Item Search

NameAudit NamePluginCategory
1.1.4.4.2 Enable listening ports range is set as appropriate for organizationCIS Zoom L2 v1.0.0Zoom

SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Ensure 'Protect RE' Firewall Filter is set for inbound traffic to the Routing EngineCIS Juniper OS Benchmark v2.1.0 L1Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Ensure firewall filter is set for inbound traffic to the Routing EngineCIS Juniper OS Benchmark v2.0.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Ensure RE firewall filter contains explicit term for SSH (when SSH is used)CIS Juniper OS Benchmark v2.0.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

2.3 Ensure RE firewall filter includes explicit term for SNMP (when SNMP is used)CIS Juniper OS Benchmark v2.0.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.18.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v3.0.1 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.18.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v3.0.1 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

5.1 Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration portsCIS Amazon Web Services Foundations L1 3.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2 Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration portsCIS Amazon Web Services Foundations L1 1.4.0amazon_aws
5.2 Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration portsCIS Amazon Web Services Foundations L1 1.3.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

5.2 Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration portsCIS Amazon Web Services Foundations L1 3.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.3 Ensure no security groups allow ingress from ::/0 to remote server administration portsCIS Amazon Web Services Foundations L1 3.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

6.18 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actionsCIS Palo Alto Firewall 9 Benchmark v1.0.0 L1Palo_Alto
6.18 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actionsCIS Palo Alto Firewall 10 v1.0.0 L1Palo_Alto
6.18 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actionsCIS Palo Alto Firewall 9 v1.0.1 L1Palo_Alto
7.1 Ensure the vSwitch Forged Transmits policy is set to rejectCIS VMware ESXi 6.5 v1.0.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.1 Ensure the vSwitch Forged Transmits policy is set to rejectCIS VMware ESXi 6.7 v1.1.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Ensure the vSwitch MAC Address Change policy is set to rejectCIS VMware ESXi 6.5 v1.0.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Ensure the vSwitch MAC Address Change policy is set to rejectCIS VMware ESXi 6.7 v1.1.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Ensure the vSwitch Promiscuous Mode policy is set to rejectCIS VMware ESXi 6.5 v1.0.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Ensure the vSwitch Promiscuous Mode policy is set to rejectCIS VMware ESXi 6.7 v1.1.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.4 Ensure port groups are not configured to the value of the native VLANCIS VMware ESXi 6.7 v1.1.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.5 Ensure port groups are not configured to VLAN values reserved by upstream physical switchesCIS VMware ESXi 7.0 v1.2.0 Level 1VMware
7.5 Ensure port groups are not configured to VLAN values reserved by upstream physical switchesCIS VMware ESXi 6.7 v1.1.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

7.8 Ensure port-level configuration overrides are disabled.CIS VMware ESXi 7.0 v1.2.0 Level 1VMware
7.8 Ensure port-level configuration overrides are disabled.CIS VMware ESXi 6.7 v1.1.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.3 (L1) Ensure secure protocols are used for virtual serial port accessCIS VMware ESXi 7.0 v1.4.0 L1VMware

CONFIGURATION MANAGEMENT, MAINTENANCE

8.3.3 Ensure secure protocols are used for virtual serial port accessCIS VMware ESXi 6.5 v1.0.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.3 Ensure secure protocols are used for virtual serial port accessCIS VMware ESXi 6.7 v1.1.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.3 Ensure secure protocols are used for virtual serial port accessCIS VMware ESXi 6.7 v1.3.0 Level 1VMware

CONFIGURATION MANAGEMENT, MAINTENANCE

8.4.1 Ensure access to VMs through the dvfilter network APIs is configured correctlyCIS VMware ESXi 6.5 v1.0.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.5.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)CIS Windows Server 2012 R2 MS L2 v2.5.0Windows

ACCESS CONTROL

18.5.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only) - EnabledCIS Microsoft Windows Server 2019 STIG MS L2 v1.0.1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.1 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v2.0.0 L1 + BL + NGWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.1 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v2.0.0 L1 + BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.1 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v2.0.0 L1 + NGWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v3.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v3.0.0 L1 + NGWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v3.0.0 L1 + BL + NGWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v3.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v3.0.0 L1 + BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v3.0.0 L1 + BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L2) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)CIS Microsoft Windows Server 2019 v3.0.0 L2 Member ServerWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L2) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)CIS Microsoft Windows Server 2016 v3.0.0 L2 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 (L2) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)CIS Microsoft Windows Server 2022 v3.0.0 L2 Member ServerWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v2.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)CIS Windows Server 2012 MS L2 v3.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.6.21.2 Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' (MS only)CIS Windows Server 2012 R2 MS L2 v3.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

CIS Control 12 (12.4(a)) Deny Communications Over Unauthorized PortsCAS Implementation Group 1 Audit FileUnix

SYSTEM AND COMMUNICATIONS PROTECTION

CIS Control 12 (12.4(b)) Deny Communications Over Unauthorized PortsCAS Implementation Group 1 Audit FileUnix

SYSTEM AND COMMUNICATIONS PROTECTION