Item Search

NameAudit NamePluginCategory
1.15 Ensure IAM policies that allow full "*:*" administrative privileges are not attachedCIS Amazon Web Services Foundations v5.0.0 L1amazon_aws

ACCESS CONTROL

2.1 Ensure IAM Policy for EC2 IAM Roles for Web tier is configuredCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

ACCESS CONTROL

2.1.1.4 Audit Security Keys Used With Apple AccountsCIS Apple macOS 15.0 Sequoia v1.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

2.6 Ensure AutoScaling Group Launch Configuration for App Tier is configured to use an App-Tier IAM RoleCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

ACCESS CONTROL

2.8 Ensure an IAM policy that allows admin privileges for all services used is created - Review Policy DocumentCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

ACCESS CONTROL

2.8 Protocol Access Controls - 'rsh.access has been configured'TNS NetApp Data ONTAP 7GNetApp

SYSTEM AND COMMUNICATIONS PROTECTION

2.8 Protocol Access Controls - 'telnet.access has been configured'TNS NetApp Data ONTAP 7GNetApp

ACCESS CONTROL

3.1.12 Ensure the correct messages are sent to the database clientCIS PostgreSQL 9.5 DB v1.1.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.14 Ensure the correct messages are written to the server logCIS PostgreSQL 14 DB v 1.2.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.14 Ensure the correct messages are written to the server logCIS PostgreSQL 15 DB v1.1.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.12 Ensure Group Write Access for the Document Root Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

3.12 Ensure Group Write Access for the Document Root Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.4 v2.2.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

3.12 Ensure Group Write Access for the Document Root Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

4.8 Ensure Billing Alerts are enabled for increments of X spendCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws
7.8 Extensible Firmware Interface (EFI) passwordCIS Apple OSX 10.11 El Capitan L2 v1.1.0Unix
8.11 (L2) VMware Tools must deactivate Service Discovery unless requiredCIS VMware ESXi 8.0 v1.2.0 L2VMware

CONFIGURATION MANAGEMENT

9.2 Check for Duplicate User NamesCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL

9.17 Check for Duplicate User NamesCIS Solaris 11.2 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

9.17 Check That Reserved UIDs Are Assigned to System AccountsCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

9.18 Check for Duplicate Group NamesCIS Solaris 11.2 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

9.18 Check for Duplicate Group NamesCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL, MEDIA PROTECTION

9.18 Check for Duplicate User NamesCIS Solaris 11 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

9.19 Check for Duplicate Group NamesCIS Solaris 11 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

9.19 Check for Duplicate Group NamesCIS Solaris 11.1 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

9.19 Check for Presence of User .netrc FilesCIS Oracle Solaris 11.4 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

9.19 Check for Presence of User .netrc FilesCIS Solaris 11.2 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

9.20 Check for Presence of User .forward FilesCIS Solaris 11.2 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

9.20 Check for Presence of User .forward FilesCIS Oracle Solaris 11.4 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

9.20 Check for Presence of User .netrc FilesCIS Solaris 11 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

9.20 Check for Presence of User .netrc FilesCIS Solaris 11.1 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

9.21 Check for Presence of User .forward FilesCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

CASA-VN-000360 - The Cisco ASA VPN gateway must be configured to renegotiate the IKE security association after 24 hours or less.DISA STIG Cisco ASA VPN v2r2Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-RT-000510 - The Cisco BGP router must be configured to reject inbound route advertisements from a customer edge (CE) router for prefixes that are not allocated to that customer.DISA STIG Cisco IOS-XR Router RTR v3r2Cisco

ACCESS CONTROL

DTBC-0030 - Incognito mode must be disabled.DISA STIG Google Chrome v2r9Windows

AUDIT AND ACCOUNTABILITY

EX16-ED-000310 - The Exchange Internet Receive connector connections count must be set to default.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r5Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000310 - The Exchange Internet Receive connector connections count must be set to default.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000131 - The Exchange Outbound Connection Limit per Domain Count must be controlled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-VN-000003 - The Juniper SRX Services Gateway VPN must renegotiate the IKE security association after 24 hours or less.DISA Juniper SRX Services Gateway VPN v3r1Juniper

ACCESS CONTROL

TNS_Best_Practices_Jetty_9_v1.0.0.auditTNS Best Practice Jetty 9 LinuxUnix
TNS_IBM_HTTP_Server_Best_Practice.auditTNS IBM HTTP Server Best PracticeWindows
TNS_IBM_HTTP_Server_Linux_Best_Practice.auditTNS IBM HTTP Server Best PracticeUnix
VCEM-70-000030 - ESX Agent Manager must set the secure flag for cookies.DISA STIG VMware vSphere 7.0 EAM Tomcat v1r2Unix

CONFIGURATION MANAGEMENT

VCLU-70-000031 - Lookup Service must set the secure flag for cookies.DISA STIG VMware vSphere 7.0 Lookup Service v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCPF-67-000030 - Performance Charts must set the secure flag for cookies.DISA STIG VMware vSphere 6.7 Perfcharts Tomcat v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCPF-70-000033 - Performance Charts must set the secure flag for cookies.DISA STIG VMware vSphere 7.0 Perfcharts Tomcat v1r1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCST-70-000030 - The Security Token Service must set the secure flag for cookies.DISA STIG VMware vSphere 7.0 STS Tomcat v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCUI-67-000030 - vSphere UI must set the secure flag for cookies.DISA STIG VMware vSphere 6.7 UI Tomcat v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCUI-70-000032 - vSphere UI must set the secure flag for cookies.DISA STIG VMware vSphere 7.0 vCA UI v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-03-000127 - Oracle WebLogic must adhere to the principles of least functionality by providing only essential capabilities.Oracle WebLogic Server 12c Linux v2r2Unix

CONFIGURATION MANAGEMENT

WBSP-AS-000970 - The WebSphere Application Server must disable JSP class reloading.DISA IBM WebSphere Traditional 9 Windows STIG v1r1Windows

CONFIGURATION MANAGEMENT