Item Search

NameAudit NamePluginCategory
1.1 Ensure packages are obtained from authorized repositoriesCIS PostgreSQL 13 v1.3.0 L1 OS Linux UnixUnix

CONFIGURATION MANAGEMENT, MAINTENANCE

1.1.3 Ensure Folders Are Structured By Environment And SensitivityCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.21 Configure 'Use enhanced Boot Configuration Data validation profile'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.3 Disable all management related services on WAN portCIS Fortigate 7.0.x v1.4.0 L1FortiGate

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.4 Ensure that Security Key Enforcement is Enabled for All Admin AccountsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION

1.5 FTP/SFTP Access Authorization - sftp top-directoryTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.9 Ensure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to UsersCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

1.12 Ensure That Separation of Duties Is Enforced While Assigning KMS Related Roles to UsersCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

1.13 Ensure API Keys Only Exist for Active ServicesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

1.14 Ensure API Keys Are Restricted To Use by Only Specified Hosts and AppsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

1.16 Ensure API Keys Are Rotated Every 90 DaysCIS Google Cloud Platform Foundation v5.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

2.2 Alter the Advertised server.number StringCIS Apache Tomcat 9 L2 v1.2.0Unix

CONFIGURATION MANAGEMENT

2.4 Ensure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket LockCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

2.8 Ensure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.9 Ensure That the Log Metric Filter and Alerts Exist for VPC Network Route ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.10 Ensure That the Log Metric Filter and Alerts Exist for VPC Network ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.11 Ensure That the Log Metric Filter and Alerts Exist for Cloud Storage IAM Permission ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.12 Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration ChangesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.15 Ensure 'Access Transparency' is 'Enabled'CIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.17 Ensure Logging is enabled for HTTP(S) Load BalancerCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.20 Apply a daemon-wide custom seccomp profile, if neededCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Ensure That the Default Network Does Not Exist in a ProjectCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.6 Ensure That SSH Access Is Restricted From the InternetCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.7 Ensure That RDP Access Is Restricted From the InternetCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.9 Ensure Private Service Connect is Used for Access to Google APIsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

3.12 Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are 'Allowed'CIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL

4.2 Ensure logrotate is configuredCIS Google Container-Optimized OS v1.2.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

4.8 Ensure Compute Instances Are Launched With Shielded VM EnabledCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND INFORMATION INTEGRITY

4.9 Ensure That Compute Instances Do Not Have Public IP AddressesCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

4.9 Use COPY instead of ADD in DockerfileCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.11 Ensure only verified packages are installedCIS Docker v1.8.0 L2 OS LinuxUnix

SYSTEM AND SERVICES ACQUISITION

4.11 Ensure verified packages are only InstalledCIS Docker Community Edition v1.1.0 L2 DockerUnix

CONFIGURATION MANAGEMENT

4.11 Install verified packages onlyCIS Docker 1.13.0 v1.0.0 L2 DockerUnix

CONFIGURATION MANAGEMENT

4.12 Ensure the Latest Operating System Updates Are Installed On Your Virtual Machines in All ProjectsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

SYSTEM AND SERVICES ACQUISITION

5.1.3.1 Ensure 'ALL' Is Revoked from Unauthorized 'GRANTEE' on 'AUD$'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

5.1.3.1 Ensure 'ALL' Is Revoked from Unauthorized 'GRANTEE' on 'AUD$'CIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

ACCESS CONTROL

5.2 Ensure That Cloud Storage Buckets Have Uniform Bucket-Level Access EnabledCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

5.2.15 Ensure 'GRANT ANY ROLE' Is Revoked from Unauthorized 'GRANTEE'CIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

ACCESS CONTROL

5.4 Restrict Linux Kernel Capabilities within containersCIS Docker 1.6 v1.0.0 L1 DockerUnix

ACCESS CONTROL

5.6 Ensure sensitive host system directories are not mounted on containersCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.10.2 Use GKE Sandbox for untrusted or high risk workloadsCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

SYSTEM AND COMMUNICATIONS PROTECTION

6.2.4 Ensure 'Log_statement' Database Flag for Cloud SQL PostgreSQL Instance Is Set AppropriatelyCIS Google Cloud Platform Foundation v5.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

6.7 Ensure That Cloud SQL Database Instances Do Not Have Public IPsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

7.2 Ensure That All BigQuery Tables Are Encrypted With Customer-Managed Encryption Key (CMEK)CIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Ensure That a Default Customer-Managed Encryption Key (CMEK) Is Specified for All BigQuery Data SetsCIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.1 Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption KeyCIS Google Cloud Platform Foundation v5.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.3.4 Ensure standard processes are used for VM deploymentCIS VMware ESXi 6.7 v1.3.0 Level 1VMware

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

TCAT-AS-001020 - LockOutRealms must be used for management of Tomcat.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

ACCESS CONTROL

TCAT-AS-001030 - LockOutRealms failureCount attribute must be set to 5 failed logins for admin users.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

ACCESS CONTROL

VCPF-67-000003 - Performance Charts must limit the maximum size of a POST request.DISA STIG VMware vSphere 6.7 Perfcharts Tomcat v1r3Unix

ACCESS CONTROL