Item Search

NameAudit NamePluginCategory
1.2 Password Security Policy - b) The password must include either three of 'number', 'capital', 'lowercase', 'special-character' or set the 'character-set-num' value to 3-4Tenable ZTE ROSNG Best PracticesZTE_ROSNG
1.2 Password Security Policy - e) Check for strong-password date-check enableTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.4 SNMP Security - a) SNMP Community SecurityTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.4 SNMP Security - b) SNMP Security Protection FunctionTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.6 Support Web Access Security - c) versionTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - b) Disable encryption 3des-cbcTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - f) Disable encryption blowfish-cbcTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - k) Disable hmac sha1Tenable ZTE ROSNG Best PracticesZTE_ROSNG
1.9 SSL Strong Algorithm - a) VersionTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.9 SSL Strong Algorithm - b) ciphersuiteTenable ZTE ROSNG Best PracticesZTE_ROSNG
2.2 NTP Security Protection - a) Enable NTPTenable ZTE ROSNG Best PracticesZTE_ROSNG

AUDIT AND ACCOUNTABILITY

2.2 NTP Security Protection - c) NTP Auth-key MD5 or KeychainTenable ZTE ROSNG Best PracticesZTE_ROSNG

AUDIT AND ACCOUNTABILITY

2.3 Disable the Proxy ARP Function - b) No inter-vlan-proxyTenable ZTE ROSNG Best PracticesZTE_ROSNG
2.3 Disable the Proxy ARP Function - d) No local-proxy-arpTenable ZTE ROSNG Best PracticesZTE_ROSNG
2.4 Disable the IP Unreachable FunctionTenable ZTE ROSNG Best PracticesZTE_ROSNG
3.1 Authentication and Verification of OSPFv3 Routing Protocols - authentication keychain/ipsecTenable ZTE ROSNG Best PracticesZTE_ROSNG
6.1 Perform regular security audits of your host system and containersCIS Docker 1.11.0 v1.0.0 L1 DockerUnix
7.2 Ensure Asymmetric Key Size is set to 'greater than or equal to 2048' in non-system databasesCIS SQL Server 2017 Database L1 AWS RDS v1.3.0MS_SQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.4.25 Disable VM Console Copy operationsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

8.4.26 Disable VM Console Drag and Drop operationsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

8.4.27 Disable VM Console and Paste GUI OptionsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

12.20 Monitor for development on production databases - 'Prevent development on production databases'CIS v1.1.0 Oracle 11g OS L1Unix
12.20 Monitor for development on production databases - 'Prevent development on production databases'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows
Brocade - Bottleneck alerts must be enabledTenable Best Practices Brocade FabricOSBrocade

AUDIT AND ACCOUNTABILITY

Brocade - Bottleneck detection must be enabledTenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Disable Telnet IPv4Tenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Disable Telnet IPv6Tenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Disable TFTP IPv6Tenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Enable HTTPS IPv4Tenable Best Practices Brocade FabricOSBrocade

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade - Enable HTTPS ssl logTenable Best Practices Brocade FabricOSBrocade

AUDIT AND ACCOUNTABILITY

Brocade - Enable SSH IPv6Tenable Best Practices Brocade FabricOSBrocade

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade - Enable the track changes feature for SNMP trapsTenable Best Practices Brocade FabricOSBrocade

AUDIT AND ACCOUNTABILITY

Brocade - Ensure a SSL certificate file is establishedTenable Best Practices Brocade FabricOSBrocade

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade - Fabric Element Authentication must be rejectedTenable Best Practices Brocade FabricOSBrocade

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade - lockout duration set to 30 minutesTenable Best Practices Brocade FabricOSBrocade

ACCESS CONTROL

Brocade - maximum password age must be set to no more than 60 daysTenable Best Practices Brocade FabricOSBrocade

IDENTIFICATION AND AUTHENTICATION

Brocade - password warning must be set to at least 30 daysTenable Best Practices Brocade FabricOSBrocade

ACCESS CONTROL

Brocade - SCP server host is approvedTenable Best Practices Brocade FabricOSBrocade

ACCESS CONTROL

Brocade - Set SNMP security level to authentication and privacyTenable Best Practices Brocade FabricOSBrocade

ACCESS CONTROL

Brocade - SNMP v3 uses AES instead of DESTenable Best Practices Brocade FabricOSBrocade

SYSTEM AND COMMUNICATIONS PROTECTION

OpenStack Server FlavorsTenable Best Practices OpenStack v2.0.0OpenStack

CONFIGURATION MANAGEMENT

OpenStack Servers owned by SERVER_UIDTenable Best Practices OpenStack v2.0.0OpenStack

CONFIGURATION MANAGEMENT

OpenStack Servers updated since the last scanTenable Best Practices OpenStack v2.0.0OpenStack

CONFIGURATION MANAGEMENT

Rackspace Networks and their attached subnetsTenable Best Practices RackSpace v2.0.0Rackspace

CONFIGURATION MANAGEMENT

Rackspace Server FlavorsTenable Best Practices RackSpace v2.0.0Rackspace

CONFIGURATION MANAGEMENT

Rackspace Servers created since the last scanTenable Best Practices RackSpace v2.0.0Rackspace

CONFIGURATION MANAGEMENT

Rackspace Servers updated since the last scanTenable Best Practices RackSpace v2.0.0Rackspace

CONFIGURATION MANAGEMENT

Review the list of active Rackspace Role Names (RBAC)Tenable Best Practices RackSpace v2.0.0Rackspace

ACCESS CONTROL

Review the list of Current OpenStack UsersTenable Best Practices OpenStack v2.0.0OpenStack

ACCESS CONTROL

VCFL-67-000013 - vSphere Client must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

CONFIGURATION MANAGEMENT