Item Search

NameAudit NamePluginCategory
1.1 Ensure Latest SQL Server Cumulative and Security Updates are InstalledCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.6.6 Configure Image Provenance using ImagePolicyWebhook admission controllerCIS Kubernetes 1.11 Benchmark v1.3.0 L2Unix
1.6.7 Configure Image Provenance using ImagePolicyWebhook admission controllerCIS Kubernetes 1.7.0 Benchmark v1.1.0 L2Unix
1.10 RHEL-10-001020CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.1 Ensure 'Ad Hoc Distributed Queries' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Ensure 'CLR Enabled' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT

2.2 Ensure 'CLR Enabled' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT

2.3 Ensure 'Cross DB Ownership Chaining' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

2.3 Ensure 'Cross DB Ownership Chaining' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

2.5 Ensure 'Ole Automation Procedures' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT

2.10 Ensure Unnecessary SQL Server Protocols are set to 'Disabled'CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine WindowsWindows

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.11 Ensure that authorization for Docker client commands is enabledCIS Docker Community Edition v1.1.0 L2 DockerUnix

IDENTIFICATION AND AUTHENTICATION

2.13 Ensure the 'sa' Login Account is set to 'Disabled'CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

2.16 Ensure no login exists with the name 'sa'CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

2.17 Ensure 'clr strict security' Server Configuration Option is set to '1'CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

3.4 Ensure SQL Authentication is not used in contained databasesCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.5 Ensure the SQL Server's MSSQL Service Account is Not an AdministratorCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.6 Ensure the SQL Server's SQLAgent Service Account is Not an AdministratorCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS WindowsWindows

ACCESS CONTROL

3.7 Ensure the SQL Server's Full-Text Service Account is Not an AdministratorCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.7 Ensure the SQL Server's Full-Text Service Account is Not an AdministratorCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS WindowsWindows

ACCESS CONTROL

3.9 Ensure Windows BUILTIN groups are not SQL LoginsCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

3.11 Ensure the public role in the msdb database is not granted access to SQL Agent proxiesCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

3.13 Ensure no admin role membership in MSDB databaseCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

4.1 Ensure 'MUST_CHANGE' Option is set to 'ON' for All SQL Authenticated LoginsCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

4.3 Ensure 'CHECK_POLICY' Option is set to 'ON' for All SQL Authenticated LoginsCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

5.1 Ensure 'Maximum number of error log files' is set to greater than or equal to '12'CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

5.2 Ensure 'Default Trace Enabled' Server Configuration Option is set to '1'CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

5.2 Verify SELinux security options, if applicableCIS Docker 1.12.0 v1.0.0 L2 DockerUnix

ACCESS CONTROL

5.2 Verify SELinux security options, if applicableCIS Docker 1.11.0 v1.0.0 L2 DockerUnix

ACCESS CONTROL

5.2 Verify SELinux security options, if applicableCIS Docker 1.13.0 v1.0.0 L2 DockerUnix

ACCESS CONTROL

5.2 Verify SELinux security options, if applicable (Scored)CIS Docker 1.6 v1.0.0 L2 DockerUnix

ACCESS CONTROL

5.3 Ensure 'Login Auditing' is set to 'failed logins'CIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

5.5.1 Configure Image Provenance using ImagePolicyWebhook admission controllerCIS Kubernetes v2.0.1 L2 Master NodeUnix

CONFIGURATION MANAGEMENT

5.23 Do not docker exec commands with user optionCIS Docker 1.12.0 v1.0.0 L2 DockerUnix
5.23 Ensure docker exec commands are not used with user optionCIS Docker Community Edition v1.1.0 L2 DockerUnix
6.2 Ensure 'CLR Assembly Permission Set' is set to 'SAFE_ACCESS' for All CLR AssembliesCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

6.2 Ensure 'CLR Assembly Permission Set' is set to 'SAFE_ACCESS' for All CLR AssembliesCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

6.2.6 Ensure 'Log_min_error_statement' Database Flag for Cloud SQL PostgreSQL Instance Is Set to 'Error' or StricterCIS Google Cloud Platform Foundation v5.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

6.2.8 Ensure That 'cloudsql.enable_pgaudit' Database Flag for each Cloud Sql Postgresql Instance Is Set to 'on' For Centralized LoggingCIS Google Cloud Platform Foundation v5.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

6.4 Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSLCIS Google Cloud Platform Foundation v5.0.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.9 Ensure Cloud SQL Database Instances Have Deletion Protection EnabledCIS Google Cloud Platform Foundation v5.0.0 L1GCP

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

9.2.2 Ensure that Soft Delete for Containers on Azure Blob Storage Storage Accounts is EnabledCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

CONTINGENCY PLANNING

18.9.5.4 Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

18.9.5.6 Ensure 'Turn On Virtualization Based Security: Secure Launch Configuration' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

18.11.1 Ensure 'Disable HTTP proxy features: Disable WPAD' is set to 'Enabled: Checked'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.11.1 Ensure 'Disable HTTP proxy features: Disable WPAD' is set to 'Enabled: Checked'CIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

CONFIGURATION MANAGEMENT

18.11.1 Ensure 'Disable HTTP proxy features: Disable WPAD' is set to 'Enabled: Checked'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

CONFIGURATION MANAGEMENT

CIS Docker Community Edition v1.1.0 L1 Linux Host OSCIS Docker Community Edition v1.1.0 L1 Linux Host OSUnix
CNTR-K8-000440 - The Kubernetes kubelet staticPodPath must not enable static pods.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

CNTR-R2-000060 - Rancher RKE2 components must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including SRGs, STIGs, NSA configuration guides, CTOs, and DTMs.DISA Rancher Government Solutions RKE2 STIG v2r7Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE