Item Search

NameAudit NamePluginCategory
1.1.2 Ensure only trusted users are allowed to control Docker daemonCIS Docker v1.6.0 L1 Docker LinuxUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.7 Ensure that 'Number of days before users are asked to re-confirm their authentication information' is not set to '0'CIS Microsoft Azure Foundations v2.1.0 L1microsoft_azure

ACCESS CONTROL

2.2.10 Ensure 'SEC_MAX_FAILED_LOGIN_ATTEMPTS' Is '3' or LessCIS Oracle Server 19c DB Traditional Auditing v1.2.0OracleDB

ACCESS CONTROL

2.2.10 Ensure 'SEC_MAX_FAILED_LOGIN_ATTEMPTS' Is '3' or LessCIS Oracle Server 19c DB Unified Auditing v1.2.0OracleDB

ACCESS CONTROL

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.24 Benchmark v1.0.0 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.23 Benchmark v1.0.1 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes Benchmark v1.9.0 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.14 Ensure containers are restricted from acquiring new privilegesCIS Docker v1.6.0 L1 Docker LinuxUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

3.1 Ensure 'FAILED_LOGIN_ATTEMPTS' Is Less than or Equal to '5'CIS Oracle Server 19c DB Traditional Auditing v1.2.0OracleDB

ACCESS CONTROL

3.1.2 Service account token authentication should not be used for usersCIS Kubernetes Benchmark v1.9.0 L1 MasterUnix

ACCESS CONTROL

3.1.3 Bootstrap token authentication should not be used for usersCIS Kubernetes Benchmark v1.9.0 L1 MasterUnix

ACCESS CONTROL

3.2 Ensure 'PASSWORD_LOCK_TIME' Is Greater than or Equal to '1'CIS Oracle Server 19c DB Traditional Auditing v1.2.0OracleDB

ACCESS CONTROL

3.3 Ensure 'PASSWORD_LIFE_TIME' Is Less than or Equal to '90'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

3.3 Ensure 'PASSWORD_LIFE_TIME' Is Less than or Equal to '90'CIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

ACCESS CONTROL

3.8 Ensure 'SESSIONS_PER_USER' Is Less than or Equal to '10'CIS Oracle Server 19c DB Traditional Auditing v1.2.0OracleDB

ACCESS CONTROL

4.4.2.1.2 Ensure password failed attempts lockout is configuredCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

ACCESS CONTROL

4.4.2.1.3 Ensure password unlock time is configuredCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

ACCESS CONTROL

4.4.3.1.1 Ensure password failed attempts lockout is configuredCIS Red Hat EL8 Workstation L1 v3.0.0Unix

ACCESS CONTROL

4.4.3.1.2 Ensure password unlock time is configuredCIS Red Hat EL8 Workstation L1 v3.0.0Unix

ACCESS CONTROL

4.4.3.1.3 Ensure password failed attempts lockout includes root accountCIS AlmaLinux OS 8 Workstation L2 v3.0.0Unix

ACCESS CONTROL

4.4.3.1.3 Ensure password failed attempts lockout includes root accountCIS Rocky Linux 8 Server L2 v2.0.0Unix

ACCESS CONTROL

4.4.3.1.3 Ensure password failed attempts lockout includes root accountCIS Oracle Linux 8 Workstation L2 v3.0.0Unix

ACCESS CONTROL

4.4.3.1.3 Ensure password failed attempts lockout includes root accountCIS AlmaLinux OS 8 Server L2 v3.0.0Unix

ACCESS CONTROL

5.1.6.1 Ensure that collaboration invitations are sent to allowed domains onlyCIS Microsoft 365 Foundations E3 L2 v3.0.0microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.2.1 Ensure Password Account Lockout Threshold Is ConfiguredCIS Apple macOS 13.0 Ventura v2.0.0 L1Unix

ACCESS CONTROL

5.2.1 Ensure Password Account Lockout Threshold Is ConfiguredCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure system accounts are secured - non loginCIS Google Container-Optimized OS L2 Server v1.1.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.3.2.2 Ensure pam_faillock module is enabledCIS Debian Linux 11 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.3.2.2 Ensure pam_faillock module is enabledCIS Debian Linux 11 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.2.2 Ensure pam_faillock module is enabledCIS Debian Linux 12 v1.0.1 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Debian Linux 11 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Debian Linux 12 v1.0.1 L1 WorkstationUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Debian Linux 12 v1.0.1 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS Debian Linux 12 v1.0.1 L1 WorkstationUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS Debian Linux 11 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.3 Ensure password failed attempts lockout includes root accountCIS Ubuntu Linux 22.04 LTS v2.0.0 L2 ServerUnix

ACCESS CONTROL

5.3.3.1.3 Ensure password failed attempts lockout includes root accountCIS Debian Linux 12 v1.0.1 L2 WorkstationUnix

ACCESS CONTROL

5.5.2 Ensure lockout for failed password attempts is configured - <= 8.1 denyCIS CentOS Linux 8 Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.5.2 Ensure lockout for failed password attempts is configured - <= 8.1 unlock_timeCIS CentOS Linux 8 Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.5.2 Ensure lockout for failed password attempts is configured - >= 8.2 denyCIS CentOS Linux 8 Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.5.2 Ensure lockout for failed password attempts is configured - denyCIS Oracle Linux 9 Server L1 v1.0.0Unix

ACCESS CONTROL

5.5.2 Ensure lockout for failed password attempts is configured - unlock_timeCIS Oracle Linux 9 Server L1 v1.0.0Unix

ACCESS CONTROL

6.17 Set Retry Limit for Account LockoutCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL

7.1 Ensure authentication file permissions are set correctlyCIS MongoDB 3.6 L1 Windows Audit v1.1.0Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

7.1 Ensure authentication file permissions are set correctlyCIS MongoDB 3.6 L1 Unix Audit v1.1.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

8.1 Ensure that the Expiration Date is set for all Keys in RBAC Key VaultsCIS Microsoft Azure Foundations v2.1.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

8.3 Ensure that the Expiration Date is set for all Secrets in RBAC Key VaultsCIS Microsoft Azure Foundations v2.1.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

8.4 Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key VaultsCIS Microsoft Azure Foundations v2.1.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY