Item Search

NameAudit NamePluginCategory
1.1 Create a separate partition for containersCIS Docker 1.11.0 v1.0.0 L1 LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1 Ensure a separate partition for containers has been createdCIS Docker Community Edition v1.1.0 L1 Linux Host OSUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1 Place Databases on Non-System PartitionsCIS MySQL 5.6 Community Linux OS L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1 Place Databases on Non-System PartitionsCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.1 Place Databases on Non-System PartitionsCIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS on Linux UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1 Place Databases on Non-System PartitionsCIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS on Linux UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1 Place Databases on Non-System PartitionsCIS MySQL 5.7 Community Database L1 v2.0.0MySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.1 Place Databases on Non-System PartitionsCIS MySQL 5.7 Community Windows OS L1 v2.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1 Place Databases on Non-System PartitionsCIS MySQL 5.7 Community Linux OS L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.1 Ensure a separate partition for containers has been createdCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.2 Ensure Single-Function Member Servers are UsedCIS Microsoft SQL Server 2025 v1.0.0 L1 Database Engine MS_SQLDBMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.2 Ensure Single-Function Member Servers are UsedCIS SQL Server 2016 Database L1 OS v1.4.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2 Ensure Single-Function Member Servers are UsedCIS Microsoft SQL Server 2022 v1.2.1 L1 AWS RDSMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.2 Ensure Single-Function Member Servers are UsedCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.2 Ensure Single-Function Member Servers are UsedCIS Microsoft SQL Server 2019 v1.5.2 L1 Database EngineMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS Red Hat Enterprise Linux 8 v4.0.0 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS Rocky Linux 8 v3.0.0 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS Rocky Linux 8 v3.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS Oracle Linux 8 v4.0.0 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS Oracle Linux 8 v4.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.7 Ensure MariaDB is Run Under a Sandbox EnvironmentCIS MariaDB 10.6 on Linux L2 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.7 Ensure MySQL is Run Under a Sandbox EnvironmentCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.7 Ensure MySQL is Run Under a Sandbox EnvironmentCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L2 MySQL RDBMS UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.6 Community Windows OS L1 v2.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.7 Community Windows OS L1 v2.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.6 Community Database L1 v2.0.0MySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.6 Community Linux OS L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.6 Enterprise Windows OS L1 v2.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.7 Enterprise Linux OS L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.3 Dedicate the Machine Running MySQLCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS on Linux UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4 IP Source LockdownCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security RecommendationsArubaOS

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.2 Minimize access to secretsCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.3 Minimize the admission of containers wishing to share the host IPC namespaceCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.4 Minimize the admission of containers wishing to share the host IPC namespaceCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.4 Minimize the admission of containers wishing to share the host network namespaceCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.5 Minimize the admission of containers wishing to share the host network namespaceCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.5 Minimize the admission of containers wishing to share the host network namespaceCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.11 Minimize the admission of HostPath volumesCIS Kubernetes v2.0.1 L1 Master NodeUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.4.2 Consider external secret storageCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

5.11 Ensure that the memory usage for containers is limitedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.12 Ensure that CPU priority is set appropriately on containersCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.16 Ensure that the host's process namespace is not sharedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.17 Ensure host devices are not directly exposed to containersCIS Docker Community Edition v1.1.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

7.1.11 Ensure world writable files and directories are securedCIS Rocky Linux 8 v3.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

7.1.11 Ensure world writable files and directories are securedCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

7.1.11 Ensure world writable files and directories are securedCIS Oracle Linux 10 v1.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

7.1.11 Ensure world writable files and directories are securedCIS AlmaLinux OS 10 v1.0.0 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.10 Ensure that Azure Key Vault Managed HSM is used when requiredCIS Microsoft Azure Foundations v5.0.0 L2microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION