Item Search

NameAudit NamePluginCategory
1.1 Ensure a separate user and group exist for Cassandra - groupCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

1.1.3.1.2 Configure 'Accounts: Rename guest account'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.3.1.4 Configure 'Accounts: Rename administrator account'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.3.9 Ensure 'Prevent Password Reuse Limit' is set to 24 or more passwordsCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

ACCESS CONTROL

1.4.2 Ensure 'Failed Attempts' and 'Lockout Time' for Authentication Profile are properly configured - Lockout TimeCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

ACCESS CONTROL

1.11 Ensure credentials unused for 45 days or more are disabledCIS Amazon Web Services Foundations v5.0.0 L1amazon_aws

ACCESS CONTROL

2.1 Run BIND as a non-root User - process -u namedCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

ACCESS CONTROL

2.2.10 Ensure 'SEC_MAX_FAILED_LOGIN_ATTEMPTS' Is '3' or LessCIS Oracle Server 18c DB Traditional Auditing v1.1.0OracleDB

ACCESS CONTROL

2.2.10 Ensure 'SEC_MAX_FAILED_LOGIN_ATTEMPTS' Is '3' or LessCIS Oracle Server 18c DB Unified Auditing v1.1.0OracleDB

ACCESS CONTROL

2.3.1.1 Ensure 'Accounts: Administrator account status' is set to 'Disabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.3.1.4 Configure 'Accounts: Rename administrator account'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

3.1 Ensure 'FAILED_LOGIN_ATTEMPTS' Is Less than or Equal to '5'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

3.2 Ensure 'PASSWORD_LOCK_TIME' Is Greater than or Equal to '1'CIS Oracle Server 18c DB Traditional Auditing v1.1.0OracleDB

ACCESS CONTROL

3.2 Ensure 'PASSWORD_LOCK_TIME' Is Greater than or Equal to '1'CIS Oracle Server 18c DB Unified Auditing v1.1.0OracleDB

ACCESS CONTROL

3.3 Ensure 'PASSWORD_LIFE_TIME' Is Less than or Equal to '90'CIS Oracle Server 18c DB Unified Auditing v1.1.0OracleDB

ACCESS CONTROL

3.20 (L1) Host must enable normal lockdown modeCIS VMware ESXi 8.0 v1.1.0 L1VMware

ACCESS CONTROL

4.4 Ensure excessive function privileges are revokedCIS PostgreSQL 9.5 DB v1.1.0PostgreSQLDB

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - at.allowCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - at.denyCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - cron.allowCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - cron.allowCIS Debian 9 Server L1 v1.0.1Unix

ACCESS CONTROL

5.1.8 Ensure cron is restricted to authorized users - /etc/cron.allowCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

5.1.8 Ensure cron is restricted to authorized users - /etc/cron.allowCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.1.9 Ensure at is restricted to authorized users - /etc/at.allowCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

5.1.9 Ensure at is restricted to authorized users - /etc/at.denyCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.2.7 Ensure Password Age Is ConfiguredCIS Apple macOS 12.0 Monterey Cloud-tailored v1.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configuredCIS Debian 9 Workstation L1 v1.0.1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - auth pam_tally2.soCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

5.3.2 Lockout for failed password attempts - 'auth sufficient pam_unix.so'CIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.4.2 Ensure system accounts are non-loginCIS Debian 8 Server L1 v2.0.2Unix

ACCESS CONTROL

5.4.2 Ensure system accounts are securedCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

5.7 Ensure access to the su command is restricted - pam_wheel.soCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

5.7 Ensure access to the su command is restricted - wheel group contains rootCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.2.12 Ensure all groups in /etc/passwd exist in /etc/groupCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Red Hat 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate UIDs existCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate UIDs existCIS Red Hat 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.19 Ensure no duplicate group names existCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

6.3.3 Use pam_deny.so to Deny Services - auth requisite pam_deny.so /etc/pam.d/sshdCIS Red Hat Enterprise Linux 5 L1 v2.2.1Unix

ACCESS CONTROL

6.5 Ensure 'Superuser' Runtime Parameters are ConfiguredCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

7.1 Ensure a replication-only user is created and used for streaming replicationCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

7.3 Disable the dnssec-accept-expired OptionCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

ACCESS CONTROL

7.3 Disable the dnssec-accept-expired OptionCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

ACCESS CONTROL

9.1 Ensure 'zosSecurity-1.0' feature is 'enabled' for SAF authorizationCIS IBM WebSphere Liberty v1.0.0 L1Unix

ACCESS CONTROL