Item Search

NameAudit NamePluginCategory
1.2.1.6 Ensure access to files in the /etc/apt/auth.conf.d/ directory is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.1.6 Ensure access to files in the /etc/apt/auth.conf.d/ directory is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.3.1.5 Ensure the SELinux mode is enforcingCIS Oracle Linux 8 v4.0.0 L2 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.3.1.5 Ensure the SELinux mode is enforcingCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.3.1.5 Ensure the SELinux mode is enforcingCIS AlmaLinux OS 10 v1.0.0 L2 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.3.1.5 Ensure the SELinux mode is enforcingCIS AlmaLinux OS 8 v4.0.0 L2 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.4.1 Ensure permissions on bootloader config are not overridden - if lineCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS Red Hat Enterprise Linux 8 v4.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS AlmaLinux OS 8 v4.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.6.1.1 Ensure SELinux is enabled in the bootloader configuration - security=selinuxCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.1 Ensure SELinux is enabled in the bootloader configuration - security=selinuxCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.1 Ensure SELinux is enabled in the bootloader configuration - selinux = 1CIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.1 Ensure SELinux is not disabled in bootloader configuration - enforcingCIS Aliyun Linux 2 L2 v1.0.0Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcing - /etc/selinux/configCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcing - sestatusCIS Aliyun Linux 2 L2 v1.0.0Unix

ACCESS CONTROL

1.6.1.3 Ensure SELinux policy is configured - sestatusCIS Aliyun Linux 2 L2 v1.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure all AppArmor Profiles are enforcing - complainCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure all AppArmor Profiles are enforcing - unconfinedCIS Ubuntu Linux 16.04 LTS Server L2 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure no unconfined daemons existCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.3 Ensure SELinux or AppArmor are installedCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.7.1.1 Ensure AppArmor is installedCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

1.7.1.2 Ensure SELinux is not disabled in bootloader configuration - selinuxCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

2.2.45 (L1) Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MSWindows

ACCESS CONTROL

2.3.10.12 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

ACCESS CONTROL

4.4 Ensure logrotate assigns appropriate permissionsCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

4.11.30.1 Ensure 'Prevent users from sharing files within their profile. (User)' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

ACCESS CONTROL

5.1.6 Ensure permissions on /etc/cron.monthly are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

5.1.8 Ensure cron is restricted to authorized users - '/etc/cron.allow'CIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

ACCESS CONTROL

5.2.1 Ensure permissions on /etc/ssh/sshd_config are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

5.2.2 Ensure permissions on SSH private host key files are configuredCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

5.2.3 Ensure permissions on SSH public host key files are configuredCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

5.2.3 Ensure permissions on SSH public host key files are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

5.3.3 Ensure permissions on SSH public host key files are configuredCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/login.defsCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

5.5.3 Ensure default group for the root account is GID 0CIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.5.4 Ensure default user umask is 027 or more restrictive - '/etc/bash.bashrc'CIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.1.1 Audit system file permissionsCIS Aliyun Linux 2 L2 v1.0.0Unix

ACCESS CONTROL

6.1.6 Ensure permissions on /etc/passwd- are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

6.2.7 Ensure users' dot files are not group or world writableCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.13 Ensure users' .netrc Files are not group or world accessibleCIS Aliyun Linux 2 L1 v1.0.0Unix

ACCESS CONTROL

6.2.17 Ensure shadow group is emptyCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.17 Ensure shadow group is emptyCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.2.20 Ensure shadow group is empty - /etc/passwdCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

7.6 Ensure directory in logging.properties is a secure location - check log directory locationCIS Apache Tomcat 9 L1 v1.2.0 MiddlewareUnix

ACCESS CONTROL

7.6 Ensure directory in logging.properties is a secure location - check prefix application nameCIS Apache Tomcat 9 L1 v1.2.0 MiddlewareUnix

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows Server 2025 v2.1.0 L2 MSWindows

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2Windows

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows Server 2019 v5.0.0 L2 DCWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L1 MSWindows

ACCESS CONTROL