Item Search

NameAudit NamePluginCategory
1.2 Enable SSH (/etc/ssh/sshd_config)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

1.2 Enable SSH (Banner)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

1.3 Enable TCP Wrappers and a host based firewall (/etc/hosts.allow)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

1.3 Enable TCP Wrappers and a host based firewall (firewall_enable)CIS FreeBSD v1.0.5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Disable all inetd daemonsCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.2 Only enable telnetd if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.6 Only enable finger if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.7 Only enable Kerberos-related daemons if absolutely necessary (kadmind5_server_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.7 Only enable Kerberos-related daemons if absolutely necessary (kerberos5_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.8 Minimize the inetd.conf fileCIS FreeBSD v1.0.5Unix
3.1 Disable login prompts on serial ports (ttyd2)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.2 Set password on single user consoleCIS FreeBSD v1.0.5Unix

ACCESS CONTROL

3.3 Set daemon umask (/etc/* umask)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

3.3 Set daemon umask (/usr/local/etc/rc.d/* umask)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

3.5 Disable the email server if possible (sendmail_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.5 Disable the email server if possible (sendmail_outbound_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.5 Disable the email server if possible (sendmail_submit_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.6 Only enable BIND if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.7 Only enable other RPC-based services if absolutely necessary (rpc_statd_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.9 Only enable NFS client processes if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.10.9.1.2 (BL) Ensure 'Prevent installation of devices that match any of these device IDs: Also apply to matching devices that are already installed.' is set to 'True' (checked)CIS Microsoft Intune for Windows 10 v3.0.1 BitLocker (BL)Windows

MEDIA PROTECTION

3.11 Block non-privileged mountd requestsCIS FreeBSD v1.0.5Unix

ACCESS CONTROL

5.1 Capture ftpd and inetd informationCIS FreeBSD v1.0.5Unix
5.2 Enable system accounting (/var/account/acct)CIS FreeBSD v1.0.5Unix
5.4 Set permissions on system log files (/var/log/mess*)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

5.5 Configure newsyslog for secure file permissions (/var/log/amd.log)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/lpd-errs)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/maillog)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/monthly.log)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/ppp.log)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.5 Configure newsyslog for secure file permissions (/var/log/sendmail.st)CIS FreeBSD v1.0.5Unix

AUDIT AND ACCOUNTABILITY

5.6 Configure periodic log files (/etc/periodic.conf)CIS FreeBSD v1.0.5Unix
5.6 Configure periodic log files (daily_output)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

5.242 - Windows Installer - User ControlDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

6.2 Verify passwd, master.passwd, and group file permissions (/etc/passwd)CIS FreeBSD v1.0.5Unix

IDENTIFICATION AND AUTHENTICATION

6.2 Verify passwd, master.passwd, and group file permissions (/etc/pwd.db)CIS FreeBSD v1.0.5Unix
6.2 Verify passwd, master.passwd, and group file permissions (/etc/spwd.db)CIS FreeBSD v1.0.5Unix
6.4 Find world writable filesCIS FreeBSD v1.0.5Unix

ACCESS CONTROL

6.5 Find SUID and SGID files (/usr/sbin)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

7.1 Remove weak authentication services from PAM (/etc/pam.d/rexecd)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

7.4 Restrict at/cron to authorized users (/var/at/at.allow)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

7.4 Restrict at/cron to authorized users (/var/cron/allow)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

7.7 Prevent xdm from listening on port 6000/TCPCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

8.3 Set account expiration parameters on all active user accountsCIS FreeBSD v1.0.5Unix

IDENTIFICATION AND AUTHENTICATION

8.4 Create default adduser.conf fileCIS FreeBSD v1.0.5Unix

IDENTIFICATION AND AUTHENTICATION

8.8 Set default umask for users (/etc/csh.cshrc)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

8.8 Set default umask for users (/etc/login.conf)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

8.8 Set default umask for users (/usr/share/skel/dot.cshrc)CIS FreeBSD v1.0.5Unix

ACCESS CONTROL

8.9 Set 'mesg n' as the default for all users (/etc/csh.login)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

SOL-11.1-100010 - The /etc/zones directory, and its contents, must have the vendor default owner, group, and permissions.DISA STIG Solaris 11 SPARC v3r1Unix

CONFIGURATION MANAGEMENT