Item Search

NameAudit NamePluginCategory
1.5 Ensure 'unique application pools' is set for sitesCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL

2.1 Ensure 'global authorization rule' is set to restrict accessCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, MEDIA PROTECTION

2.2 Ensure access to sensitive site features is restricted to authenticated principals onlyCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL

2.2.29 Configure 'Log on as a service'CIS Windows 7 Workstation Level 2 v3.2.0Windows

ACCESS CONTROL

2.3 Ensure 'forms authentication' require SSL - ApplicationsCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3 Ensure 'forms authentication' require SSL - DefaultCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.5 Ensure 'cookie protection mode' is configured for forms authentication - ApplicationsCIS IIS 10 v1.2.1 Level 1Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.5 Ensure 'cookie protection mode' is configured for forms authentication - DefaultCIS IIS 10 v1.2.1 Level 1Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.6 Ensure transport layer security for 'basic authentication' is configuredCIS IIS 8.0 v1.5.1 Level 1Windows

IDENTIFICATION AND AUTHENTICATION

3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotelyCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND INFORMATION INTEGRITY

3.5 Ensure ASP.NET stack tracing is not enabled - ApplicationsCIS IIS 10 v1.2.1 Level 2Windows

SYSTEM AND SERVICES ACQUISITION

3.7 Ensure 'cookies' are set with HttpOnly attributeCIS IIS 8.0 v1.5.1 Level 1Windows

ACCESS CONTROL

3.7 Ensure 'cookies' are set with HttpOnly attribute - ApplicationsCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND SERVICES ACQUISITION

3.7 Ensure 'cookies' are set with HttpOnly attribute - DefaultCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND SERVICES ACQUISITION

3.8 Ensure 'MachineKey validation method - .Net 3.5' is configuredCIS IIS 8.0 v1.5.1 Level 2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.8 Ensure 'MachineKey validation method - .Net 3.5' is configured - ApplicationsCIS IIS 10 v1.2.1 Level 2Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.9 Ensure 'MachineKey validation method - .Net 4.5' is configuredCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.9 Ensure 'MachineKey validation method - .Net 4.5' is configured - ApplicationsCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.10 Ensure global .NET trust level is configuredCIS IIS 8.0 v1.5.1 Level 1Windows

ACCESS CONTROL

3.10 Ensure global .NET trust level is configured - DefaultCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, MEDIA PROTECTION

3.11 Ensure X-Powered-By Header is removed - ApplicationsCIS IIS 10 v1.2.1 Level 2Windows

CONFIGURATION MANAGEMENT

3.11 Ensure X-Powered-By Header is removed - DefaultCIS IIS 10 v1.2.1 Level 2Windows

CONFIGURATION MANAGEMENT

4.9 Ensure 'notListedIsapisAllowed' is set to falseCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.9 Ensure 'notListedIsapisAllowed' is set to falseCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND SERVICES ACQUISITION

6.1 Ensure FTP requests are encrypted - Control Channel SitesCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.2 Ensure FTP Logon attempt restrictions is enabled - Deny IP AddressCIS IIS 8.0 v1.5.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

7.1 Ensure HSTS Header is setCIS IIS 8.0 v1.5.1 Level 2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Ensure SSLv3 is disabledCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

7.9 Ensure RC2 Cipher Suites is disabledCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

7.10 Ensure RC4 Cipher Suites is disabledCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

7.12 Ensure TLS Cipher Suite ordering is ConfiguredCIS IIS 10 v1.2.1 Level 2Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.13 Ensure AES 256/256 Cipher Suite is enabledCIS IIS 8.0 v1.5.1 Level 1Windows
7.13 Ensure AES 256/256 Cipher Suite is enabled - EnabledCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

CIS_Apache_Tomcat_7_L1_v1.1.0_Middleware.audit from CIS Apach Tomcat 7 BenchmarkCIS Apache Tomcat 7 L1 v1.1.0 MiddlewareUnix
CIS_Apache_Tomcat_7_L2_v1.1.0_Middleware.audit from CIS Apach Tomcat 7 BenchmarkCIS Apache Tomcat 7 L2 v1.1.0 MiddlewareUnix
CIS_Apache_Tomcat_9_L1_v1.2.0_Middleware.audit from CIS Apache Tomcat 9 BenchmarkCIS Apache Tomcat 9 L1 v1.2.0 MiddlewareUnix
CIS_Debian_Family_Linux_v1.0.0_L1_Workstation.audit from CIS Debian Family Linux BenchmarkCIS Debian Family Workstation L1 v1.0.0Unix
CIS_IBM_DB2_10_v1.1.0_Level_1_OS_Linux.audit from CIS DB2 10.x LinuxCIS IBM DB2 v10 v1.1.0 Linux OS Level 1Unix
CIS_IBM_DB2_10_v1.1.0_Level_2_OS_Linux.audit from CIS DB2 10.x LinuxCIS IBM DB2 v10 v1.1.0 Linux OS Level 2Unix
CIS_Kubernetes_v1.1.0_Level_2.audit from CIS Kubernetes Benchmark v1.1.0CIS Kubernetes 1.7.0 Benchmark v1.1.0 L2Unix
CIS_Kubernetes_v1.3.0_Level_2.audit from CIS Kubernetes Benchmark v1.3.0CIS Kubernetes 1.11 Benchmark v1.3.0 L2Unix
CIS_MongoDB_3.4_Benchmark_Level_2_OS_Unix_v1.0.0.audit from CIS MongoDB 3.4 BenchmarkCIS MongoDB 3.4 L2 Unix Audit v1.0.0Unix
CIS_MongoDB_3.6_Benchmark_Level_1_DB_v1.1.0.audit from CIS MongoDB 3.6 BenchmarkCIS MongoDB 3.6 Database Audit L1 v1.1.0MongoDB
CIS_MongoDB_3.6_Benchmark_Level_1_OS_Unix_v1.1.0.audit from CIS MongoDB 3.6 BenchmarkCIS MongoDB 3.6 L1 Unix Audit v1.1.0Unix
CIS_MongoDB_4_Benchmark_Level_1_OS_Linux_v1.0.0.audit from CIS MongoDB 4 BenchmarkCIS MongoDB 4 L1 OS Linux v1.0.0Unix
CIS_MongoDB_4_Benchmark_Level_2_OS_Windows_v1.0.0.audit from CIS MongoDB 4 BenchmarkCIS MongoDB 4 L2 OS Windows v1.0.0Windows
CIS_MongoDB_6_v1.2.0_L1_OS_Windows.audit from CIS MongoDB 6 Benchmark v1.2.0CIS MongoDB 6 v1.2.0 L1 MongoDBWindows
CIS_MongoDB_6_v1.2.0_L2_OS_Linux.audit from CIS MongoDB 6 Benchmark v1.2.0CIS MongoDB 6 v1.2.0 L2 MongoDBUnix
CIS_MongoDB_7_v1.1.0_L1_OS_Linux.audit from CIS MongoDB 7 Benchmark v1.1.0CIS MongoDB 7 v1.1.0 L1 MongoDBUnix
CIS_MongoDB_7_v1.1.0_L2_OS_Windows.audit from CIS MongoDB 7 Benchmark v1.1.0CIS MongoDB 7 v1.1.0 L2 MongoDBWindows