Item Search

NameAudit NamePluginCategory
1.1.1 Ensure Super Admin Email Address Is Not Tied To A Single UserCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.1.3 Ensure Folders Are Structured By Environment And SensitivityCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.4 Ensure Organization Policies Are Configured For Centralized ConstraintsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL

1.1.11 Ensure separate partition exists for /var/logCIS Ubuntu Linux 18.04 LXD Host L2 Server v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.13 Ensure separate partition exists for /homeCIS Oracle Linux 6 Server L2 v2.0.0Unix

CONFIGURATION MANAGEMENT

1.1.17 Ensure separate partition exists for /homeCIS Fedora 19 Family Linux Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.17 Ensure separate partition exists for /homeCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.1.17 Ensure separate partition exists for /homeCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.1.17 Ensure separate partition exists for /homeCIS Ubuntu Linux 16.04 LTS Server L2 v2.0.0Unix

CONFIGURATION MANAGEMENT

1.5 Ensure That There Are Only GCP-Managed Service Account Keys for Each Service AccountCIS Google Cloud Platform Foundation v5.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

1.6 Ensure That Service Account Has No Admin PrivilegesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL

1.7 Ensure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project LevelCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

1.16 Ensure API Keys Are Rotated Every 90 DaysCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

2.1.3 Ensure notifications for internal users sending malware is EnabledCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.5 Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/ChangesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

3.9 Ensure Private Service Connect is Used for Access to Google APIsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

3.12 Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are 'Allowed'CIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL

4.3 Ensure "Block Project-Wide SSH Keys" Is Enabled for VM InstancesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.4 Ensure Oslogin Is Enabled for a ProjectCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL

4.7 Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)CIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.10 Ensure That App Engine Applications Enforce HTTPS ConnectionsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

4.11 Ensure That Compute Instances Have Confidential Computing EnabledCIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.12 Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All ProjectsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND SERVICES ACQUISITION

5.5 Ensure all WildFire session information settings are enabledCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

7.1 Ensure That BigQuery Datasets Are Not Anonymously or Publicly AccessibleCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

7.2 Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)CIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.1.4.1 Ensure That Microsoft Defender for Containers Is Set To 'On'CIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

RISK ASSESSMENT

18.5.10.1 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L2Windows

CONFIGURATION MANAGEMENT

18.5.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2008 R2 Member Server Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Windows Server 2012 DC L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2Windows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2Windows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L2 DCWindows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

AIOS-12-004000 - Apple iOS must not allow backup of managed app data to locally connected systems.MobileIron - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-004000 - Apple iOS/iPadOS must not allow backup of managed app data to locally connected systems.AirWatch - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-14-003600 - The mobile operating system must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS/iPadOS 14 v1r3MDM

ACCESS CONTROL

AIOS-15-009200 - Apple iOS/iPadOS 15 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-15-009200 - Apple iOS/iPadOS 15 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-16-009200 - Apple iOS/iPadOS 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-16-709200 - Apple iOS/iPadOS 16 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS/iPadOS BYOAD 16 v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-17-009200 - Apple iOS/iPadOS 17 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS/iPadOS 17 v2r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-17-709200 - Apple iOS/iPadOS 17 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-AP-300069 - The F5 BIG-IP appliance providing content filtering must generate a log record when unauthorized network services are detected.DISA F5 BIG-IP TMOS ALG STIG v1r3F5

SYSTEM AND INFORMATION INTEGRITY

GOOG-14-706700 - Google Android 14 allowlist must be configured to not include applications with the following characteristics (work profile only):MobileIron - DISA Google Android 14 BYOAD v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-14-706700 - Google Android 14 allowlist must be configured to not include applications with the following characteristics (work profile only):AirWatch - DISA Google Android 14 BYOAD v1r2MDM

CONFIGURATION MANAGEMENT