Item Search

NameAudit NamePluginCategory
1.1 Ensure Latest SQL Server Service Packs and Hotfixes are InstalledCIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

CONFIGURATION MANAGEMENT

1.98 (L2) Ensure 'Enable search suggestions' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

2.2.2 Ensure ldap client is not installedCIS SUSE Linux Enterprise 15 v2.0.1 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

2.3.9.5 Ensure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client' or higherCIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT

2.11 (L1) Ensure 'Allow download restrictions' is set to 'Enabled: Block malicious downloads'CIS Google Chrome L1 v3.0.0Windows

AUDIT AND ACCOUNTABILITY

2.17 Ensure 'clr strict security' Server Configuration Option is set to '1'CIS Microsoft SQL Server 2019 v1.5.0 L1 AWS RDSMS_SQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.2.1.4 Ensure journald is not configured to receive logs from a remote clientCIS Fedora 28 Family Linux Server L1 v2.0.0Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.1.2.1.4 Ensure journald is not configured to receive logs from a remote clientCIS CentOS Linux 7 v4.0.0 L1 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.1.2.1.4 Ensure journald is not configured to receive logs from a remote clientCIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.1.2.1.4 Ensure journald is not configured to receive logs from a remote clientCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.1.2.1.4 Ensure journald is not configured to receive logs from a remote clientCIS Red Hat EL8 Workstation L1 v3.0.0Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.21 Do not disable default seccomp profileCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.124 - Client computers required to authenticate for RPC communication.DISA Windows Vista STIG v6r41Windows

IDENTIFICATION AND AUTHENTICATION

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS SUSE Linux Enterprise 15 v2.0.1 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS AlmaLinux OS 9 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS Oracle Linux 9 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS Red Hat Enterprise Linux 9 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS Rocky Linux 9 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

CONFIGURATION MANAGEMENT

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS Oracle Linux 9 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS Red Hat Enterprise Linux 9 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

6.2.2.1.4 Ensure systemd-journal-remote service is not in useCIS Rocky Linux 9 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

8.14 (L1) VMware Tools must send VMware Tools logs to the system log serviceCIS VMware ESXi 8.0 v1.2.0 L1VMware

AUDIT AND ACCOUNTABILITY

Allow Basic authentication - Service - AllowBasicMSCT Windows 10 v2004 v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasicMSCT Windows 10 v20H2 v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasicMSCT Windows Server 1903 MS v1.19.9Windows

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasicMSCT Windows Server v1909 MS v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasicMSCT Windows 10 v21H2 v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasicMSCT Windows 10 v22H2 v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasicMSCT Windows Server v2004 MS v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasicMSCT MSCT Windows Server 2022 DC v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - Service - AllowBasicMSCT Windows Server v20H2 DC v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - WinRM ServiceMSCT Windows 10 1803 v1.0.0Windows

ACCESS CONTROL

Allow Basic authentication - WinRM ServiceMSCT Windows 10 1809 v1.0.0Windows

ACCESS CONTROL

DKER-EE-001810 - On Linux, a non-AUFS storage driver in the Docker Engine - Enterprise component of Docker Enterprise must be used.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DTAM059 - McAfee VirusScan On-Demand scan must be configured to record scanning activity in a log file.DISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

ESXI5-VMNET-000010 - All port groups must be configured to a value other than that of the native VLAN.DISA STIG VMWare ESXi Server 5 STIG v2r1VMware

CONFIGURATION MANAGEMENT

ESXI5-VMNET-000011 - All port groups must not be configured to VLAN 4095 except for Virtual Guest Tagging (VGT) - VGTDISA STIG VMWare ESXi Server 5 STIG v2r1VMware

CONFIGURATION MANAGEMENT

EX16-MB-000600 - Exchange services must be documented and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX19-MB-000198 - Exchange services must be documented, and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r2Windows

CONFIGURATION MANAGEMENT

Firewall Filter - Permit only required protocols from authorized sourcesJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Microsoft network client: Digitally sign communications (if server agrees)MSCT Windows Server 2012 R2 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Microsoft network client: Digitally sign communications (if server agrees)MSCT Windows 10 v1507 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Microsoft network client: Digitally sign communications (if server agrees)MSCT Windows Server 2016 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Microsoft network client: Digitally sign communications (if server agrees)MSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

SonicWALL - Security Services - Gateway AV - TCP Stream InboundTNS SonicWALL v5.9SonicWALL

SYSTEM AND INFORMATION INTEGRITY

WN10-CC-000290 - Remote Desktop Services must be configured with the client connection encryption set to the required level.DISA Microsoft Windows 10 STIG v3r4Windows

ACCESS CONTROL, MAINTENANCE

WN11-CC-000290 - Remote Desktop Services must be configured with the client connection encryption set to the required level.DISA Microsoft Windows 11 STIG v2r3Windows

ACCESS CONTROL

WN12-CC-000100 - Remote Desktop Services must be configured with the client connection encryption set to the required level.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

ACCESS CONTROL, MAINTENANCE

WN12-SO-000030 - Unencrypted passwords must not be sent to third-party SMB Servers.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

IDENTIFICATION AND AUTHENTICATION