Item Search

NameAudit NamePluginCategory
1.1.1.2 Ensure mounting of squashfs filesystems is disabledCIS CentOS Linux 8 Workstation L2 v2.0.0Unix

CONFIGURATION MANAGEMENT

1.2 AZLX-23-000110CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.3 Disable all management related services on WAN portCIS FortiGate 7.4.x v1.0.1 L1FortiGate

CONFIGURATION MANAGEMENT

1.21 AZLX-23-001010CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.22 AZLX-23-001015CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.57 AZLX-23-001245CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

1.85 AZLX-23-002070CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.91 OL09-00-000499CIS Oracle Linux 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.106 AZLX-23-002180CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.107 AZLX-23-002185CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.178 AZLX-23-002555CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.185 AZLX-23-002585CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.357 ALMA-09-046550CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

2.1.1 Remove telnet-serverCIS Red Hat Enterprise Linux 5 L1 v2.2.1Unix

CONFIGURATION MANAGEMENT

2.1.7 Ensure message access server services are not in useCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.1.7 Ensure message access server services are not in useCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.1.8 Ensure message access server services are not in useCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.1.8 Ensure message access server services are not in useCIS Red Hat Enterprise Linux 10 v1.0.1 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.1.8 Ensure message access server services are not in useCIS Red Hat Enterprise Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.1.8 Ensure message access server services are not in useCIS Red Hat Enterprise Linux 8 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.1.8 Ensure message access server services are not in useCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.1.8 Ensure message access server services are not in useCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.1.8 Ensure message access server services are not in useCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.1.11 Ensure message access server services are not in useCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.1.12 Ensure Samba is not enabledCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.1.12 Ensure Samba is not enabled - statusCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.1.12 Ensure Samba is not installedCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.2.8 Ensure message access server services are not in useCIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.2.8 Ensure message access server services are not in useCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.2.12 Ensure Samba is not enabledCIS Debian 9 Server L1 v1.0.1Unix

CONFIGURATION MANAGEMENT

2.2.12 Ensure Samba is not enabledCIS Debian 9 Workstation L1 v1.0.1Unix

CONFIGURATION MANAGEMENT

3.4.2.11 Ensure nftables rules are permanentCIS Fedora 28 Family Linux Server L1 v2.0.0Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.9 Ensure nftables rules are permanentCIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.9 Ensure nftables rules are permanentCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.10 Ensure nftables rules are permanentCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.11 Ensure nftables rules are permanentCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.3.8 Ensure nftables rules are permanentCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.6.3.8 Ensure nftables rules are permanentCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

5.8 Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL NGWindows

CONFIGURATION MANAGEMENT

5.8 Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.43.1 Ensure 'Allow auditing events in Microsoft Defender Application Guard' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

AUDIT AND ACCOUNTABILITY

18.10.43.4 Ensure 'Allow files to download and save to the host operating system from Microsoft Defender Application Guard' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.43.5 Ensure 'Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting' is set to 'Enabled: Enable clipboard operation from an isolated session to the host'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

DTAVSEL-005 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to find unknown program viruses.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-007 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to find potentially unwanted programs.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-009 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to scan files when being read from disk.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-012 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must only be configured with exclusions that are documented and approved by the ISSO/ISSM/AO.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-018 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to allow access to files if scanning times out.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-019 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be enabled to scan mounted volumes when mounted volumes point to a network server without an anti-virus solution installed.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-301 - Access to the McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x Web UI must be enforced by firewall rules.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

CONFIGURATION MANAGEMENT