Item Search

NameAudit NamePluginCategory
1.1.3.2.1.1 Ensure 'Allow Trusted Locations on the network' is set to DisabledCIS Microsoft Office Access 2013 v1.0.1Windows

CONFIGURATION MANAGEMENT

1.5 Enable macOS update installsCIS Apple macOS 10.12 L1 v1.2.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.5 Enable macOS update installsCIS Apple macOS 10.13 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.6 Ensure Install of macOS Updates Is EnabledCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.6.6.2.3.1 Ensure 'Allow Trusted Locations on The Network' is set to DisabledCIS Microsoft Office PowerPoint 2016 v1.0.1Windows

CONFIGURATION MANAGEMENT

1.32 EX19-MB-000123CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.36 EX19-MB-000127CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.47 EX19-ED-000137CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

1.48 EX19-ED-000138CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

1.159 SOL-11.1-070060CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.2 Ensure Trusted Execution Path is enabledCIS IBM AIX 7 v1.2.0 L2Unix

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

2.9 Ensure IAM password policy prevents password reuseCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

IDENTIFICATION AND AUTHENTICATION

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Community Server 9.7 v1.0.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Community Server 8.4 v1.1.0 L2 MySQL RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL

2.13 Ensure 'sa' Login Account is set to 'Disabled'CIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

ACCESS CONTROL

2.13 Ensure 'sa' Login Account is set to 'Disabled'CIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

ACCESS CONTROL

3.1.2 Ensure MFA Delete is enabled on S3 bucketsCIS Amazon Web Services Foundations v7.0.0 L2amazon_aws

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MEDIA PROTECTION

5.2 Ensure management console sign-in without MFA is monitoredCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

AUDIT AND ACCOUNTABILITY

6.3 Use CloudFront Content Distribution NetworkCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

CONFIGURATION MANAGEMENT

6.7 Ensure that the EC2 Metadata Service only allows IMDSv2CIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

CONFIGURATION MANAGEMENT

6.17 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actionsCIS Palo Alto Firewall 11 v1.2.0 L1Palo_Alto

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.28 Ensure EC2 instances within App Tier have no Elastic / Public IP addresses associatedCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

9.11 Check Groups in passwd(4)CIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

9.12 Check That Users Are Assigned Home DirectoriesCIS Solaris 11 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

9.12 Check That Users Are Assigned Home DirectoriesCIS Solaris 11.1 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

9.12 Check That Users Are Assigned Home DirectoriesCIS Solaris 11.2 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

9.24 Find Files and Directories with Extended AttributesCIS Oracle Solaris 11.4 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

9.25 Find Files and Directories with Extended AttributesCIS Solaris 11 L1 v1.1.0Unix
9.25 Find Files and Directories with Extended AttributesCIS Solaris 11.1 L1 v1.0.0Unix
AMLS-NM-000440 - The Arista Multilayer Switch must support organizational requirements to conduct backups of system-level information contained in the information system when changes occur or weekly, whichever is sooner.DISA STIG Arista MLS DCS-7000 Series NDM v1r4Arista

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

ARBA-ND-000340 - AOS must be configured to conduct backups of system-level information contained in the information system when changes occur.DISA HPE Aruba Networking AOS NDM STIG v1r1ArubaOS

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

ARBA-ND-000341 - AOS must support organizational requirements to conduct backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner.DISA HPE Aruba Networking AOS NDM STIG v1r1ArubaOS

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

CISC-ND-001410 - The Cisco router must be configured to back up the configuration when changes occur.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

CISC-ND-001410 - The Cisco router must be configured to back up the configuration when changes occur.DISA Cisco IOS Router NDM STIG v3r8Cisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

CISC-ND-001410 - The Cisco switch must be configured to support organizational requirements to conduct backups of the configuration when changes occur.DISA Cisco IOS Switch NDM STIG v3r8Cisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

EX13-EG-000120 - Exchange message size restrictions must be controlled on Send connectors.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-MB-000175 - Exchange Message size restrictions must be controlled on Receive connectors.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-MB-000205 - Exchange Message size restrictions must be controlled on Send connectors.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000240 - Exchange message size restrictions must be controlled on Send connectors.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000350 - Exchange Message size restrictions must be controlled on Receive connectors.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000410 - Exchange Message size restrictions must be controlled on Send connectors.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-ED-000115 - Exchange message size restrictions must be controlled on Send connectors.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000124 - Exchange Message size restrictions must be controlled on Receive connectors.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000128 - Exchange message size restrictions must be controlled on send connectors.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-DM-000277 - The BIG-IP appliance must create backups of system-level information contained in the information system when changes occur or weekly, whichever is sooner.DISA F5 BIG-IP Device Management STIG v2r4F5

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

F5BI-DM-000279 - The BIG-IP appliance must be configured to create backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner.DISA F5 BIG-IP Device Management STIG v2r4F5

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

F5BI-DM-300060 - The F5 BIG-IP appliance must conduct backups of the configuration at a weekly or organization-defined frequency and store on a separate device.DISA F5 BIG-IP TMOS NDM STIG v1r2F5

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

FGFW-ND-000180 - The FortiGate device must conduct backups of system-level information contained in the information system when changes occur.DISA Fortigate Firewall NDM STIG v1r4FortiGate

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

SOL-11.1-070060 - Groups assigned to users must exist in the /etc/group file.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

vCenter: vcenter-8.vami-timeVMware vSphere Security Configuration and Hardening GuideVMware

AUDIT AND ACCOUNTABILITY