ZEBR-11-001100 - Zebra Android 11 allow list must be configured to not include applications with the following characteristics:MobileIron - DISA Zebra Android 11 COBO STIG v1r4MDM

CONFIGURATION MANAGEMENT