Item Search

NameAudit NamePluginCategory
1.2 Password Security Policy - e) Check for strong-password max-lengthTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.2 Password Security Policy - f) The validity period of an account can be configuredTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.3 Account Anti-riot AttackTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.5 FTP/SFTP Access Authorization - login-type-allowedTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.5 FTP/SFTP Access Authorization - sftp top-directoryTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.6 Support Web Access Security - a) ciphersuiteTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.7 Log AuditingTenable ZTE ROSNG Best PracticesZTE_ROSNG

AUDIT AND ACCOUNTABILITY

1.8 SSH Strong Algorithm - c) Disable encryption aes128-cbcTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - d) Disable encryption aes192-cbcTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - g) Disable hmac md5Tenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - h) Disable hmac noneTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.9 SSL Strong Algorithm - a) VersionTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.9 SSL Strong Algorithm - b) ciphersuiteTenable ZTE ROSNG Best PracticesZTE_ROSNG
2.2 NTP Security Protection - a) Enable NTPTenable ZTE ROSNG Best PracticesZTE_ROSNG

AUDIT AND ACCOUNTABILITY

2.3 Disable the Proxy ARP Function - a) No proxyTenable ZTE ROSNG Best PracticesZTE_ROSNG
2.3 Disable the Proxy ARP Function - d) No local-proxy-arpTenable ZTE ROSNG Best PracticesZTE_ROSNG
3.1 Authentication and Verification of OSPFv3 Routing Protocols - authentication keychain/ipsecTenable ZTE ROSNG Best PracticesZTE_ROSNG
3.2 Authentication and Verification of ISIS Routing Protocols - authentication-type hmac-md5/authentication-keychainTenable ZTE ROSNG Best PracticesZTE_ROSNG
6.1 Perform regular security audits of your host system and containersCIS Docker 1.11.0 v1.0.0 L1 DockerUnix
7.2 Ensure Asymmetric Key Size is set to 'greater than or equal to 2048' in non-system databasesCIS SQL Server 2017 Database L1 AWS RDS v1.3.0MS_SQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

12.20 Monitor for development on production databases - 'Prevent development on production databases'CIS v1.1.0 Oracle 11g OS L1Unix
12.20 Monitor for development on production databases - 'Prevent development on production databases'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows
Big Sur - Disable Unix-to-Unix Copy Protocol ServiceNIST macOS Big Sur v1.4.0 - 800-53r5 HighUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Big Sur - Disable Unix-to-Unix Copy Protocol ServiceNIST macOS Big Sur v1.4.0 - 800-53r4 LowUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Big Sur - Disable Unix-to-Unix Copy Protocol ServiceNIST macOS Big Sur v1.4.0 - 800-53r5 ModerateUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Big Sur - Disable Unix-to-Unix Copy Protocol ServiceNIST macOS Big Sur v1.4.0 - CNSSI 1253Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Brocade - All audit severity level must be auditedTenable Best Practices Brocade FabricOSBrocade

AUDIT AND ACCOUNTABILITY

Brocade - Brocade licenses must not be expiredTenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Configures filters for a specified audit classTenable Best Practices Brocade FabricOSBrocade

AUDIT AND ACCOUNTABILITY

Brocade - Device Connection Control policy must be rejectedTenable Best Practices Brocade FabricOSBrocade

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade - Disable HTTPTenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Disable HTTP IPv4Tenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Disable HTTP IPv6Tenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Disable TFTP IPv4Tenable Best Practices Brocade FabricOSBrocade

CONFIGURATION MANAGEMENT

Brocade - Enable the power-on self-test (POST)Tenable Best Practices Brocade FabricOSBrocade

SYSTEM AND INFORMATION INTEGRITY

Brocade - Enable the track changes featureTenable Best Practices Brocade FabricOSBrocade

AUDIT AND ACCOUNTABILITY

Brocade - Enforce signature validation for firmwareTenable Best Practices Brocade FabricOSBrocade

SYSTEM AND INFORMATION INTEGRITY

Brocade - FIPS Mode is enabledTenable Best Practices Brocade FabricOSBrocade

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade - IPfilter policy must be rejectedTenable Best Practices Brocade FabricOSBrocade

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade - lockout threshold set to 3Tenable Best Practices Brocade FabricOSBrocade

ACCESS CONTROL

Brocade - minimum password age must be set to at least 30 daysTenable Best Practices Brocade FabricOSBrocade

IDENTIFICATION AND AUTHENTICATION

Brocade - password history must be set to 1Tenable Best Practices Brocade FabricOSBrocade

IDENTIFICATION AND AUTHENTICATION

Brocade - Review the NTP server configurationTenable Best Practices Brocade FabricOSBrocade

AUDIT AND ACCOUNTABILITY

DG0102-ORACLE11 - DBMS processes or services should run under custom, dedicated OS accounts - 'tns services are using correct service account'DISA STIG Oracle 11 Instance v9r1 OS UnixUnix

ACCESS CONTROL

Ensure that database instances do not allow root accessTenable Best Practices RackSpace v2.0.0Rackspace

ACCESS CONTROL

EPAS-00-004950 - The EDB Postgres Advanced Server must be configured on a platform that has a NIST-certified FIPS 140-2 or 140-3 installation of OpenSSL.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

IDENTIFICATION AND AUTHENTICATION

OpenStack Inactive ServersTenable Best Practices OpenStack v2.0.0OpenStack

CONFIGURATION MANAGEMENT

OpenStack Servers created since the last scanTenable Best Practices OpenStack v2.0.0OpenStack

CONFIGURATION MANAGEMENT

PGS9-00-012800 - The DBMS must be configured on a platform that has a NIST certified FIPS 140-2 or 140-3 installation of OpenSSL.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

IDENTIFICATION AND AUTHENTICATION

PPS9-00-013200 - The EDB Postgres Advanced Server must be configured on a platform that has a NIST certified FIPS 140-2 ior 140-3 nstallation of OpenSSL.EDB PostgreSQL Advanced Server OS Linux Audit v2r3Unix

IDENTIFICATION AND AUTHENTICATION