Item Search

NameAudit NamePluginCategory
1.1.1 Ensure mounting of squashfs filesystems is disabled - lsmodCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.4 Ensure mounting of hfs filesystems is disabled - lsmodCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - lsmodCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.2 Ensure /tmp is configured - mountCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.6 Ensure separate partition exists for /varCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.9 Ensure nosuid option set on /var/tmp partitionCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.15 Ensure nodev option set on /dev/shm partitionCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.2.14 Ensure that the admission control plugin NamespaceLifecycle is setCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

CONFIGURATION MANAGEMENT

1.3.1 Ensure that the --terminated-pod-gc-threshold argument is set as appropriateCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND INFORMATION INTEGRITY

1.4.2 Ensure authentication required for single user mode - rescue.serviceCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.5.1 Ensure core dumps are restricted - sysctlCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.5.2 Ensure bootloader password is set - password_pbkdf2CIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.6.4 Ensure core dumps are restricted - processsizemaxCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.7.1.3 Ensure remote login warning banner is configured properly - banner checkCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.8.2 Ensure GDM login banner is configured - banner message enabledCIS CentOS 6 Server L1 v3.0.0Unix

CONFIGURATION MANAGEMENT

1.8.2 Ensure GDM login banner is configured - banner message enabledCIS CentOS 6 Workstation L1 v3.0.0Unix

CONFIGURATION MANAGEMENT

1.8.2 Ensure GDM login banner is configured - banner message textCIS CentOS 6 Server L1 v3.0.0Unix

CONFIGURATION MANAGEMENT

1.8.2 Ensure GDM login banner is configured - banner message textCIS CentOS 6 Workstation L1 v3.0.0Unix

CONFIGURATION MANAGEMENT

1.9 Ensure GDM is removed or login is configured - banner message enabledCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.9 Ensure GDM is removed or login is configured - disable-user-listCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.1.1 Ensure a 'Consent Message' has been 'Configured'MobileIron - CIS Apple iOS 13 and iPadOS 13 v1.0.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT

2.1.1 Ensure a 'Consent Message' has been 'Configured'AirWatch - CIS Apple iOS 14 and iPadOS 14 v1.0.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT

2.1.2 Ensure 'Controls when the profile can be removed' is set to 'Always'AirWatch - CIS Apple iOS 13 and iPadOS 13 v1.0.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT

2.2.1.5 Ensure 'Allow users to accept untrusted TLS certificates' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 v1.0.0 End User Owned L2MDM

CONFIGURATION MANAGEMENT

4.1.12 Ensure successful file system mounts are collected - auditctl mount x64CIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.16 Ensure kernel module loading and unloading is collected - auditctl /sbin/insmodCIS CentOS 6 Workstation L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

4.1.16 Ensure kernel module loading and unloading is collected - auditctl /sbin/modprobeCIS CentOS 6 Workstation L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

4.1.16 Ensure kernel module loading and unloading is collected - auditctl /sbin/rmmodCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.16 Ensure kernel module loading and unloading is collected - auditctl modulesCIS CentOS 6 Server L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

4.1.16 Ensure kernel module loading and unloading is collected - rules.d /sbin/rmmodCIS CentOS 6 Server L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

5.2 Use LockOut RealmsCIS Apache Tomcat 10 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

5.2 Use LockOut RealmsCIS Apache Tomcat 8 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

5.2.16 Ensure SSH LoginGraceTime is set to one minute or lessCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.2.18 Ensure SSH access is limitedCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.2.21 Ensure SSH MaxStartups is configuredCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.2.22 Ensure SSH MaxSessions is limitedCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.4.1.5 Ensure all users last password change date is in the pastCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/bashrcCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.6 Ensure access to the su command is restrictedCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.7.3 Apply Security Context to Your Pods and ContainersCIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

CONFIGURATION MANAGEMENT

6.1.14 Audit SGID executablesCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.1.14 Audit SGID executablesCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.4 Ensure no legacy "+" entries exist in /etc/groupCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

10.8 Do not allow additional path delimiters - ALLOW_ENCODED_SLASHCIS Apache Tomcat 8 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

10.9 Configure connectionTimeoutCIS Apache Tomcat 9 L2 v1.2.0Unix

CONFIGURATION MANAGEMENT

10.9 Do not allow custom header status messagesCIS Apache Tomcat 8 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

10.16 Enable memory leak listenerCIS Apache Tomcat 10 L1 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

10.17 Enable memory leak listener - verify presentCIS Apache Tomcat 8 L1 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

11.1 Limit HTTP Request MethodsCIS Apache Tomcat 8 L1 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT