Item Search

NameAudit NamePluginCategory
1.1.3 Ensure that the --insecure-allow-any-token argument is not setCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

1.1.17 Ensure that the controller-manager.conf file permissions are set to 600 or more restrictiveCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.18 Ensure that the controller-manager.conf file ownership is set to root:rootCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

1.1.23 Ensure that the --service-account-lookup argument is set to trueCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

1.1.38 Ensure that the --request-timeout argument is set as appropriateCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

AUDIT AND ACCOUNTABILITY

1.2.29 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate - keyCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.3.3 Ensure that the --use-service-account-credentials argument is set to trueCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

ACCESS CONTROL

1.4.2 Ensure that the API server pod specification file ownership is set to root:rootCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

CONFIGURATION MANAGEMENT

1.4.3 Ensure that the controller manager pod specification file permissions are set to 644 or more restrictiveCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

CONFIGURATION MANAGEMENT

1.4.4 Ensure that the controller manager pod specification file ownership is set to root:rootCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

CONFIGURATION MANAGEMENT

1.5.1 Ensure that the --cert-file and --key-file arguments are set as appropriate - ca-fileCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

1.5.1 Ensure that the --cert-file and --key-file arguments are set as appropriate - certCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes 1.11 Benchmark v1.3.0 L2Unix
1.5.9 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes 1.7.0 Benchmark v1.1.0 L2Unix
1.5.9 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes 1.8 Benchmark v1.2.0 L2Unix
1.9 SQLI-22-004300CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT II MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

1.143 ALMA-09-018830CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.1.11 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate - tls-private-key-fileCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

2.1.12 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate - tls-cert-fileCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

2.2.1 Ensure that the kubelet.conf file permissions are set to 644 or more restrictiveCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.1 Ensure that the kubelet.conf file permissions are set to 644 or more restrictiveCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.2 Ensure that the config file ownership is set to root:rootCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.2 Ensure that the kubelet.conf file ownership is set to root:rootCIS Kubernetes 1.13 Benchmark v1.4.1 L1Unix

CONFIGURATION MANAGEMENT

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.1.2 Service account token authentication should not be used for usersCIS Kubernetes v2.0.1 L1 Master NodeUnix

ACCESS CONTROL

4.5.1 Configure Image Provenance using ImagePolicyWebhook admission controllerCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

CONFIGURATION MANAGEMENT, MAINTENANCE

4.5.1 Configure Image Provenance using ImagePolicyWebhook admission controllerCIS Google Kubernetes Engine GKE v1.9.0 L2 GCPGCP

CONFIGURATION MANAGEMENT, MAINTENANCE

5.2.1 Minimize the admission of privileged containersCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL

5.2.2 Minimize the admission of containers wishing to share the host process ID namespaceCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.5 Minimize the admission of containers with allowPrivilegeEscalationCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL

5.4.7 Ensure minimum and maximum requirements are set for password changes - maxrepeatCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.140 - The HBSS McAfee Agent is not installed. - FrameworkServiceDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

CASA-ND-000090 - The Cisco ASA must be configured to automatically audit account creation.DISA STIG Cisco ASA NDM v2r5Cisco

ACCESS CONTROL

CASA-ND-000160 - The Cisco ASA must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.DISA STIG Cisco ASA NDM v2r5Cisco

ACCESS CONTROL

CASA-ND-000240 - The Cisco ASA must be configured to generate audit records when successful/unsuccessful attempts to access privileges occur.DISA STIG Cisco ASA NDM v2r5Cisco

AUDIT AND ACCOUNTABILITY

CASA-ND-000470 - The Cisco ASA must be configured to implement replay-resistant authentication mechanisms for network access to privileged accounts.DISA STIG Cisco ASA NDM v2r5Cisco

IDENTIFICATION AND AUTHENTICATION

CASA-ND-000530 - The Cisco ASA must be configured to enforce password complexity by requiring that at least one lowercase character be used.DISA STIG Cisco ASA NDM v2r5Cisco

IDENTIFICATION AND AUTHENTICATION

CASA-ND-000690 - The Cisco ASA must be configured to terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.DISA STIG Cisco ASA NDM v2r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CASA-ND-000920 - The Cisco ASA must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.DISA STIG Cisco ASA NDM v2r5Cisco

AUDIT AND ACCOUNTABILITY

CASA-ND-001070 - The Cisco ASA must be configured to encrypt Simple Network Management Protocol (SNMP) messages using a FIPS 140-2 approved algorithm.DISA STIG Cisco ASA NDM v2r5Cisco

IDENTIFICATION AND AUTHENTICATION

O112-BP-022200 - The Oracle password file ownership and permissions should be limited and the REMOTE_LOGIN_PASSWORDFILE parameter must be set to EXCLUSIVE or NONE.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-BP-025600 - Network access to the DBMS must be restricted to authorized personnel.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-BP-026400 - The /diag subdirectory under the directory assigned to the DIAGNOSTIC_DEST parameter must be protected from unauthorized access.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-BP-026500 - Remote administration must be disabled for the Oracle connection manager.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-C1-011100 - Vendor-supported software must be evaluated and patched against newly found vulnerabilities.DISA STIG Oracle 11.2g v2r5 WindowsWindows

SYSTEM AND INFORMATION INTEGRITY

O112-C2-001700 - The DBMS must support the disabling of network protocols deemed by the organization to be non-secure.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-C2-014600 - The DBMS must support organizational requirements to enforce password encryption for storage.DISA STIG Oracle 11.2g v2r5 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

O112-C2-015100 - DBMS passwords must not be stored in compiled, encoded, or encrypted batch jobs or compiled, encoded, or encrypted application source code.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-C2-015700 - The DBMS must use NIST-validated FIPS 140-2-compliant cryptography for authentication mechanisms.DISA STIG Oracle 11.2g v2r5 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

O112-C2-019100 - The DBMS must protect against or limit the effects of the organization-defined types of Denial of Service (DoS) attacks.DISA STIG Oracle 11.2g v2r5 LinuxUnix

ACCESS CONTROL