Item Search

NameAudit NamePluginCategory
1.1.3 (L1) Ensure that between two and four global admins are designatedCIS Microsoft 365 Foundations v6.0.1 L1 E3microsoft_azure

ACCESS CONTROL

1.1.3 (L1) Ensure that between two and four global admins are designatedCIS Microsoft 365 Foundations v6.0.1 L1 E5microsoft_azure

ACCESS CONTROL

1.4 Ensure that the Forged Transmits policy is set to rejectCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

1.5 Ensure that VDS Netflow traffic is only being sent to authorized collector IP AddressesCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
2.2 Configure the ESXi host firewall to restrict access to services running on the hostCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

2.2.27 (L1) Ensure 'Enable computer and user accounts to be trusted for delegation' is set to 'Administrators' (DC only)CIS Microsoft Windows Server 2008 R2 Domain Controller Level 1 v3.3.1Windows

ACCESS CONTROL

2.2.27 (L1) Ensure 'Enable computer and user accounts to be trusted for delegation' is set to 'No One' (MS only)CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

2.2.27 (L1) Ensure 'Force shutdown from a remote system' is set to 'Administrators'CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DCWindows

ACCESS CONTROL

2.2.28 (L1) Ensure 'Force shutdown from a remote system' is set to 'Administrators'CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

2.2.29 (L1) Ensure 'Force shutdown from a remote system' is set to 'Administrators'CIS Windows Server 2012 DC L1 v3.0.0Windows

ACCESS CONTROL

2.2.29 (L1) Ensure 'Force shutdown from a remote system' is set to 'Administrators'CIS Windows Server 2012 MS L1 v3.0.0Windows

ACCESS CONTROL

2.4 Do not use default self-signed certificates for ESXi communicationCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
2.6 Ensure proper SNMP configuration- 'community name public does not exist'CIS VMware ESXi 5.1 v1.0.1 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

2.8 When adding ESXi hosts to Active Directory use the vSphere Authentication Proxy to protect passwordsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
4.2 Ensure Example or Test Databases are Not Installed on Production ServersCIS Oracle MySQL Community Server 8.4 v1.1.0 L1 MySQL RDBMS MySQLDBMySQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure Example or Test Databases are Not Installed on Production ServersCIS Oracle MySQL Enterprise Edition 8.4 v1.1.0 L1 MySQL RDBMS MySQLDBMySQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

4.2 Ensure the vpxuser account's password is automatically changed every 10 or fewer daysCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

5.1.4 Ensure an Inventory of Administrator accounts is established and maintainedCIS IBM AIX 7 v1.1.0 L1Unix

ACCESS CONTROL

5.4 Ensure 'SUPER' is Not Granted to Non-Administrative UsersCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

ACCESS CONTROL

5.5 Remove keys from SSH authorized_keys fileCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
5.6 Set a timeout to automatically terminate idle ESXi Shell and SSH sessionsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

6.1 Enable bidirectional CHAP authentication for iSCSI trafficCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

7.1.2 Ensure that the MAC Address Change policy is set to rejectCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.1.6 Verify that the autoexpand option for VDS dvPortgroups is disabledCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
7.2.1 Ensure that port groups are not configured to the value of the native VLANCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
7.3.1 Ensure that the vSwitch Forged Transmits policy is set to rejectCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

8.1.2 Limit informational messages from the VM to the VMX fileCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

AUDIT AND ACCOUNTABILITY

8.1.3 Limit sharing of console connectionsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

8.2.1 Disconnect unauthorized devices - Floppy DevicesCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

MEDIA PROTECTION

8.3.1 Disable unnecessary or superfluous functions inside VMsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
8.3.3 Use secure protocols for virtual serial port accessCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
8.4.9 Disable Unity ActiveCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.10 Disable Unity Window ContentsCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.13 Disable Drag and Drop Version SetCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.14 Disable Shell ActionCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

CONFIGURATION MANAGEMENT

8.4.28 Disable VM Console Paste operationsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

8.5.1 Prevent virtual machines from taking over resources - Num CPU SharesCIS VMware ESXi 5.1 v1.0.1 Level 2VMware

SYSTEM AND COMMUNICATIONS PROTECTION

8.6.1 Avoid using nonpersistent disksCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

AUDIT AND ACCOUNTABILITY

10.2 Allowlist Approved Servers Belonging to a MySQL InnoDB ClusterCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL, MEDIA PROTECTION

10.2 Allowlist Approved Servers Belonging to a MySQL InnoDB ClusterCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L2 MySQL RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL, MEDIA PROTECTION

GOOG-13-707200 - Google Android 13 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.AirWatch - DISA Google Android 13 BYOAD v1r3MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-14-007200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.AirWatch - DISA Google Android 14 COPE STIG v2r3MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-14-707200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MobileIron - DISA Google Android 14 BYOAD v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-15-007200 - Google Android 15 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MobileIron - DISA Google Android 15 COBO STIG v1r3MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-16-007200 - Google Android 16 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.AirWatch - DISA Google Android 16 COBO STIG v1r1MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-16-007200 - Google Android 16 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.AirWatch - DISA Google Android 16 COPE STIG v1r1MDM

IDENTIFICATION AND AUTHENTICATION

KNOX-07-003300 - The Samsung must be configured to disable authentication mechanisms providing user access to protected data - PasswordMobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

MSFT-11-002300 - Microsoft Android 11 must be configured to disable trust agents. Note: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation - NA for specific biometric authentication factors included in the products Common Criteria evaluation.AirWatch - DISA Microsoft Android 11 COPE v1r2MDM

CONFIGURATION MANAGEMENT

MYS8-00-007500 - The MySQL Database Server 8.0 and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

SYSTEM AND INFORMATION INTEGRITY

ZEBR-10-002300 - Zebra Android 10 must be configured to disable trust agents - NA for specific biometric authentication factors included in the products Common Criteria evaluation.MobileIron - DISA Zebra Android 10 COBO v1r2MDM

CONFIGURATION MANAGEMENT