Item Search

NameAudit NamePluginCategory
1.1 Keep ESXi system properly patchedCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
1.22 Ensure 'Wi-Fi assistant' is set to 'Disabled'MobileIron - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.3 Disable Managed Object Browser (MOB)CIS VMware ESXi 5.1 v1.0.1 Level 1VMware
2.6 Ensure proper SNMP configuration- 'community name public does not exist'CIS VMware ESXi 5.1 v1.0.1 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

2.7 Prevent unintended use of dvfilter network APIsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

2.8 When adding ESXi hosts to Active Directory use the vSphere Authentication Proxy to protect passwordsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
3.3 Configure persistent logging for all ESXi hostCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

AUDIT AND ACCOUNTABILITY

3.9 Ensure 'audit_log_file' Has Appropriate PermissionsCIS MySQL 5.7 Enterprise Database L1 v2.0.0MySQLDB

ACCESS CONTROL, MEDIA PROTECTION

4.1 - System Administration Methods - Message of the DayNetApp Security Hardening Guide for ONTAP 9 v1.7.0Netapp_API

ACCESS CONTROL

4.1 Create a non-root user account for local admin accessCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
4.1 Use TSIG Keys 256 Bits in LengthCIS BIND DNS v3.0.1 Caching Only Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

4.2 Enable Auditing of Incoming Network Connections - AUE_inetd_connect : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.2 Enable Auditing of Incoming Network Connections - AUE_SOCKCONNECT : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

5.1 Ensure that system activity is auditedCIS MongoDB 5 L1 OS Linux v1.2.0Unix

AUDIT AND ACCOUNTABILITY

5.2 Disable ESXi Shell unless needed for diagnostics or troubleshootingCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

5.3 Ensure 'PROCESS' is Not Granted to Non-Administrative UsersCIS Oracle MySQL Enterprise Edition 8.0 v1.4.0 L2 DatabaseMySQLDB

ACCESS CONTROL

5.6 Set a timeout to automatically terminate idle ESXi Shell and SSH sessionsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

6.1 Enable bidirectional CHAP authentication for iSCSI trafficCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

7.1 Ensure default_authentication_plugin is Set to a Secure OptionCIS Oracle MySQL Community Server 8.4 v1.0.0 L1 DatabaseMySQLDB

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.1 Ensure default_authentication_plugin is Set to a Secure OptionCIS Oracle MySQL Enterprise Edition 8.0 v1.4.0 L1 DatabaseMySQLDB

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.1 Ensure default_authentication_plugin is Set to a Secure OptionCIS MySQL 8.0 Community Database L1 v1.1.0MySQLDB

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.1 Ensure default_authentication_plugin is Set to a Secure OptionCIS MySQL 8.4 Enterprise v1.0.0 L1 DatabaseMySQLDB

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.1.2 Ensure that the MAC Address Change policy is set to rejectCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.1.4 Ensure that there are no unused ports on a distributed virtual port groupCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
7.1.6 Verify that the autoexpand option for VDS dvPortgroups is disabledCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
7.2.1 Ensure that port groups are not configured to the value of the native VLANCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
7.3 Ensure 'sql_mode' Contains 'NO_AUTO_CREATE_USER' - %PROGRAMDATA%\MySQL\MySQL Server 5.7\my.cnfCIS MySQL 5.7 Community Windows OS L1 v2.0.0Windows

PLANNING, SYSTEM AND SERVICES ACQUISITION

7.3 Ensure 'sql_mode' Contains 'NO_AUTO_CREATE_USER' - %PROGRAMDATA%\MySQL\MySQL Server 5.7\my.iniCIS MySQL 5.7 Community Windows OS L1 v2.0.0Windows

PLANNING, SYSTEM AND SERVICES ACQUISITION

7.3 Ensure 'sql_mode' Contains 'NO_AUTO_CREATE_USER' - %PROGRAMDATA%\MySQL\MySQL Server 5.7\my.iniCIS MySQL 5.7 Enterprise Windows OS L1 v2.0.0Windows

PLANNING, SYSTEM AND SERVICES ACQUISITION

7.3.2 Ensure that the vSwitch MAC Address Change policy is set to rejectCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.3.3 Ensure that the vSwitch Promiscuous Mode policy is set to rejectCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

8.1.3 Limit sharing of console connectionsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

8.2.1 Disconnect unauthorized devices - Floppy DevicesCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

MEDIA PROTECTION

8.2.3 Disconnect unauthorized devices - Parallel DevicesCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

8.3.3 Use secure protocols for virtual serial port accessCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
8.3.4 Use templates to deploy VMs whenever possibleCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
8.4.4 Control VMsafe Agent ConfigurationCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND INFORMATION INTEGRITY

8.4.12 Disable Drag and Drop Version GetCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.13 Disable Drag and Drop Version SetCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.20 Disable GetCredsCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.21 Disable Host Guest File System ServerCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.24 Disable VM Monitor ControlCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.26 Disable VM Console Drag and Drop operationsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

8.5.1 Prevent virtual machines from taking over resources - CPU Share LevelCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

8.5.1 Prevent virtual machines from taking over resources - Mem Share LevelCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

CIS VMware ESXi 5.5 v1.2.0 Level 1CIS VMware ESXi 5.5 v1.2.0 Level 1VMware
HONW-09-002300 - The Honeywell Mobility Edge Android Pie device must be configured to disable trust agents.MobileIron - DISA Honeywell Android 9.x COBO v1r2MDM

CONFIGURATION MANAGEMENT

MOTS-11-002300 - Motorola Solutions Android 11 must be configured to disable trust agents.MobileIron - DISA Motorola Solutions Android 11 COBO v1r3MDM

CONFIGURATION MANAGEMENT

MYS8-00-000300 - MySQL Database Server 8.0 must produce audit records containing sufficient information to establish what type of events occurred.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

AUDIT AND ACCOUNTABILITY

MYS8-00-006500 - The MySQL Database Server 8.0 must isolate security functions from non-security functions.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION