Item Search

NameAudit NamePluginCategory
1.1 (L1) Host hardware must have auditable, authentic, and up to date system & device firmwareCIS VMware ESXi 8.0 v1.3.0 L1 VMwareVMware

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure Latest SQL Server Cumulative and Security Updates are InstalledCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure Latest SQL Server Cumulative and Security Updates are InstalledCIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure Latest SQL Server Cumulative and Security Updates are InstalledCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure Latest SQL Server Service Packs and Hotfixes are InstalledCIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure That Appropriate Version/Patches For Oracle Software Are InstalledCIS Oracle Database 26ai v1.0.0 L1 RDBMS On Linux Host OS OracleDBOracleDB

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure That Appropriate Version/Patches For Oracle Software Are InstalledCIS Oracle Database 23ai v1.1.0 L1 RDBMSOracleDB

SYSTEM AND SERVICES ACQUISITION

1.1.1 Ensure NGINX is installedCIS NGINX v3.0.0 L1 ProxyUnix

SYSTEM AND SERVICES ACQUISITION

1.2 Ensure the Image Profile VIB acceptance level is configured properlyCIS VMware ESXi 6.7 v1.3.0 Level 1 Bare MetalUnix

SYSTEM AND SERVICES ACQUISITION

1.2.31 Ensure unsupported configuration overrides are not usedCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.5 Ensure the Latest Security Patches are AppliedCIS PostgreSQL 17 v1.1.0 L1 Database PostgreSQLDBPostgreSQLDB

SYSTEM AND SERVICES ACQUISITION

1.133 (L1) Ensure 'Suppress the unsupported OS warning' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L1Windows

SYSTEM AND SERVICES ACQUISITION

2.1 (L1) Host must run software that has not reached End of General Support statusCIS VMware ESXi 8.0 v1.3.0 L1 VMwareVMware

SYSTEM AND SERVICES ACQUISITION

2.9 Ensure Legacy EFI Is Valid and Updating - checked regularlyCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

SYSTEM AND SERVICES ACQUISITION

2.9 Ensure Legacy EFI Is Valid and Updating - validCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

SYSTEM AND SERVICES ACQUISITION

2.11 Ensure EFI Version Is Valid and Checked Regularly - integrity-checkCIS Apple macOS 10.14 v2.0.0 L1Unix

SYSTEM AND SERVICES ACQUISITION

2.81 (L1) Ensure 'Suppress the unsupported OS warning' is set to 'Disabled'CIS Google Chrome Group Policy v1.1.0 L1Windows

SYSTEM AND SERVICES ACQUISITION

4.1 Ensure the Latest Security Patches are AppliedCIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L1 MySQL RDBMS on Linux MySQLDBMySQLDB

SYSTEM AND SERVICES ACQUISITION

4.1 Ensure the Latest Security Patches are AppliedCIS Oracle MySQL Enterprise Edition 8.4 v1.1.0 L1 MySQL RDBMS on Linux MySQLDBMySQLDB

SYSTEM AND SERVICES ACQUISITION

4.1 Ensure the Latest Security Patches are AppliedCIS MySQL 5.7 Enterprise Database L1 v2.0.0MySQLDB

SYSTEM AND SERVICES ACQUISITION

4.1 Ensure the Latest Security Patches are AppliedCIS Oracle MySQL Community Server 8.4 v1.1.0 L1 MySQL RDBMS on Linux MySQLDBMySQLDB

SYSTEM AND SERVICES ACQUISITION

4.1 Ensure the Latest Security Patches are AppliedCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L1 MySQL RDBMS on Linux MySQLDBMySQLDB

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedAirWatch - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L1MDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iOS 17 Institution Owned L1MDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedAirWatch - CIS Apple iOS 18 v2.0.0 L1 Institution OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iOS 26 v1.0.0 L1 Institution OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedAirWatch - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedAirWatch - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iPadOS 26 v1.0.0 L1 End User OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedAirWatch - CIS Apple iOS 18 Benchmark v2.0.0 L1 End User OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iOS 26 v1.0.0 L1 End User OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iPadOS 17 Institutionally Owned L1MDM

SYSTEM AND SERVICES ACQUISITION

5.9 Ensure Legacy EFI Is Valid and UpdatingCIS Apple macOS 13.0 Ventura v4.0.0 L1Unix

SYSTEM AND SERVICES ACQUISITION

6.1.5 Ensure Basic, Free, and Consumption SKUs are not used on Production artifacts requiring monitoring and SLACIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

SYSTEM AND SERVICES ACQUISITION

7.13 Ensure 'HTTP2' is Set to 'Enabled' on Azure Application GatewayCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SYSTEM AND SERVICES ACQUISITION

7.29 (L2) Virtual machines should have virtual machine hardware version 19 or newerCIS VMware ESXi 8.0 v1.3.0 L2VMware

SYSTEM AND SERVICES ACQUISITION

20.3 (L1) Ensure 'Microsoft Internet Explorer is not installed on the system'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

MS.TEAMS.5.1v1 - Agencies SHOULD only allow installation of Microsoft apps approved by the agency.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY

MS.TEAMS.5.2v1 - Agencies SHOULD only allow installation of third-party apps approved by the agency.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY

MS.TEAMS.5.3v1 - Agencies SHOULD only allow installation of custom apps approved by the agency.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY

MS.TEAMS.8.1v1 - URL comparison with a blocklist SHOULD be enabled.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

MS.TEAMS.8.2v1 - User click tracking SHOULD be enabled.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY