Item Search

NameAudit NamePluginCategory
1.1.2.38 Set 'Audit Policy: Object Access: Filtering Platform Packet Drop' to 'No Auditing'CIS Windows 8 L1 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

1.2.4.2.2.30 Configure 'Reset platform validation data after BitLocker recovery'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.3 Disable all management related services on WAN portCIS FortiGate 7.4.x v1.0.1 L1FortiGate

CONFIGURATION MANAGEMENT

1.5.1.4 Ensure permissions on /etc/motd are configuredCIS Google Container-Optimized OS v1.2.0 L2 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

1.5.1.6 Ensure permissions on /etc/issue.net are configuredCIS Google Container-Optimized OS v1.2.0 L2 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

2.2 Alter the Advertised server.number StringCIS Apache Tomcat 10 L2 v1.1.0 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

2.2 Alter the Advertised server.number StringCIS Apache Tomcat 10 L2 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.2 Alter the Advertised server.number StringCIS Apache Tomcat 9 L2 v1.2.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

2.13 Disable operations on legacy registry (v1)CIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

2.13 Ensure operations on legacy registry (v1) are DisabledCIS Docker Community Edition v1.1.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

2.16 Ensure daemon-wide custom seccomp profile is applied, if neededCIS Docker Community Edition v1.1.0 L2 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

2.18 Ensure that a daemon-wide custom seccomp profile is applied if appropriateCIS Docker v1.8.0 L2 OS LinuxUnix

SYSTEM AND SERVICES ACQUISITION

2.19 Encrypt data exchanged between containers on different nodes on the overlay networkCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

4.5 Enable Content trust for DockerCIS Docker 1.13.0 v1.0.0 L2 DockerUnix

SYSTEM AND INFORMATION INTEGRITY

4.6.3 Require hardened security contexts for all workload Pods and containersCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

CONFIGURATION MANAGEMENT

5.1.1.5 Ensure 'EXECUTE' is revoked from 'PUBLIC' on 'Job Scheduler' PackagesCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

5.1.1.5 Ensure 'EXECUTE' is revoked from 'PUBLIC' on 'Job Scheduler' PackagesCIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

ACCESS CONTROL

5.1.1.7 Ensure 'EXECUTE' is revoked from 'PUBLIC' on 'DBMS_CREDENTIAL' PackageCIS Oracle Server 18c DB Traditional Auditing v1.1.0OracleDB

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.2.1 Ensure '%ANY%' Is Revoked from Unauthorized 'GRANTEE'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

5.2.14 Ensure 'GRANT ANY OBJECT PRIVILEGE' Is Revoked from Unauthorized 'GRANTEE'CIS Oracle Server 18c DB Traditional Auditing v1.1.0OracleDB

ACCESS CONTROL

5.2.15 Ensure 'GRANT ANY ROLE' Is Revoked from Unauthorized 'GRANTEE'CIS Oracle Server 18c DB Traditional Auditing v1.1.0OracleDB

ACCESS CONTROL

5.3.2 Ensure 'SELECT_CATALOG_ROLE' Is Revoked from Unauthorized 'GRANTEE'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

5.3.3 Ensure 'EXECUTE_CATALOG_ROLE' Is Revoked from Unauthorized 'GRANTEE'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

5.3.4 Ensure 'DBA' Is Revoked from Unauthorized 'GRANTEE'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

6.1.2 Ensure the 'ROLE' Audit Option Is EnabledCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

AUDIT AND ACCOUNTABILITY

6.1.5 Ensure the 'DATABASE LINK' Audit Option Is EnabledCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

AUDIT AND ACCOUNTABILITY

6.1.9 Ensure the 'DIRECTORY' Audit Option Is EnabledCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

AUDIT AND ACCOUNTABILITY

6.1.10 Ensure the 'SELECT ANY DICTIONARY' Audit Option Is EnabledCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

AUDIT AND ACCOUNTABILITY

6.2.19 Ensure 'PDB_DBA' Is Revoked From Unauthorized 'GRANTEE'CIS Oracle Database 19c v2.0.0 L1 RDBMSOracleDB

ACCESS CONTROL, MEDIA PROTECTION

6.2.20 Ensure 'PDB_DBA' Is Revoked From Unauthorized 'GRANTEE'CIS Oracle Database 26ai v1.0.0 L1 RDBMS On Linux Host OS OracleDBOracleDB

ACCESS CONTROL, MEDIA PROTECTION

6.2.20 Ensure 'PDB_DBA' Is Revoked From Unauthorized 'GRANTEE'CIS Oracle Database 26ai v1.0.0 L1 RDBMS On Windows Server Host OS OracleDBOracleDB

ACCESS CONTROL, MEDIA PROTECTION

6.2.20 Ensure 'PDB_DBA' Is Revoked From Unauthorized 'GRANTEE'CIS Oracle Database 26ai v1.0.0 L1 RDBMSOracleDB

ACCESS CONTROL, MEDIA PROTECTION

6.2.20 Ensure 'PDB_DBA' Is Revoked From Unauthorized 'GRANTEE'CIS Oracle Database 23ai v1.1.0 L1 RDBMSOracleDB

ACCESS CONTROL, MEDIA PROTECTION

7.3 Ensure Database Backups are EncryptedCIS Microsoft SQL Server 2019 v1.6.0 L2 Database EngineMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

7.4 Ensure data exchanged between containers are encrypted on different nodes on the overlay networkCIS Docker Community Edition v1.1.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

18.9.5.7 Ensure 'Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection' is set to 'Enabled: Enabled in enforcement mode'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

SYSTEM AND INFORMATION INTEGRITY

18.10.43.1 Ensure 'Allow auditing events in Microsoft Defender Application Guard' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

AUDIT AND ACCOUNTABILITY

18.10.43.1 Ensure 'Allow auditing events in Microsoft Defender Application Guard' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

AUDIT AND ACCOUNTABILITY

18.10.43.2 Ensure 'Allow camera and microphone access in Microsoft Defender Application Guard' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.43.4 Ensure 'Allow files to download and save to the host operating system from Microsoft Defender Application Guard' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.43.4 Ensure 'Allow files to download and save to the host operating system from Microsoft Defender Application Guard' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.43.5 Ensure 'Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting' is set to 'Enabled: Enable clipboard operation from an isolated session to the host'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.10.43.5 Ensure 'Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting' is set to 'Enabled: Enable clipboard operation from an isolated session to the host'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.10.43.5 Ensure 'Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting' is set to 'Enabled: Enable clipboard operation from an isolated session to the host'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

CONFIGURATION MANAGEMENT

CNTR-R2-000010 - Rancher RKE2 must protect authenticity of communications sessions with the use of FIPS-validated 140-2 or 140-3 security requirements for cryptographic modules.DISA Rancher Government Solutions RKE2 STIG v2r7Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

MS.POWERPLATFORM.3.1v1 - Power Platform tenant isolation SHALL be enabled.CISA SCuBA Microsoft 365 Power Platform v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

RHEL-06-000068 - The system boot loader must require authentication - UEFIDISA Red Hat Enterprise Linux 6 STIG v2r2Unix

ACCESS CONTROL

Select the channel for Microsoft Defender monthly platform updatesMSCT Windows Server 2025 DC v1.0.0Windows
Select the channel for Microsoft Defender monthly platform updatesMSCT Windows Server 2025 MS v1.0.0Windows
TCAT-AS-000860 - Clusters must operate on a trusted network.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION