Item Search

NameAudit NamePluginCategory
1.1.2.3 Ensure 'Authentication with Exchange server.' is set to 'Enabled:Kerberos/NTLM Password Authentication'CIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

IDENTIFICATION AND AUTHENTICATION

1.1.3.2.1.2 Ensure 'Disable all trusted locations' is set to EnabledCIS Microsoft Office Access 2013 v1.0.1Windows

CONFIGURATION MANAGEMENT

1.2.1 Ensure 'Do Not Show Data Extraction Options When Opening Corrupt Workbooks' is set to EnabledCIS Microsoft Office Excel 2013 v1.0.1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.4.2 Ensure 'Default file format' is set to Enabled (Access 2007)CIS Microsoft Office Access 2013 v1.0.1Windows

CONFIGURATION MANAGEMENT

1.4.7.2.1.5 Ensure 'Excel 4 Worksheets' is set to Enabled(Open/Save blocked, use open policy)CIS Microsoft Office Excel 2013 v1.0.1Windows

SYSTEM AND INFORMATION INTEGRITY

1.4.7.2.1.9 Ensure 'Excel 95 Workbooks' is set to Enabled (Open/Save Blocked, Use Open Policy)CIS Microsoft Office Excel 2013 v1.0.1Windows

SYSTEM AND INFORMATION INTEGRITY

1.4.7.2.3.2 Ensure 'Disabled all Trusted Locations' is set to EnabledCIS Microsoft Office Excel 2013 v1.0.1Windows

CONFIGURATION MANAGEMENT

1.4.7.5 Ensure' Scan Encrypted Macros in Excel Open XML Workbooks' is set to Enable (Scan encrypted macros (default))CIS Microsoft Office Excel 2013 v1.0.1Windows

SYSTEM AND INFORMATION INTEGRITY

1.5.2 Ensure 'Modal Trust Decision Only' is set to DisabledCIS Microsoft Office Access 2013 v1.0.1Windows

CONFIGURATION MANAGEMENT

1.6.2 Ensure 'Use Online Translation Dictionaries' is set to DisabledCIS Microsoft Office Word 2013 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.6.5.1 Ensure 'Default file format' is set to Enabled (PowerPoint Presentation (*pptx))CIS Microsoft Office PowerPoint 2013 v1.0.1Windows

CONFIGURATION MANAGEMENT

1.6.6.2.3.2 Ensure 'Disable all trusted locations' is set to EnabledCIS Microsoft Office PowerPoint 2013 v1.0.1Windows

CONFIGURATION MANAGEMENT

1.6.6.4 Ensure 'Scan Encrypted Macros in PowerPoint Open XML Presentations' is set to Enabled (Scan Encrypted Macros)CIS Microsoft Office PowerPoint 2013 v1.0.1Windows

SYSTEM AND INFORMATION INTEGRITY

1.6.6.7 Ensure 'Unblock Automatic Download of Linked Images' is set to DisabledCIS Microsoft Office PowerPoint 2013 v1.0.1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.8.2.1 Ensure 'PST Null Data On Delete' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.8.7.2.3.2 Ensure 'Disable All Trusted Locations' is set to EnabledCIS Microsoft Office Word 2013 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.8.7.2.4 Ensure 'Scan Encrypted Macros in Word Open XML Documents' to EnabledCIS Microsoft Office Word 2013 v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

1.9.6.1.2 Ensure 'Do not allow folders in non-default stores to be set as folder home pages' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.9.6.3 Ensure 'Make Outlook the default program for E-mail, Contacts, and Calendar' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.9.8.1.2.1 Ensure 'Access to published calendars' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

ACCESS CONTROL

1.9.8.4.4 Ensure 'Trust e-mail from contacts' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.13.2.8 Ensure 'Send all signed messages as clear signed messages' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.13.3.1.6 Ensure 'Remove file extensions blocked as Level 2' is set to DisabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.13.4.1 Ensure 'Allow hyperlinks in suspected phishing e-mail messages' is set to DisabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND INFORMATION INTEGRITY

4.6 Ensure That IP Forwarding Is Not Enabled on InstancesCIS Google Cloud Platform Foundation v5.0.0 L1GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.5 Firewall ConsiderationCIS Apple macOS 10.12 L2 v1.2.0Unix

CONFIGURATION MANAGEMENT

Allow Basic Authentication prompts from network proxiesMSCT M365 Apps for enterprise 2412 v1.0.0Windows
CIS_Microsoft_Exchange_2019_Edge_Server_STIG_v1.0.0_CAT_I.audit from CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IWindows
CIS_Microsoft_Exchange_2019_Edge_Server_STIG_v1.0.0_CAT_II.audit from CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows
CIS_Microsoft_Exchange_2019_Mailbox_Server_STIG_v1.0.0_CAT_II.audit from CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIWindows
CIS_Microsoft_Exchange_2019_Mailbox_Server_STIG_v1.0.0_CAT_III.audit from CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIIWindows
CIS_Microsoft_SQL_Server_2022_Instance_STIG_v1.0.0_CAT_I_Windows.audit from CIS Microsoft SQL Server 2022 Instance STIG v1.0.0CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I WindowsWindows
CIS_Microsoft_SQL_Server_2022_Instance_STIG_v1.0.0_CAT_II_Windows.audit from CIS Microsoft SQL Server 2022 Instance STIG v1.0.0CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT II WindowsWindows
DISA_VMware_vSphere_8.0_vCenter_Appliance_Management_Interface_(VAMI)_STIG_v2r1.audit from DISA VMware vSphere 8.0 vCenter Appliance Management Interface (VAMI) STIG v2r1DISA VMware vSphere 8.0 vCenter Appliance Management Interface (VAMI) STIG v2r1Unix
DISA_VMware_vSphere_8.0_vCenter_Appliance_User_Interface_(UI)_STIG_v2r1.audit from DISA VMware vSphere 8.0 vCenter Appliance User Interface (UI) STIG v2r1DISA VMware vSphere 8.0 vCenter Appliance User Interface (UI) STIG v2r1Unix
EX13-CA-000025 - Exchange must have Administrator audit logging enabled.DISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

ACCESS CONTROL

EX13-CA-000035 - Exchange ActiveSync (EAS) must only use certificate-based authentication to access email - BasicAuthEnabledDISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

ACCESS CONTROL

EX13-CA-000035 - Exchange ActiveSync (EAS) must only use certificate-based authentication to access email - ExternalAuthenticationMethodsDISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

ACCESS CONTROL

EX13-CA-000035 - Exchange ActiveSync (EAS) must only use certificate-based authentication to access email - WindowsAuthEnabledDISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

ACCESS CONTROL

EX13-CA-000080 - Exchange must have audit data protected against unauthorized deletion.DISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

EX13-CA-000115 - Exchange application directory must be protected from unauthorized access.DISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

CONFIGURATION MANAGEMENT

EX13-CA-000150 - Exchange OWA must use https - InternalDISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-CA-000160 - The version of Exchange running on the system must be a supported version.DISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

EX13-CA-000165 - Exchange must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.DISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

CONFIGURATION MANAGEMENT

EX13-EG-000030 - The Exchange email Diagnostic log level must be set to the lowest level.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

AUDIT AND ACCOUNTABILITY

EX13-EG-000095 - Exchange Outbound Connection Timeout must be 10 minutes or less.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-EG-000100 - Exchange Outbound Connection Limit per Domain Count must be controlled.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-EG-000155 - The Exchange Internet Receive connector connections count must be set to default.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-EG-000170 - Exchange messages with a blank sender field must be filtered.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND INFORMATION INTEGRITY

F5BI-AP-000231 - The F5 BIG-IP appliance must be configured to deny access when revocation data is unavailable using OCSP.DISA F5 BIG-IP Access Policy Manager STIG v2r4F5

IDENTIFICATION AND AUTHENTICATION