Item Search

NameAudit NamePluginCategory
1.3 Enable TCP Wrappers and a host based firewall (/etc/hosts.allow)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

1.3 Enable TCP Wrappers and a host based firewall (firewall_enable)CIS FreeBSD v1.0.5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.3 Enable TCP Wrappers and a host based firewall (inetd_flags)CIS FreeBSD v1.0.5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Disable all inetd daemonsCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.3 Only enable ftpd if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.4 Only enable rlogin/rsh/rcp if absolutely necessary (login)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.6 Only enable finger if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.7 Only enable Kerberos-related daemons if absolutely necessary (kadmind5_server_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.7 Only enable Kerberos-related daemons if absolutely necessary (kerberos5_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.8 Minimize the inetd.conf fileCIS FreeBSD v1.0.5Unix
3.1 Disable login prompts on serial ports (ttyd2)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.2 Set password on single user consoleCIS FreeBSD v1.0.5Unix

ACCESS CONTROL

3.3 Set daemon umask (/etc/* umask)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

3.3 Set daemon umask (/usr/local/etc/rc.d/* umask)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

3.5 Disable the email server if possible (sendmail_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.5 Disable the email server if possible (sendmail_outbound_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.5 Disable the email server if possible (sendmail_submit_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.6 Only enable BIND if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.7 Only enable other RPC-based services if absolutely necessary (rpc_statd_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.9 Only enable NFS client processes if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.11 Block non-privileged mountd requestsCIS FreeBSD v1.0.5Unix

ACCESS CONTROL

3.12 Only enable NIS if absolutely necessary (nis_server_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

4.10.9.1.2 (BL) Ensure 'Prevent installation of devices that match any of these device IDs: Also apply to matching devices that are already installed.' is set to 'True' (checked)CIS Microsoft Intune for Windows 10 v4.0.0 BLWindows

MEDIA PROTECTION

5.1 Capture ftpd and inetd informationCIS FreeBSD v1.0.5Unix
5.2 Enable system accounting (/var/account/acct)CIS FreeBSD v1.0.5Unix
5.4 Set permissions on system log files (/var/log/mess*)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

5.5 Configure newsyslog for secure file permissions (/var/log/amd.log)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/lpd-errs)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/maillog)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/monthly.log)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/ppp.log)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/sendmail.st)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.6 Configure periodic log files (/etc/periodic.conf)CIS FreeBSD v1.0.5Unix
5.6 Configure periodic log files (daily_output)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

5.242 - Windows Installer - User ControlDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

6.2 Verify passwd, master.passwd, and group file permissions (/etc/passwd)CIS FreeBSD v1.0.5Unix

IDENTIFICATION AND AUTHENTICATION

6.2 Verify passwd, master.passwd, and group file permissions (/etc/pwd.db)CIS FreeBSD v1.0.5Unix
6.2 Verify passwd, master.passwd, and group file permissions (/etc/spwd.db)CIS FreeBSD v1.0.5Unix
6.4 Find world writable filesCIS FreeBSD v1.0.5Unix

ACCESS CONTROL

6.5 Find SUID and SGID files (/usr/sbin)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

7.1 Remove weak authentication services from PAM (/etc/pam.d/rexecd)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

7.4 Restrict at/cron to authorized users (/var/at/at.allow)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

7.4 Restrict at/cron to authorized users (/var/cron/allow)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

8.3 Set account expiration parameters on all active user accountsCIS FreeBSD v1.0.5Unix

IDENTIFICATION AND AUTHENTICATION

8.4 Create default adduser.conf fileCIS FreeBSD v1.0.5Unix

IDENTIFICATION AND AUTHENTICATION

8.8 Set default umask for users (/etc/csh.cshrc)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

8.8 Set default umask for users (/etc/login.conf)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

8.8 Set default umask for users (/usr/share/skel/dot.cshrc)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

8.9 Set 'mesg n' as the default for all users (/etc/csh.login)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

18.9.7.1.1 (L1) Ensure 'Allow installation of devices that match any of these device IDs' is set to 'Enabled: <Org Specific Device IDs>'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL, MEDIA PROTECTION