Item Search

NameAudit NamePluginCategory
1.1 Set 'Maximum send size - connector level' to '10240'CIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.6 Set 'Enable Sender reputation' to 'True' - OpenProxyDetectionEnabledCIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

1.7 Set 'Maximum number of recipients - organization level' to '5000'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.9 Set 'Configure login authentication for POP3' to 'SecureLogin'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

1.10 Set receive connector 'Configure Protocol logging' to 'Verbose'CIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

AUDIT AND ACCOUNTABILITY

1.11 Set send connector 'Configure Protocol logging' to 'Verbose'CIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

AUDIT AND ACCOUNTABILITY

1.12 Set 'External send connector authentication: Domain Security' to 'True'CIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.15 Set 'Configure login authentication for IMAP4' to 'SecureLogin'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

1.16 Set 'Turn on Connectivity logging' to 'True'CIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

AUDIT AND ACCOUNTABILITY

1.17 Set 'Maximum send size - organization level' to '10240'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Set 'Mailbox quotas: Prohibit send and receive at' to '2411520'CIS Microsoft Exchange Server 2013 Mailbox v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.3.6.2 (L1) Ensure 'Disable UI extending from documents and templates' is set to 'Enabled'CIS Microsoft Intune for Office v1.1.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.3.27.5 Ensure 'Allow Basic Authentication prompts from network proxies' is set to 'Disabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

CONFIGURATION MANAGEMENT

2.4 Set 'Keep deleted mailboxes for the specified number of days' to '30'CIS Microsoft Exchange Server 2013 Mailbox v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.5 Set 'Do not permanently delete items until the database has been backed up' to 'True'CIS Microsoft Exchange Server 2013 Mailbox v1.1.0Windows

CONTINGENCY PLANNING

2.6 Set 'Allow simple passwords' to 'False'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

2.7 Set 'Enforce Password History' to '4' or greaterCIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

2.9 Set 'Minimum password length' to '4' or greaterCIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

2.10 Set 'Configure startup mode' to 'TLS'CIS Microsoft Exchange Server 2013 UM v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.11 Set 'Refresh interval' to '1'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

ACCESS CONTROL

2.15 Set 'Allow unmanaged devices' to 'False'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

ACCESS CONTROL

2.16 Ensure 'Access Approval' is 'Enabled'CIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

2.16 Set 'Require encryption on device' to 'True'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

ACCESS CONTROL

3.1 Set cmdlets 'Turn on Administrator Audit Logging' to 'True'CIS Microsoft Exchange Server 2013 UM v1.1.0Windows

AUDIT AND ACCOUNTABILITY

3.4 Set 'Turn on Administrator Audit Logging' to 'True'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

AUDIT AND ACCOUNTABILITY

3.5 Set 'Enable automatic replies to remote domains' to 'False'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

CONFIGURATION MANAGEMENT

3.6 Set 'Allow basic authentication' to 'False'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

3.7 Set 'Enable non-delivery reports to remote domains' to 'False'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

CONFIGURATION MANAGEMENT

3.9 Set 'Enable automatic forwards to remote domains' to 'False'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

CONFIGURATION MANAGEMENT

3.10 Set 'Enable S/MIME for OWA 2010' to 'True'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.11 Set mailbox 'Turn on Administrator Audit Logging' to 'True'CIS Microsoft Exchange Server 2013 UM v1.1.0Windows

AUDIT AND ACCOUNTABILITY

5.018 - Windows Messenger (MSN Messenger, .NET messenger) is run at system startup.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

AIOS-14-011000 - Apple iOS/iPadOS must implement the management setting: disable paired Apple Watch.AirWatch - DISA Apple iOS/iPadOS 14 v1r3MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Disable additional security checks on VBA library references that may refer to unsafe locations on the local machineMSCT Microsoft 365 Apps for Enterprise 2206 v1.0.0Windows

CONFIGURATION MANAGEMENT

FNFG-FW-000005 - The FortiGate firewall must use filters that use packet headers and packet attributes, including source and destination IP addresses and ports.DISA Fortigate Firewall STIG v1r4FortiGate

ACCESS CONTROL

FNFG-FW-000015 - The FortiGate firewall must use organization-defined filtering rules that apply to the monitoring of remote access traffic for the traffic from the VPN access points.DISA Fortigate Firewall STIG v1r4FortiGate

ACCESS CONTROL

FNFG-FW-000020 - The FortiGate firewall must generate traffic log entries containing information to establish what type of events occurred.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000030 - The FortiGate firewall must generate traffic log entries containing information to establish the network location where the events occurred.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000035 - The FortiGate firewall must generate traffic log entries containing information to establish the source of the events, such as the source IP address at a minimum.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000040 - The FortiGate firewall must generate traffic log entries containing information to establish the outcome of the events, such as, at a minimum, the success or failure of the application of the firewall rule.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000045 - In the event that communication with the central audit server is lost, the FortiGate firewall must continue to queue traffic log records locally.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000055 - The FortiGate firewall must protect the traffic log from unauthorized modification of local log records.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000060 - The FortiGate firewall must protect the traffic log from unauthorized deletion of local log files and log records.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000065 - The FortiGate firewall must disable or remove unnecessary network services and functions that are not used as part of its role in the architecture.DISA Fortigate Firewall STIG v1r4FortiGate

CONFIGURATION MANAGEMENT

FNFG-FW-000070 - The FortiGate firewall must block outbound traffic containing denial-of-service (DoS) attacks to protect against the use of internal information systems to launch any DoS attacks against other networks or endpoints.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000085 - The FortiGate firewall must filter traffic destined to the internal enclave in accordance with the specific traffic that is approved and registered in the Ports, Protocols, and Services Management (PPSM) Category Assurance List (CAL), Vulnerability Assessments (VAs) for that the enclave.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000100 - The FortiGate firewall must send traffic log entries to a central audit server for management and configuration of the traffic log entries.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000125 - When employed as a premise firewall, FortiGate must block all outbound management traffic.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000135 - The FortiGate firewall must be configured to inspect all inbound and outbound traffic at the application layer.DISA Fortigate Firewall STIG v1r4FortiGate

CONFIGURATION MANAGEMENT

FNFG-FW-000160 - The FortiGate firewall must generate traffic log records when traffic is denied, restricted, or discarded.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY