Item Search

NameAudit NamePluginCategory
1.1.2 Ensure only trusted users are allowed to control Docker daemonCIS Docker v1.7.0 L1 Docker - LinuxUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.1.5 Ensure 'Password Policy' is enabledCIS Cisco ASA 9.x Firewall L1 v1.1.0Cisco

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.4.1.1 Ensure 'aaa local authentication max failed attempts' is set to less than or equal to '3'CIS Cisco ASA 9.x Firewall L1 v1.1.0Cisco

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.10 Do not create access keys during initial setup for IAM users with a console passwordCIS Amazon Web Services Foundations v5.0.0 L1amazon_aws

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.21 Ensure access to AWSCloudShellFullAccess is restrictedCIS Amazon Web Services Foundations v5.0.0 L1amazon_aws

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.6.1 Ensure Guest Account Is DisabledCIS Apple macOS 15.0 Sequoia Cloud-tailored v1.0.0 L1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.23 Benchmark v1.0.1 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.24 Benchmark v1.0.0 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.8 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.11.1 L2 Master NodeUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.14 Ensure containers are restricted from acquiring new privilegesCIS Docker v1.7.0 L1 Docker - LinuxUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

4.4.3.1.1 Ensure password failed attempts lockout is configuredCIS Red Hat EL8 Server L1 v3.0.0Unix

ACCESS CONTROL

4.4.3.1.3 Ensure password failed attempts lockout includes root accountCIS Oracle Linux 8 Workstation L2 v3.0.0Unix

ACCESS CONTROL

5.1.6.1 (L2) Ensure that collaboration invitations are sent to allowed domains onlyCIS Microsoft 365 Foundations v5.0.0 L2 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.6.1 (L2) Ensure that collaboration invitations are sent to allowed domains onlyCIS Microsoft 365 Foundations v5.0.0 L2 E3microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.6.2 (L1) Ensure that guest user access is restrictedCIS Microsoft 365 Foundations v5.0.0 L1 E3microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.6.2 (L1) Ensure that guest user access is restrictedCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.6.3 (L2) Ensure guest user invitations are limited to the Guest Inviter roleCIS Microsoft 365 Foundations v5.0.0 L2 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.6.3 (L2) Ensure guest user invitations are limited to the Guest Inviter roleCIS Microsoft 365 Foundations v5.0.0 L2 E3microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.2.1 Ensure Password Account Lockout Threshold Is ConfiguredCIS Apple macOS 14.0 Sonoma v2.1.0 L1Unix

ACCESS CONTROL

5.3.1 (L2) Ensure 'Privileged Identity Management' is used to manage rolesCIS Microsoft 365 Foundations v5.0.0 L2 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.3.2 Ensure system accounts are securedCIS Google Container-Optimized OS v1.2.0 L2 ServerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.3.2.1.2 Ensure password unlock time is configuredCIS SUSE Linux Enterprise 15 v2.0.1 L1 WorkstationUnix

ACCESS CONTROL

5.3.2.1.3 Ensure password failed attempts lockout includes root accountCIS SUSE Linux Enterprise 15 v2.0.1 L2 WorkstationUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Debian Linux 11 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.4 (L1) Ensure approval is required for Global Administrator role activationCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.3.5 (L1) Ensure approval is required for Privileged Role Administrator activationCIS Microsoft 365 Foundations v5.0.0 L1 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.1.3 Ensure Guest Account Is DisabledCIS Apple macOS 10.14 v2.0.0 L1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

6.1.3 Ensure Guest Account Is DisabledCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

6.1.3 Ensure Guest Account Is DisabledCIS Apple macOS 12.0 Monterey Cloud-tailored v1.1.0 L1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

6.1.3 Ensure Guest Account Is DisabledCIS Apple macOS 12.0 Monterey v4.0.0 L1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

6.2.3 Ensure that an exclusionary device code flow policy is consideredCIS Microsoft Azure Foundations v4.0.0 L2microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Debian 8 Server L1 v2.0.2Unix

ACCESS CONTROL

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Debian 8 Workstation L1 v2.0.2Unix

ACCESS CONTROL

6.12 Ensure that 'User consent for applications' is set to 'Do not allow user consent'CIS Microsoft Azure Foundations v4.0.0 L1microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

6.25 Ensure that 'Subscription leaving Microsoft Entra tenant' and 'Subscription entering Microsoft Entra tenant' is set to 'Permit no one'CIS Microsoft Azure Foundations v4.0.0 L2microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

7.1 Ensure authentication file permissions are set correctlyCIS MongoDB 3.6 L1 Unix Audit v1.1.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

7.1 Ensure authentication file permissions are set correctlyCIS MongoDB 3.6 L1 Windows Audit v1.1.0Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

9.2 Check for Duplicate User NamesCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL

9.3.1 Ensure that the Expiration Date is set for all Keys in RBAC Key VaultsCIS Microsoft Azure Foundations v4.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

9.3.2 Ensure that the Expiration Date is set for all Keys in Non-RBAC Key Vaults.CIS Microsoft Azure Foundations v4.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

9.3.3 Ensure that the Expiration Date is set for all Secrets in RBAC Key VaultsCIS Microsoft Azure Foundations v4.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

9.3.4 Ensure that the Expiration Date is set for all Secrets in Non-RBAC Key VaultsCIS Microsoft Azure Foundations v4.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

9.13 Check Groups in passwdCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL

10.3.1.2 Ensure that Storage Account access keys are periodically regeneratedCIS Microsoft Azure Foundations v4.0.0 L1microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MAINTENANCE

10.3.1.3 Ensure 'Allow storage account key access' for Azure Storage Accounts is 'Disabled'CIS Microsoft Azure Foundations v4.0.0 L1microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

MS.AAD.7.3v1 - Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers.CISA SCuBA Microsoft 365 Entra ID v1.5.0microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION