Item Search

NameAudit NamePluginCategory
1.1 (L1) Host hardware must have auditable, authentic, and up to date system & device firmwareCIS VMware ESXi 8.0 v1.2.0 L1VMware

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure Latest SQL Server Cumulative and Security Updates are InstalledCIS SQL Server 2017 Database L1 DB v1.3.0MS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure Latest SQL Server Cumulative and Security Updates are InstalledCIS Microsoft SQL Server 2019 v1.5.0 L1 Database EngineMS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.2 Ensure the Image Profile VIB acceptance level is configured properlyCIS VMware ESXi 6.7 v1.3.0 Level 1 Bare MetalUnix

SYSTEM AND SERVICES ACQUISITION

1.2.6 Ensure the version of the operating system is an active vendor supported releaseCIS Amazon Linux 2 STIG v2.0.0 STIGUnix

SYSTEM AND SERVICES ACQUISITION

1.2.33 Ensure unsupported configuration overrides are not usedCIS Red Hat OpenShift Container Platform v1.7.0 L1OpenShift

SYSTEM AND SERVICES ACQUISITION

1.28 (L1) Ensure 'Suppress the unsupported OS warning' is set to 'Disabled'CIS Google Chrome L1 v3.0.0Windows

SYSTEM AND SERVICES ACQUISITION

1.130 (L1) Ensure 'Suppress the unsupported OS warning' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND SERVICES ACQUISITION

2.1 (L1) Host must run software that has not reached End of General Support statusCIS VMware ESXi 8.0 v1.2.0 L1VMware

SYSTEM AND SERVICES ACQUISITION

2.4 (L1) Host image profile acceptance level must be PartnerSupported or higherCIS VMware ESXi 8.0 v1.2.0 L1Unix

SYSTEM AND SERVICES ACQUISITION

2.9 Ensure Legacy EFI Is Valid and Updating - checked regularlyCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

SYSTEM AND SERVICES ACQUISITION

2.9 Ensure Legacy EFI Is Valid and Updating - validCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

SYSTEM AND SERVICES ACQUISITION

4.1 Ensure the Latest Security Patches are AppliedCIS Oracle MySQL Enterprise Edition 8.0 v1.4.0 L1 DatabaseMySQLDB

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedAirWatch - CIS Apple iPadOS 18 v1.0.0 L1 End User OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedAirWatch - CIS Apple iOS 17 Benchmark v1.1.0 End User Owned L1MDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L1MDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iPadOS 17 Institutionally Owned L1MDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iOS 18 v1.0.0 L1 End User OwnedMDM

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure device is not obviously jailbroken or compromisedMobileIron - CIS Apple iPadOS 18 v1.0.0 L1 End User OwnedMDM

SYSTEM AND SERVICES ACQUISITION

7.1.5 Ensure that SKU Basic/Consumption is not used on artifacts that need to be monitored (Particularly for Production Workloads)CIS Microsoft Azure Foundations v4.0.0 L2microsoft_azure

SYSTEM AND SERVICES ACQUISITION

7.29 (L2) Virtual machines should have virtual machine hardware version 19 or newerCIS VMware ESXi 8.0 v1.2.0 L2VMware

SYSTEM AND SERVICES ACQUISITION

8.1 (L1) VMware Tools must be a version that has not reached End of General Support statusCIS VMware ESXi 8.0 v1.2.0 L1VMware

SYSTEM AND SERVICES ACQUISITION

20.3 (L1) Ensure 'Microsoft Internet Explorer is not installed on the system'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

20.42 Ensure 'Operating System is maintained at a supported servicing level'CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG DCWindows

SYSTEM AND SERVICES ACQUISITION

MS.TEAMS.5.1v1 - Agencies SHOULD only allow installation of Microsoft apps approved by the agency.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY

MS.TEAMS.5.2v1 - Agencies SHOULD only allow installation of third-party apps approved by the agency.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY

MS.TEAMS.5.3v1 - Agencies SHOULD only allow installation of custom apps approved by the agency.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY

MS.TEAMS.8.1v1 - URL comparison with a blocklist SHOULD be enabled.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

MS.TEAMS.8.2v1 - User click tracking SHOULD be enabled.CISA SCuBA Microsoft 365 Teams v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY