Item Search

NameAudit NamePluginCategory
1.3 Ensure that Snowflake password is unset for SSO usersCIS Snowflake Foundations v1.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION

1.6 Ensure that service accounts use key pair authenticationCIS Snowflake Foundations v1.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION

2.3.6.5 (L1) Ensure 'Domain member: Maximum machine account password age' is set to '30 or fewer days, but not 0'CIS Microsoft Windows Server 2022 v4.0.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

2.3.6.5 (L1) Ensure 'Domain member: Maximum machine account password age' is set to '30 or fewer days, but not 0'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

IDENTIFICATION AND AUTHENTICATION

2.3.6.5 Ensure 'Domain member: Maximum machine account password age' is set to '30 or fewer days, but not 0'CIS Microsoft Windows Server 2016 STIG v3.0.0 L1 Domain ControllerWindows

IDENTIFICATION AND AUTHENTICATION

2.3.7.6 (L2) Ensure 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is set to '4 or fewer logon(s)' (MS only)CIS Microsoft Windows Server 2022 v4.0.0 L2 MSWindows

IDENTIFICATION AND AUTHENTICATION

2.3.7.7 (L1) Ensure 'Interactive logon: Prompt user to change password before expiration' is set to 'between 5 and 14 days'CIS Microsoft Windows Server 2022 v4.0.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

2.3.7.7 (L2) Ensure 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is set to '4 or fewer logon(s)'CIS Microsoft Windows 10 Enterprise v4.0.0 L2 BLWindows

IDENTIFICATION AND AUTHENTICATION

2.6 Ensure Password Complexity is Configured - validate_password_mixed_case_countCIS MySQL 5.6 Community Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.6 Ensure Password Complexity is Configured - validate_password_policyCIS MySQL 5.6 Community Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.6 Ensure Password Complexity is Configured - validate_password_policyCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.7 Ensure Password Complexity is Configured - validate_password_mixed_case_countCIS MySQL 5.7 Enterprise Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

3.2 Disable NTLM v1CIS Mozilla Firefox 102 ESR Linux L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

3.4 Require Authentication for Single-User ModeCIS Debian Linux 7 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

4.11.8.1 (L1) Ensure 'Do not display the password reveal button' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v4.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

4.11.8.1 (L1) Ensure 'Do not display the password reveal button' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v4.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

5.2.3.2 (L1) Ensure custom banned passwords lists are usedCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.3 Ensure Password Complexity is configuredCIS PostgreSQL 16 DB v1.0.0PostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

5.3.1.1 Ensure latest version of pam is installedCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.1.2 Ensure libpam-modules is installedCIS Debian Linux 12 v1.1.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.1.2 Ensure libpam-modules is installedCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.1.2 Ensure libpam-modules is installedCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.1.3 Ensure libpam-pwquality is installedCIS Debian Linux 12 v1.1.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.1.3 Ensure libpam-pwquality is installedCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.1.3 Ensure libpam-pwquality is installedCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.6 Ensure login keychain is locked when the computer sleepsCIS Apple macOS 10.12 L2 v1.2.0Unix

IDENTIFICATION AND AUTHENTICATION

5.6 Ensure Password Complexity is configuredCIS PostgreSQL 13 DB v1.2.0PostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

6.1 Setup Client-cert AuthenticationCIS Apache Tomcat 7 L2 v1.1.0 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

9.2.1 Set Password Creation Requirement Parameters Using pam_cracklib - libpam-cracklib packageCIS Debian Linux 7 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

18.9.25.7 (L1) Ensure 'Post-authentication actions: Grace period (hours)' is set to 'Enabled: 8 or fewer hours, but not 0'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BLWindows

IDENTIFICATION AND AUTHENTICATION

18.9.25.8 (L1) Ensure 'Post-authentication actions: Actions' is set to 'Enabled: Reset the password and logoff the managed account' or higherCIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

IDENTIFICATION AND AUTHENTICATION

18.9.39.1 (L1) Ensure 'Configure SAM change password RPC methods policy' is set to 'Enabled: Block all change password RPC methods'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

IDENTIFICATION AND AUTHENTICATION

18.10.15.1 (L1) Ensure 'Do not display the password reveal button' is set to 'Enabled'CIS Microsoft Windows Server 2022 v4.0.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

105.5 (L1) Ensure 'Post-authentication actions' is set to 'Reset the password and logoff the managed account' or higherCIS Microsoft Intune for Windows 10 v4.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

Allow Basic authentication for HTTPMSCT Edge v136 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Big Sur - Require Passwords Contain a Minimum of One Numeric CharacterNIST macOS Big Sur v1.4.0 - 800-53r4 LowUnix

IDENTIFICATION AND AUTHENTICATION

Big Sur - Require Passwords Contain a Minimum of One Special CharacterNIST macOS Big Sur v1.4.0 - 800-53r5 HighUnix

IDENTIFICATION AND AUTHENTICATION

Big Sur - Require Passwords Contain a Minimum of One Special CharacterNIST macOS Big Sur v1.4.0 - All ProfilesUnix

IDENTIFICATION AND AUTHENTICATION

Catalina - Require a Minimum Password Length of 15 CharactersNIST macOS Catalina v1.5.0 - 800-53r4 HighUnix

IDENTIFICATION AND AUTHENTICATION

Catalina - Require a Minimum Password Length of 15 CharactersNIST macOS Catalina v1.5.0 - 800-53r4 LowUnix

IDENTIFICATION AND AUTHENTICATION

Catalina - Require a Minimum Password Length of 15 CharactersNIST macOS Catalina v1.5.0 - All ProfilesUnix

IDENTIFICATION AND AUTHENTICATION

Catalina - Require Passwords Contain a Minimum of One Numeric CharacterNIST macOS Catalina v1.5.0 - 800-53r4 HighUnix

IDENTIFICATION AND AUTHENTICATION

Catalina - Require Passwords Contain a Minimum of One Numeric CharacterNIST macOS Catalina v1.5.0 - 800-53r5 ModerateUnix

IDENTIFICATION AND AUTHENTICATION

Catalina - Require Passwords Contain a Minimum of One Special CharacterNIST macOS Catalina v1.5.0 - 800-53r5 HighUnix

IDENTIFICATION AND AUTHENTICATION

Catalina - Restrict Maximum Password Lifetime to 60 DaysNIST macOS Catalina v1.5.0 - 800-53r4 LowUnix

IDENTIFICATION AND AUTHENTICATION

Network security: LAN Manager authentication levelMSCT Windows 11 v24H2 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: LDAP client signing requirementsMSCT Windows 11 v24H2 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: LDAP client signing requirementsMSCT Windows 11 v22H2 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Sign-in and lock last interactive user automatically after a restart - DisableAutomaticRestartSignOnMSCT Windows Server 2025 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Supported authentication schemesMSCT Edge v136 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION