Item Search

NameAudit NamePluginCategory
1.1 Ensure a separate user and group exist for Cassandra - groupCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

1.1 Ensure a separate user and group exist for Cassandra - groupCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

ACCESS CONTROL

1.1 Ensure a separate user and group exist for Cassandra - passwdCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

1.2 Ensure the latest version of Java is installedCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

SYSTEM AND SERVICES ACQUISITION

1.2 Ensure the latest version of Java is installedCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

SYSTEM AND SERVICES ACQUISITION

1.3 Ensure the latest version of Python is installedCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

SYSTEM AND SERVICES ACQUISITION

1.4 Ensure latest version of Cassandra is installedCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

SYSTEM AND SERVICES ACQUISITION

1.6 Ensure clocks are synchronized on all nodesCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

AUDIT AND ACCOUNTABILITY

2.1 Ensure that authentication is enabled for Cassandra databasesCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

2.2 Ensure that authorization is enabled for Cassandra databasesCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

ACCESS CONTROL

2.2.4 Set IP address for 'logging host'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY

2.4 Configure TCP Wrappers - Allow localhost.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Disable RPC Encryption KeyCIS Oracle Solaris 11.4 L1 v1.1.0Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Do Not Reuse UsernamesCIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.4 Do Not Reuse UsernamesCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.4 Do Not Reuse UsernamesCIS MySQL 5.7 Community Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.4 Do not use insecure registriesCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

SYSTEM AND INFORMATION INTEGRITY

2.4 Password Security - 'security.passwd.firstlogin.enable = on'TNS NetApp Data ONTAP 7GNetApp

IDENTIFICATION AND AUTHENTICATION

2.4 Set Update Interval Time ChecksCIS Mozilla Firefox 38 ESR Windows L1 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.4 Set Update Wait Time PromptCIS Mozilla Firefox 102 ESR Linux L1 v1.0.0Unix

RISK ASSESSMENT

2.8 Do not bind Docker to another IP/Port or a Unix socketCIS Docker 1.6 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.2 Ensure that the default password changed for the cassandra roleCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

3.2 Ensure that the default password changed for the cassandra roleCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

ACCESS CONTROL

3.4 Ensure that Cassandra is run using a non-privileged, dedicated service accountCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

ACCESS CONTROL

3.4 Ensure that Cassandra is run using a non-privileged, dedicated service accountCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

3.5 Ensure that Cassandra only listens for network connections on authorized interfacesCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.5 Ensure that Cassandra only listens for network connections on authorized interfacesCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.11 Ensure Group Write Access for the Apache Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

4.1 Ensure that logging is enabled. - logback.xmlCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1 Ensure that logging is enabled. - logback.xmlCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1 Ensure that logging is enabled. - nodetool getlogginglevelsCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1 Ensure that logging is enabled. - nodetool getlogginglevelsCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

AUDIT AND ACCOUNTABILITY

5.1 Inter-node EncryptionCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2 Client EncryptionCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.4 Ensure Log Storage and Rotation Is Configured Correctly - '/etc/logrotate.conf rotate > 13'CIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

6.4 Ensure Log Storage and Rotation Is Configured Correctly - '/etc/logrotate.conf rotate log files = weekly'CIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

DISA_STIG_Microsoft_Project_2016_v1r1.audit for Microsoft Project 2016, from DISA STIG Microsoft Project 2016 v1r1DISA STIG Microsoft Project 2016 v1r1Windows
DISA_STIG_Splunk_Enterprise_7.x_for_Windows_REST_API_v3r2.audit from DISA Splunk Enterprise 7.x for Windows v3r2 STIGDISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk
DISA_STIG_Splunk_Enterprise_8.x_for_Linux_REST_API_v2r3.audit from DISA Splunk Enterprise 8.x for Linux v2r3 STIGDISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk
DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'LSNRCTL Security'DISA STIG Oracle 11 Installation v9r1 LinuxUnix
DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'No listeners are running'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'No listeners are running'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

F5BI-DM-000013 - The BIG-IP appliance must provide automated support for account management functions.DISA F5 BIG-IP Device Management STIG v2r4F5

ACCESS CONTROL, CONFIGURATION MANAGEMENT

O112-BP-022700 - The Oracle Listener must be configured to require administration authentication.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-BP-022700 - The Oracle Listener must be configured to require administration authentication.DISA STIG Oracle 11.2g v2r5 LinuxUnix

CONFIGURATION MANAGEMENT

VCFL-67-000006 - vSphere Client must be configured to enable SSL/TLS.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

VCLD-67-000027 - VAMI must protect against or limit the effects of HTTP types of denial-of-service (DoS) attacks.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCLD-80-000060 - The vCenter VAMI service must restrict the ability of users to launch denial-of-service (DoS) attacks against other information systems or networks.DISA VMware vSphere 8.0 vCenter Appliance Management Interface VAMI STIG v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000042 - IPSec Exemptions must be limited.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN25-00-000390 - Windows Server 2025 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT