Item Search

NameAudit NamePluginCategory
1.3 Ensure Download New Updates When Available Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.4 Ensure Install of macOS Updates Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.7 Ensure Software Update Deferment Is Less Than or Equal to 30 DaysCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.1.1.2 Audit iCloud DriveCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.1.1.4 Audit Security Keys Used With Apple AccountsCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

2.1.1.5 Audit Freeform Sync to iCloudCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.1.1.6 Audit Find My MacCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.1.2 Audit App Store Password SettingsCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.1.2 Ensure AirPlay Receiver Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.1.3 Ensure 'Accounts: Guest account status' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

ACCESS CONTROL

2.3.2.1 Ensure Set Time and Date Automatically Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

2.3.2.2 Ensure the Time Service Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

2.3.3.1 Ensure Screen Sharing Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.3.2 Ensure File Sharing Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.3.3 Ensure Printer Sharing Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.3.5 Ensure Remote Management Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.3.9 Ensure Media Sharing Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.3.10 Ensure Bluetooth Sharing Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION, SYSTEM AND SERVICES ACQUISITION

2.3.4.2 Ensure Time Machine Volumes Are Encrypted If Time Machine Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONTINGENCY PLANNING, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.5.3 Ensure 'Domain controller: LDAP server channel binding token requirements' is set to 'Always' (DC Only)CIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.5.3 Ensure 'Domain controller: LDAP server channel binding token requirements' is set to 'Always' (DC Only)CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.10.9 (L1) Configure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

2.3.10.9 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

ACCESS CONTROL

2.4.1 Audit Menu Bar and Control Center IconsCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.5.2 Ensure Listen for (Siri) Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.4 Ensure Limit Ad Tracking Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.6.5 Ensure Gatekeeper Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

SYSTEM AND INFORMATION INTEGRITY

2.6.6 Ensure FileVault Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.7.1 Ensure Screen Saver Hot Corners Are Secure For Current UserCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL

2.10.1 Ensure an Inactivity Interval of 15 Minutes Or Less for the Screen Saver Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL

2.10.2 Ensure Require Password After Screen Saver Begins or Display Is Turned Off Is Enabled for 5 Seconds or ImmediatelyCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

2.11.2 Audit Touch IDCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND SERVICES ACQUISITION

2.12.1 Ensure Guest Account Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

2.13.1 Audit Passwords System Preference SettingCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.14.1 Audit Game Center SettingsCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT

2.18.1 Ensure On-Device Dictation Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.1 Ensure Security Auditing Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.7 Audit Software InventoryCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, MAINTENANCE

4.3 Ensure NFS Server Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.1.5 Ensure Appropriate Permissions Are Enabled for System Wide ApplicationsCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

5.1.6 Ensure No World Writable Folders Exist in the System FolderCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

5.2.6 Ensure Complex Password Must Contain Uppercase and Lowercase Characters Is ConfiguredCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure all internal user storage APFS volumes are encryptedCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.3.2 Ensure all APFS and HFS+ external user storage volumes are encryptedCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.5 Ensure a Separate Timestamp Is Enabled for Each User/tty ComboCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL

5.6 Ensure the "root" Account Is DisabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL

5.8 Ensure a Login Window Banner ExistsCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.3.4 Ensure Prevent Cross-site Tracking in Safari Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.9 Audit Pop-up WindowsCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.10 Ensure Show Status Bar Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION