Item Search

NameAudit NamePluginCategory
1.3 Verify no unauthorized kernel modules are loaded on the hostCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
2.1 Configure NTP time synchronizationCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

AUDIT AND ACCOUNTABILITY

2.2 Configure the ESXi host firewall to restrict access to services running on the hostCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.6 Community Database L1 v2.0.0MySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.6 Enterprise Linux OS L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.7 Community Linux OS L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.10 Use Dual Passwords to Enable Higher Frequency Password RotationCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

IDENTIFICATION AND AUTHENTICATION

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

ACCESS CONTROL

2.12 Ensure AES Encryption Mode for AES_ENCRYPT/AES_DECRYPT is Configured CorrectlyCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

SYSTEM AND SERVICES ACQUISITION

2.16 Require Client-Side Certificates (X.509)CIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Configure a centralized location to collect ESXi host core dumpsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
3.2 Configure Host Profiles to monitor and alert on configuration changesCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
3.7 Ensure SSL Key Files Have Appropriate PermissionsCIS MySQL 8.0 Community Linux OS L1 v1.1.0Unix

ACCESS CONTROL, MEDIA PROTECTION

3.9 Ensure 'audit_log_file' Has Appropriate PermissionsCIS MySQL 5.7 Enterprise Linux OS L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.1 Ensure Prelogin 'Login Banner' is set - EnabledCIS F5 Networks v1.0.0 L1F5

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.1 Ensure that logging is enabled. - nodetool getlogginglevelsCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1 Ensure that logging is enabled. - nodetool getlogginglevelsCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1 Review Organization's Policies against DB2 RCAC PoliciesCIS IBM DB2 v10 v1.1.0 Linux OS Level 2Unix
4.1 Review Organization's Policies against DB2 RCAC PoliciesCIS IBM DB2 v10 v1.1.0 Windows OS Level 2Windows
4.3 Enable Auditing of File Metadata Modification Events - AUE_FACLSET : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.3 Enable Auditing of File Metadata Modification Events - AUE_FCHMOD : cisCIS Solaris 11.1 L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.3 Establish a password policy for password complexityCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

4.4 Use Active Directory for local user authentication - Enabled = 'true'CIS VMware ESXi 5.1 v1.0.1 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

4.5 Verify Active Directory group membership for the 'ESX Admins' groupCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

4.9 Ensure 'sql_mode' Contains 'STRICT_ALL_TABLES'CIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

5.1 Ensure all resources are correctly taggedCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws
5.1 Ensure that system activity is auditedCIS MongoDB 3.2 L1 Windows Audit v1.0.0Windows

AUDIT AND ACCOUNTABILITY

5.1 Ensure that system activity is auditedCIS MongoDB 3.6 L1 Unix Audit v1.1.0Unix

AUDIT AND ACCOUNTABILITY

5.1 Ensure that system activity is auditedCIS MongoDB 7 v1.1.0 L1 MongoDBUnix

AUDIT AND ACCOUNTABILITY

5.1 Ensure that system activity is auditedCIS MongoDB 7 v1.1.0 L1 MongoDBWindows

AUDIT AND ACCOUNTABILITY

5.1 Ensure that system activity is auditedCIS MongoDB 6 v1.2.0 L1 MongoDBUnix

AUDIT AND ACCOUNTABILITY

5.4 Enable lockdown mode to restrict remote accessCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
5.5 Remove keys from SSH authorized_keys fileCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
6.2 Ensure uniqueness of CHAP authentication secretsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
6.8 Disable Host-based Authentication for Login-based Services - rlogin auth sufficient pam_rhosts_auth.so.1CIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.8 Disable Host-based Authentication for Login-based Services - rlogin auth sufficient pam_rhosts_auth.so.1CIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

7.3.1 Ensure that the vSwitch Forged Transmits policy is set to rejectCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.1 Disable unnecessary or superfluous functions inside VMsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
8.4.2 Control VMsafe Agent AddressCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND INFORMATION INTEGRITY

8.4.3 Control VMsafe Agent PortCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND INFORMATION INTEGRITY

8.4.6 Disable BIOS BBSCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.9 Disable Unity ActiveCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.11 Disable Unity Push UpdateCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.16 Disable Trash Folder StateCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.18 Disable UnityCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.22 Disable Guest Host Interaction Launch MenuCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.5.1 Prevent virtual machines from taking over resources - Num CPU SharesCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

SYSTEM AND COMMUNICATIONS PROTECTION

10.1 Ensure All Group Replication Traffic is SecuredCIS Oracle MySQL Enterprise Edition 8.0 v1.4.0 L1 DatabaseMySQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

ESXi : config-snmp - 'snmp.receiver.X.enabled'VMWare vSphere 5.X Hardening GuideVMware

CONFIGURATION MANAGEMENT

HONW-09-002300 - The Honeywell Mobility Edge Android Pie device must be configured to disable trust agents.AirWatch - DISA Honeywell Android 9.x COBO v1r2MDM

CONFIGURATION MANAGEMENT