Item Search

NameAudit NamePluginCategory
1.5 Ensure that VDS Netflow traffic is only being sent to authorized collector IP AddressesCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
1.6 Restrict port-level configuration overrides on vDSCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
2.2 Dedicate the Machine Running MySQLCIS MySQL 5.6 Community Linux OS L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.7 Enterprise Linux OS L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Dedicate the Machine Running MySQLCIS MySQL 5.7 Enterprise Windows OS L1 v2.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Ensure 'Protect RE' Firewall Filter includes explicit terms for all Management ServicesCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.1 Ensure Binary and Relay Logs are EncryptedCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Do not use default self-signed certificates for ESXi communicationCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
2.9 Require Current Password for Password ResetCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

IDENTIFICATION AND AUTHENTICATION

2.9 Require Current Password for Password ResetCIS MySQL 8.0 Community Database L2 v1.1.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.9 Require Current Password for Password ResetCIS Oracle MySQL Enterprise Edition 8.0 v1.4.0 L2 DatabaseMySQLDB

IDENTIFICATION AND AUTHENTICATION

2.9 Require Current Password for Password ResetCIS Oracle MySQL Community Server 8.4 v1.0.0 L2 DatabaseMySQLDB

IDENTIFICATION AND AUTHENTICATION

2.10 Use Dual Passwords to Enable Higher Frequency Password RotationCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

IDENTIFICATION AND AUTHENTICATION

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

ACCESS CONTROL

3.4 Configure remote logging for ESXi hostsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

AUDIT AND ACCOUNTABILITY

3.6 Ensure Relational Database Service Instances have Auto Minor Version Upgrade EnabledCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND INFORMATION INTEGRITY

3.7 Ensure SSL Key Files Have Appropriate PermissionsCIS MySQL 8.0 Enterprise Linux OS L1 v1.4.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.1 Configure 'Automatically check for Internet Explorer updates'CIS IE 9 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

4.1 Ensure the Latest Security Patches are AppliedCIS MariaDB 10.6 on Linux L1 v1.1.0Unix

SYSTEM AND SERVICES ACQUISITION

4.1 Use TSIG Keys 256 Bits in LengthCIS BIND DNS v3.0.1 Authoritative Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

4.2 Enable Auditing of Incoming Network Connections - AUE_ACCEPT : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.2 Enable Auditing of Incoming Network Connections - AUE_CONNECT : cisCIS Solaris 11.1 L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.2 Enable Auditing of Incoming Network Connections - AUE_CONNECT : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.2 Enable Auditing of Incoming Network Connections - AUE_inetd_connect : cisCIS Solaris 11.1 L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.2 Enable Auditing of Incoming Network Connections - AUE_inetd_connect : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.2 Enable Auditing of Incoming Network Connections - AUE_SOCKACCEPT : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.2 Enable Auditing of Incoming Network Connections - AUE_SOCKCONNECT : cisCIS Solaris 11.1 L1 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.3 Enable Auditing of File Metadata Modification Events - AUE_FACLSET : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.3 Enable Auditing of File Metadata Modification Events - AUE_FCHOWN : cisCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.3 Enable Auditing of File Metadata Modification Events - AUE_FCHOWN : cisCIS Solaris 11 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.4 Use Active Directory for local user authentication - Review DomainCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

4.8 Ensure the 'secure_file_priv' is Configured CorrectlyCIS MySQL 8.0 Community Database L1 v1.1.0MySQLDB

ACCESS CONTROL, MEDIA PROTECTION

5.3 Disable SSHCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

6.6 Ensure ALL Events are AuditedCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

AUDIT AND ACCOUNTABILITY

6.7 Ensure That Cloud SQL Database Instances Are Configured With Automated BackupsCIS Google Cloud Platform v3.0.0 L1GCP

CONTINGENCY PLANNING

6.7 Set audit_log_strategy to SYNCHRONOUS or SEMISYNCRONOUSCIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

AUDIT AND ACCOUNTABILITY

7.1 Ensure default_authentication_plugin is Set to a Secure OptionCIS MySQL 5.7 Community Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.1.1 Disable VDS network healthcheck if not usedCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
7.1.3 Ensure that the Promiscuous Mode policy is set to rejectCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.1.5 Ensure that VDS Port Mirror traffic is only being sent to authorized collector ports or VLANsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
8.2.5 Disconnect unauthorized devices - USB DevicesCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

MEDIA PROTECTION

8.2.6 Prevent unauthorized removal, connection, and modification of devicesCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

8.4.1 Control access to VMs through the dvfilter network APIsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

8.4.25 Disable VM Console Copy operationsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

CONFIGURATION MANAGEMENT

9.3 Ensure 'master_info_repository' is Set to 'TABLE'CIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L2 MySQL RDBMSMySQLDB

CONFIGURATION MANAGEMENT

10.1 Ensure All Group Replication Traffic is SecuredCIS MySQL 8.0 Community Database L1 v1.1.0MySQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

CIS VMware ESXi 5.5 v1.2.0 Level 2CIS VMware ESXi 5.5 v1.2.0 Level 2VMware
MYS8-00-002500 - The MySQL Database Server 8.0 must generate audit records when unsuccessful attempts to add privileges/permissions occur.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

AUDIT AND ACCOUNTABILITY

MYS8-00-005200 - If passwords are used for authentication, the MySQL Database Server 8.0 must transmit only encrypted representations of passwords.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

IDENTIFICATION AND AUTHENTICATION

MYS8-00-009600 - The MySQL Database Server 8.0 must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

AUDIT AND ACCOUNTABILITY