Item Search

NameAudit NamePluginCategory
1.1.23 Disable USB Storage - lsmodCIS Oracle Linux 6 Workstation L2 v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.23 Disable USB Storage - lsmodCIS CentOS 6 Workstation L2 v3.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.24 Disable USB Storage - modprobeCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.27 Disable AutomountingCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 WorkstationUnix

MEDIA PROTECTION

1.4 Ensure 'application pool identity' is configured for all application poolsCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.4 Ensure 'application pool identity' is configured for all application poolsCIS IIS 8.0 v1.5.1 Level 1Windows

ACCESS CONTROL

1.36 IIST-SI-000252CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

2.2.29 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only)CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DCWindows

ACCESS CONTROL

2.2.29 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only)CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DCWindows

ACCESS CONTROL

2.2.30 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' and (when the Web Server (IIS) Role with Web Services Role Service is installed) 'IIS_IUSRS' (MS only)CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MSWindows

ACCESS CONTROL

2.2.31 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only)CIS Windows Server 2012 DC L1 v3.0.0Windows

ACCESS CONTROL

2.7 Ensure 'passwordFormat' is not set to clear - ApplicationsCIS IIS 10 v1.2.1 Level 1Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.7 Ensure 'passwordFormat' is not set to clear - DefaultCIS IIS 10 v1.2.1 Level 1Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.2 Ensure 'debug' is turned off - ApplicationsCIS IIS 10 v1.2.1 Level 2Windows

SYSTEM AND SERVICES ACQUISITION

3.2 Set 'Require Client Certificates' to 'Required'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows
3.2 Set 'Require Client Certificates' to 'Required'CIS Microsoft Exchange Server 2016 CAS v1.0.0Windows
3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely - ApplicationsCIS IIS 7 L1 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

3.7 Ensure that SharePoint is set to reject or delay network traffic generated above configurable traffic volume thresholds - Max BandwidthCIS Microsoft SharePoint 2019 OS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.7 Ensure that SharePoint is set to reject or delay network traffic generated above configurable traffic volume thresholds - Max ConnectionsCIS Microsoft SharePoint 2019 OS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.11 Ensure 'encryption providers' are locked downCIS IIS 7 L2 v1.8.0Windows

ACCESS CONTROL

4.4 Ensure non-ASCII characters in URLs are not allowed - DefaultCIS IIS 10 v1.2.1 Level 2Windows

SYSTEM AND SERVICES ACQUISITION

4.5 Ensure Double-Encoded requests will be rejected - DefaultCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND INFORMATION INTEGRITY

4.6 Ensure 'HTTP Trace Method' is disabled - ApplicationsCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

4.6 Ensure 'HTTP Trace Method' is disabled - DefaultCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

5.2 Ensure forwarding is enabled for all applications and file types in WildFire file blocking profilesCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.2 Ensure forwarding is enabled for all applications and file types in WildFire file blocking profilesCIS Palo Alto Firewall 7 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.3 Ensure 'ETW Logging' is enabledCIS IIS 8.0 v1.5.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

5.3 Ensure a WildFire file blocking profile is enabled for all security policies allowing Internet traffic flowsCIS Palo Alto Firewall 7 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.3 Ensure a WildFire file blocking profile is enabled for all security policies allowing Internet traffic flowsCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.1 Ensure at least one antivirus profile is set to block on all decoders except 'imap' and 'pop3'CIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.1 Ensure at least one antivirus profile is set to block on all decoders except 'imap' and 'pop3'CIS Palo Alto Firewall 7 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.2 Ensure FTP Logon attempt restrictions is enabledCIS IIS 8.0 v1.5.1 Level 1Windows
6.2 Ensure FTP Logon attempt restrictions is enabled - Deny By Failure EnabledCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

6.2 Ensure FTP Logon attempt restrictions is enabled - Deny IP AddressCIS IIS 8.0 v1.5.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

6.3 Ensure an anti-spyware profile is configured to block on all spyware severity levels, categories, and threatsCIS Palo Alto Firewall 7 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.3 Ensure an anti-spyware profile is configured to block on all spyware severity levels, categories, and threatsCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.6 Ensure a secure anti-spyware profile is applied to all security policies permitting traffic to the InternetCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_Apache_Site-2.4_Unix_v2r6_Middleware.audit from DISA Apache Server 2.4 UNIX Site v2r6 STIGDISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix
DISA_STIG_Microsoft_Exchange_2019_Edge_Server_v2r2.audit from DISA Microsoft Exchange 2019 Edge Server STIG v2r2DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows
DISA_STIG_Microsoft_Exchange_2019_Mailbox_Server_v2r3.audit from DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows
DISA_STIG_Server_2012_and_2012_R2_MS_v3r7.audit from DISA Microsoft Windows Server 2012/2012 R2 Member Server v3r7 STIGDISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows
DISA_STIG_SLES_12_v3r5.audit from DISA SUSE Linux Enterprise Server 12 v3r5 STIGDISA SLES 12 STIG v3r5Unix
DISA_STIG_SUSE_Linux_Enterprise_Server_15_v2r6.audit from DISA SUSE Linux Enterprise Server 15 STIG v2r6DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix
EX13-CA-000130 - Exchange services must be documented and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

CONFIGURATION MANAGEMENT

EX13-EG-000305 - Exchange services must be documented and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

CONFIGURATION MANAGEMENT

EX13-MB-000300 - Exchange services must be documented and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

CONFIGURATION MANAGEMENT

EX16-ED-000610 - Exchange services must be documented and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX19-ED-000199 - Exchange services must be documented, and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

CONFIGURATION MANAGEMENT

IIST-SV-000130 - Java software installed on a production IIS 10.0 web server must be limited to .class files and the Java Virtual Machine.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000144 - IIS 10.0 web server system files must conform to minimum file permission requirements.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

ACCESS CONTROL