Item Search

NameAudit NamePluginCategory
1.2 Ensure the container host has been HardenedCIS Docker Community Edition v1.1.0 L1 Linux Host OSUnix

CONFIGURATION MANAGEMENT

1.2 Harden the container hostCIS Docker 1.13.0 v1.0.0 L1 LinuxUnix

CONFIGURATION MANAGEMENT

1.2 Use Dedicated Least Privileged Account for MariaDB Daemon/ServiceCIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

1.2 Use Dedicated Least Privileged Account for MariaDB Daemon/ServiceCIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS MySQL 5.6 Community Windows OS L1 v2.0.0Windows

ACCESS CONTROL

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS MySQL 5.6 Enterprise Linux OS L1 v2.0.0Unix

ACCESS CONTROL

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS MySQL 5.7 Community Windows OS L1 v2.0.0Windows

ACCESS CONTROL

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS MySQL 5.7 Community Linux OS L1 v2.0.0Unix

ACCESS CONTROL

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS MySQL 5.6 Enterprise Windows OS L1 v2.0.0Windows

ACCESS CONTROL

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS Oracle MySQL Enterprise Edition 8.4 v1.1.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL

1.2.1 Ensure the container host has been HardenedCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT

1.210 SOL-11.1-090280CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.211 SOL-11.1-090280CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Ensure that unused policies are reviewed regularlyCIS Fortigate 7.0.x v1.4.0 L2FortiGate

CONFIGURATION MANAGEMENT

3.1 Ensure that unused policies are reviewed regularlyCIS FortiGate 7.4.x v1.0.1 L2FortiGate

CONFIGURATION MANAGEMENT

4.1.3 Ensure network interface zone is configuredCIS Amazon Linux 2 v4.0.0 L2 ServerUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2 Ensure device enrollment for personally owned devices is blocked by defaultCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

4.2 Ensure device enrollment for personally owned devices is blocked by defaultCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

CONFIGURATION MANAGEMENT

5.1.5 Ensure No World Writable Folders Exist in the System FolderCIS Apple macOS 14.0 Sonoma Cloud-tailored v1.1.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

5.2.2.3 Enable Conditional Access policies to block legacy authenticationCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

CONFIGURATION MANAGEMENT

6.2.3.20 Ensure the audit configuration is loaded regardless of errorsCIS Amazon Linux 2 v4.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.33 Ensure the audit configuration is loaded regardless of errorsCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.20 Ensure the audit configuration is loaded regardless of errorsCIS Rocky Linux 8 v3.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.20 Ensure the audit configuration is loaded regardless of errorsCIS Red Hat Enterprise Linux 8 v4.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.20 Ensure the audit configuration is loaded regardless of errorsCIS Rocky Linux 8 v3.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.35 Ensure the audit configuration is loaded regardless of errorsCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.35 Ensure the audit configuration is loaded regardless of errorsCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.5.2 (L1) Host SSH daemon, if enabled, must use FIPS 140-2/140-3 validated cryptographic modulesCIS VMware ESXi 8.0 v1.3.0 L1 UnixUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.2.9 Audit AutofillCIS Apple macOS 11.0 Big Sur v4.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

9.23 Find SUID/SGID System ExecutablesCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

9.23 Find SUID/SGID System ExecutablesCIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL

11.2 Ensure Apache Processes Run in the httpd_t Confined ContextCIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix

ACCESS CONTROL

BIND-9X-001510 - The host running a BIND 9.x implementation must use a dedicated management interface to separate management traffic from DNS-specific traffic.DISA BIND 9.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

DG0007-ORACLE11 - The database should be secured in accordance with DoD, vendor and/or commercially accepted practices where applicable.DISA STIG Oracle 11 Installation v9r1 WindowsWindows
DG0007-ORACLE11 - The database should be secured in accordance with DoD, vendor and/or commercially accepted practices where applicable.DISA STIG Oracle 11 Installation v9r1 LinuxUnix
Ensure 'Failover' is enabledTenable Cisco Firepower Best Practices AuditCisco

CONFIGURATION MANAGEMENT

Ensure 'logging to monitor' is disabledTenable Cisco Firepower Best Practices AuditCisco

CONFIGURATION MANAGEMENT

Ensure 'Password Policy' is enabled - minimum-lengthTenable Cisco Firepower Best Practices AuditCisco

IDENTIFICATION AND AUTHENTICATION

Ensure 'SNMP traps' is enabled - linkupTenable Cisco Firepower Best Practices AuditCisco

CONFIGURATION MANAGEMENT

Ensure 'syslog hosts' is configured correctlyTenable Cisco Firepower Best Practices AuditCisco

AUDIT AND ACCOUNTABILITY

Ensure 'TACACS+/RADIUS' is configured correctly - protocolTenable Cisco Firepower Best Practices AuditCisco

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

Ensure DNS services are configured correctly - name-serverTenable Cisco Firepower Best Practices AuditCisco

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure non-default application inspection is configured correctlyTenable Cisco Firepower Best Practices AuditCisco

SYSTEM AND INFORMATION INTEGRITY

EX13-EG-000260 - The Exchange Simple Mail Transfer Protocol (SMTP) Sender filter must be enabled.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-MB-000146 - Exchange antimalware agent must be enabled and configured.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

Salesforce.com : User Access - 'No new users have been created since the last scan'TNS Salesforce Best Practices Audit v1.2.0Salesforce.com

ACCESS CONTROL

WG170 A22 - Each readable web document directory must contain either a default, home, index, or equivalent file.DISA STIG Apache Site 2.2 Unix v1r11Unix
WG170 A22 - Each readable web document directory must contain either a default, home, index, or equivalent file.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix