Item Search

NameAudit NamePluginCategory
1.8.2 Ensure GDM login banner is configured - banner message textCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.10 Ensure 'Install unknown apps' is set to 'Disabled'AirWatch - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.1.1 Ensure 'extproc' Is Not EnabledCIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS UnixUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

ACCESS CONTROL

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

ACCESS CONTROL

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

ACCESS CONTROL

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

ACCESS CONTROL

2.3.10.7 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

ACCESS CONTROL

2.3.10.8 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

ACCESS CONTROL

2.3.10.8 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

ACCESS CONTROL

2.3.10.8 Ensure 'Network access: Remotely accessible registry paths' is configuredCIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

ACCESS CONTROL

3.2.1.13 Ensure 'Allow trusting new enterprise app authors' is set to 'Disabled'MobileIron - CIS Apple iOS 18 v2.0.0 L1 Institution OwnedMDM

CONFIGURATION MANAGEMENT

3.2.1.13 Ensure 'Allow trusting new enterprise app authors' is set to 'Disabled'MobileIron - CIS Apple iOS 26 v1.0.0 L1 Institution OwnedMDM

CONFIGURATION MANAGEMENT

3.2.1.14 Ensure 'Allow trusting new enterprise app authors' is set to 'Disabled'MobileIron - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally OwnedMDM

CONFIGURATION MANAGEMENT

3.2.1.14 Ensure 'Allow trusting new enterprise app authors' is set to 'Disabled'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.2.1.14 Ensure 'Allow trusting new enterprise app authors' is set to 'Disabled'MobileIron - CIS Apple iPadOS 17 Institutionally Owned L1MDM

CONFIGURATION MANAGEMENT

4.3 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 11 v1.0.0 Institution Owned L1MDM
4.3 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 12 v1.0.0 End User Owned L1MDM
4.3 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.3 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.3 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 10 v2.0.0 End User Owned L1MDM
4.3 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 10 v2.0.0 Institution Owned L1MDM
4.3 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 11 v1.0.0 End User Owned L1MDM
4.7 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.7 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.7 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.7 Ensure 'Automatic Downloads' of 'App Updates' is set to 'Enabled'MobileIron - CIS Apple iOS 18 v2.0.0 L1 Institution OwnedMDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

6.2.3.9 Ensure events that modify /etc/netplan are collectedCIS Ubuntu Linux 24.04 LTS v2.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.9 Ensure events that modify /etc/netplan are collectedCIS Debian Linux 12 v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.9 Ensure events that modify /etc/netplan are collectedCIS Debian Linux 12 v2.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

18.9.7.1.5 (BL) Ensure 'Prevent installation of devices using drivers that match these device setup classes: Prevent installation of devices using drivers for these device setup' is set to 'IEEE 1394 device setup classes'CIS Microsoft Windows 10 Stand-alone v4.0.0 BLWindows

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_Red_Hat_Enterprise_Linux_7_v3r15.audit from DISA Red Hat Enterprise Linux 7 v3r15 STIGDISA Red Hat Enterprise Linux 7 STIG v3r15Unix
DISA_STIG_Red_Hat_Enterprise_Linux_10_v1r2.audit from DISA Red Hat Enterprise Linux 10 STIG v1r2DISA Red Hat Enterprise Linux 10 STIG v1r2Unix
DTAVSEL-110 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Demand scanner must be configured to Clean infected files automatically as first action when programs and jokes are found.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

Ensure 'logging to monitor' is disabledTenable Cisco Firepower Best Practices AuditCisco

CONFIGURATION MANAGEMENT

GEN000950 - The root account's list of preloaded libraries must be empty.DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN000950 - The root account's list of preloaded libraries must be empty.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000950-ESXI5-444 - The root accounts list of preloaded libraries must be empty.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

CONFIGURATION MANAGEMENT

GEN007841-ESXI5-000120 - Wireless network adapters must be disabled.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

Prevent installation of devices using drivers that match these device setup classes - 1MSCT Windows 11 v1.0.0Windows

MEDIA PROTECTION

Prevent installation of devices using drivers that match these device setup classes - DenyDeviceClassesMSCT Windows 11 v25H2 v1.0.0Windows

MEDIA PROTECTION

RHEL-07-030780 - The Red Hat Enterprise Linux operating system must audit all uses of the ssh-keysign command.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-07-031000 - The Red Hat Enterprise Linux operating system must send rsyslog output to a log aggregation server.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040260 - The default umask for FTP users must be 077.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040260 - The default umask for FTP users must be 077.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

WPAW-00-000600 - All high-value IT resources must be assigned to a specific administrative tier to separate highly sensitive resources from less sensitive resources.DISA Microsoft Windows PAW STIG v3r2Windows

CONFIGURATION MANAGEMENT