Item Search

NameAudit NamePluginCategory
1.1 Ensure single sign-on (SSO) is configured for your account / organizationCIS Snowflake Foundations v2.0.0 L1Snowflake

ACCESS CONTROL

1.3 Ensure that Snowflake password is unset for SCIM-managed usersCIS Snowflake Foundations v2.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION

1.3.1 Ensure 'Minimum Password Complexity' is enabledCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

IDENTIFICATION AND AUTHENTICATION

1.4 Ensure that person users do not use password-only authenticationCIS Snowflake Foundations v2.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION

1.6 Ensure that legacy service users are migrated to service usersCIS Snowflake Foundations v2.0.0 L1Snowflake

CONFIGURATION MANAGEMENT

1.8 Ensure that users who did not log in for 90 days are disabledCIS Snowflake Foundations v2.0.0 L1Snowflake

ACCESS CONTROL

1.9 Ensure that the idle session timeout is set to 15 minutes or less for users with the ACCOUNTADMIN and SECURITYADMIN rolesCIS Snowflake Foundations v2.0.0 L1Snowflake

ACCESS CONTROL

1.13 Ensure that the ACCOUNTADMIN or SECURITYADMIN role is not granted to any custom roleCIS Snowflake Foundations v2.0.0 L1Snowflake

ACCESS CONTROL

1.14 Ensure that Snowflake tasks are not owned by the ACCOUNTADMIN or SECURITYADMIN rolesCIS Snowflake Foundations v2.0.0 L1Snowflake

ACCESS CONTROL

1.18 Ensure that an account-level authentication policy has been configured to require network policies when using Programmatic Access Tokens (PATs)CIS Snowflake Foundations v2.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION

1.19 Ensure that an account-level authentication policy has been configured to require Programmatic Access Tokens be rotated at least every 90 daysCIS Snowflake Foundations v2.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION

2.1 Ensure monitoring and alerting exist for ACCOUNTADMIN and SECURITYADMIN role grantsCIS Snowflake Foundations v2.0.0 L1Snowflake

AUDIT AND ACCOUNTABILITY

2.1.3 Ensure that Traffic is Encrypted Between Cluster Worker NodesCIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.6 Ensure monitoring and alerting exist for SCIM token creationCIS Snowflake Foundations v2.0.0 L1Snowflake

AUDIT AND ACCOUNTABILITY

2.7 Ensure monitoring and alerting exists for new share exposuresCIS Snowflake Foundations v2.0.0 L1Snowflake

AUDIT AND ACCOUNTABILITY

3.5 Retain install.log for 365 or more daysCIS Apple OSX 10.9 L1 v1.3.0Unix

AUDIT AND ACCOUNTABILITY

4.2 Ensure AES encryption key size used to encrypt files stored in internal stages is set to 256 bitsCIS Snowflake Foundations v2.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.4 Enable Auditing of Process and Privilege Events - AUE_CHROOT : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_CHROOT : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_FCHROOT : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_FCHROOT : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_NICE : cisCIS Solaris 11.1 L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_NICE : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_PFEXEC : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_PRIOCNTLSYS : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_PRIOCNTLSYS : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_SETEGID : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_SETEUID : cisCIS Solaris 11.1 L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_SETGID : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_SETPPRIV : cisCIS Solaris 11.1 L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_SETPPRIV : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Enable Auditing of Process and Privilege Events - AUE_SETPPRIV : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.11.53.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v5.0.0 L2Windows

AUDIT AND ACCOUNTABILITY

7.14 Ensure Request Body Inspection is Enabled in Azure Web Application Firewall policy on Azure Application GatewayCIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION

8.1.6.1 Ensure That Microsoft Defender for App Services Is Set To 'On'CIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION

8.4.1 Ensure an Azure Bastion Host ExistsCIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.100.1 (L1) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DCWindows

AUDIT AND ACCOUNTABILITY

18.9.100.1 (L1) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DCWindows

AUDIT AND ACCOUNTABILITY

18.10.86.1 (L1) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

AUDIT AND ACCOUNTABILITY

18.10.87.1 (L1) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Windows Server 2012 DC L1 v3.0.0Windows

AUDIT AND ACCOUNTABILITY

18.10.87.1 (L1) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Windows Server 2012 MS L1 v3.0.0Windows

AUDIT AND ACCOUNTABILITY

18.10.87.1 (L1) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Windows Server 2012 R2 MS L1 v3.0.0Windows

AUDIT AND ACCOUNTABILITY

18.10.87.1 (L2) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L2 MSWindows

AUDIT AND ACCOUNTABILITY

18.10.87.1 (L2) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L2 DCWindows

AUDIT AND ACCOUNTABILITY

18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L2 DCWindows

AUDIT AND ACCOUNTABILITY

18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L2 DCWindows

AUDIT AND ACCOUNTABILITY

18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BLWindows

AUDIT AND ACCOUNTABILITY

18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v5.0.0 L2Windows

AUDIT AND ACCOUNTABILITY

18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 BLWindows

AUDIT AND ACCOUNTABILITY

18.10.88.1 Ensure 'Turn on PowerShell Script Block Logging' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L2Windows

AUDIT AND ACCOUNTABILITY