Item Search

NameAudit NamePluginCategory
1.2.1 (L1) Ensure 'Configure the list of domains on which Safe Browsing will not trigger warnings' is set to 'Disabled'CIS Google Chrome L1 v3.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.3 OL08-00-010019CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.4.1 (L1) Ensure 'UpdateMode' is set to 'Enabled: Enable Automatic Update Checks. Code will check for updates automatically and periodically.'CIS Visual Studio Code GPO v1.0.0 L1Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.86 CISC-RT-000930CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT IIICisco

ACCESS CONTROL

2.2.2 Ensure Time Is Set Within Appropriate LimitsCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

AUDIT AND ACCOUNTABILITY

2.8.4.1.3 Ensure 'Require that application add-ins are signed by Trusted Publisher' to 'Enabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

2.11.8.7.2.3.1 (L1) Ensure 'Allow Trusted Locations on the network' is set to 'Disabled'CIS Microsoft Intune for Office v1.1.0 L1Windows

CONFIGURATION MANAGEMENT

2.11.8.7.2.7 Ensure 'Require that application add-ins are signed by Trusted Publisher' is set to 'Enabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

2.15.1 (L1) Ensure 'Configure the list of domains on which Safe Browsing will not trigger warnings' is set to 'Disabled'CIS Google Chrome Group Policy v1.1.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.7 Ensure unneeded network protocol kernel modules are not availableCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

4.3.4.11 Ensure instsrv daemon is not in useCIS IBM AIX 7 v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

4.10.9.1.1 Ensure 'Prevent installation of devices that match any of these device IDs' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v5.0.0 BLWindows

MEDIA PROTECTION

4.10.9.1.1 Ensure 'Prevent installation of devices using drivers that match these device setup classes' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v5.0.0 BLWindows

MEDIA PROTECTION

4.10.9.1.4 Ensure 'Prevent installation of devices using drivers that match these device setup classes' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v5.0.0 BLWindows

MEDIA PROTECTION

5.2.3.3 Ensure events that modify the sudo log file are collectedCIS Red Hat Enterprise Linux 7 v4.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

5.2.3.3 Ensure events that modify the sudo log file are collectedCIS Amazon Linux 2023 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

5.2.3.3 Ensure events that modify the sudo log file are collectedCIS CentOS Linux 7 v4.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.2 Ensure actions as another user are always loggedCIS Debian Linux 12 v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.9 Ensure events that modify /etc/NetworkManager directory are collectedCIS Debian Linux 13 v1.1.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.9 Ensure events that modify /etc/NetworkManager directory are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.9 Ensure events that modify /etc/NetworkManager directory are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.9 Ensure events that modify /etc/NetworkManager directory are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Rocky Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Rocky Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Oracle Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.15 Ensure that a Zone Protection Profile with an enabled SYN Flood Action of SYN Cookies is attached to all untrusted zonesCIS Palo Alto Firewall 10 v1.3.0 L1Palo_Alto

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.16 Ensure that a Zone Protection Profile with an enabled SYN Flood Action of SYN Cookies is attached to all untrusted zonesCIS Palo Alto Firewall 7 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND COMMUNICATIONS PROTECTION

6.16 Ensure that a Zone Protection Profile with an enabled SYN Flood Action of SYN Cookies is attached to all untrusted zonesCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND COMMUNICATIONS PROTECTION

6.16 Ensure that a Zone Protection Profile with an enabled SYN Flood Action of SYN Cookies is attached to all untrusted zonesCIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

7.1 Ensure that RDP Access from the Internet is Evaluated and RestrictedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-002101 - AIX must monitor and record unsuccessful remote logins.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003048 - If SNMP is not required on AIX, the snmpd service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

ALMA-09-009920 - AlmaLinux OS 9 must check the GPG signature of repository metadata before package installation.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ARBA-ND-000213 - AOS must enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies.DISA HPE Aruba Networking AOS NDM STIG v1r1ArubaOS

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

ESXI-06-000045 - The system must enable a persistent log location for all locally stored logs.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-65-000045 - The ESXi host must enable a persistent log location for all locally stored logs.DISA STIG VMware vSphere ESXi 6.5 v2r4VMware

AUDIT AND ACCOUNTABILITY

GEN004900 - The ftpusers file must contain account names not allowed to use FTP.DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-07-010118 - The Red Hat Enterprise Linux operating system must be configured so that /etc/pam.d/passwd implements /etc/pam.d/system-auth when changing passwords.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-07-010240 - The Red Hat Enterprise Linux operating system must be configured so that passwords are restricted to a 24 hours/1 day minimum lifetime.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-07-010270 - The Red Hat Enterprise Linux operating system must be configured so that passwords are prohibited from reuse for a minimum of five generations.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-07-030700 - The Red Hat Enterprise Linux operating system must audit all uses of the sudoers file and all files in the /etc/sudoers.d/ directory.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

RHEL-07-040000 - The Red Hat Enterprise Linux operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

ACCESS CONTROL

SQL2-00-010100 - Use of the SQL Server software installation account must be restricted to SQL Server software installation.DISA STIG SQL Server 2012 Database OS Audit v1r20Windows

CONFIGURATION MANAGEMENT

UBTU-24-200090 - Ubuntu 24.04 LTS must monitor remote access methods.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

ACCESS CONTROL