Item Search

NameAudit NamePluginCategory
1.1 Ensure All Apple-provided Software Is CurrentCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1.1 - AirWatch - Update firmware to latest versionAirWatch - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.1.1 - MobileIron - Update firmware to latest versionMobileIron - CIS Apple iOS 9 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

1.1.2 - AirWatch - Enable Passcode Lock - 'Passcode Required = true'AirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

1.1.2 - MobileIron - Enable Passcode Lock - 'Passcode Required = on'MobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.1.4 - MobileIron - Set Auto-lock - 'Inactivity Timeout <= 2'MobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.1.19 - AirWatch - Enable Automatic Downloads of App UpdatesAirWatch - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.1.19 - AirWatch - Erase all data before return, recycle, reassignment, or other dispositionAirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

1.1.19 - MobileIron - Enable Automatic Downloads of App UpdatesMobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.1.19 - MobileIron - Erase all data before return, recycle, reassignment, or other dispositionMobileIron - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

1.1.21 - AirWatch - Erase all data before return, recycle, reassignment, or other dispositionAirWatch - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.2 Ensure Auto Update Is EnabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.2.2 - AirWatch - Enable Fraudulent Website WarningAirWatch - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.2.2 - AirWatch - Enable Fraudulent Website WarningAirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

1.4 Ensure Install of macOS Updates Is EnabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.1.1 - MobileIron - Set Security to disallow profile removalMobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

2.2.1 - AirWatch - Require passcode on deviceAirWatch - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

2.2.1 - AirWatch - Require passcode on deviceAirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

2.2.1 - MobileIron - Require passcode on deviceMobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

2.2.2 - AirWatch - Do Not Allow Simple ValueAirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

IDENTIFICATION AND AUTHENTICATION

2.2.4 - AirWatch - Set minimum passcode lengthAirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

IDENTIFICATION AND AUTHENTICATION

2.2.4 - MobileIron - Set minimum passcode lengthMobileIron - CIS Apple iOS 9 v1.0.0 L1MDM

IDENTIFICATION AND AUTHENTICATION

2.2.7 - MobileIron - Set Maximum number of failed attemptsMobileIron - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

2.2.7 - MobileIron - Set Maximum number of failed attemptsMobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

2.3.3.2 Ensure Screen Sharing Is DisabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.3.11 Ensure Bluetooth Sharing Is DisabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION, SYSTEM AND SERVICES ACQUISITION

2.3.4.2 Ensure Time Machine Volumes Are Encrypted If Time Machine Is EnabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

CONTINGENCY PLANNING, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.6.5 Ensure Gatekeeper Is EnabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

SYSTEM AND INFORMATION INTEGRITY

2.10.4 Ensure Login Window Displays as Name and Password Is EnabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.12.2 Ensure Guest Access to Shared Folders Is DisabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

2.15.1 Audit Notification & Focus SettingsCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.18.1 Ensure On-Device Dictation Is EnabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.1.1 - AirWatch - Enable 'Require password'AirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

3.1.1 - MobileIron - Enable 'Require password'MobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

3.1.3 - MobileIron - Set the 'minimum password length'MobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

IDENTIFICATION AND AUTHENTICATION

3.1.5 - MobileIron - Set the 'timeout' for 'Time without user input before password must be re-entered (in minutes)'MobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

3.1.6 - MobileIron - Limit the 'Number of failed attempts allowed'MobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

5.1.1 Ensure Home Folders Are SecureCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

5.2.2 Ensure Password Minimum Length Is ConfiguredCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.5 Ensure a Separate Timestamp Is Enabled for Each User/tty ComboCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

ACCESS CONTROL

6.3.10 Ensure Show Status Bar Is EnabledCIS Apple macOS 15.0 Sequoia v1.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.5.7 (L1) Ensure 'Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection' is set to 'Enabled: Enabled in enforcement mode'CIS Microsoft Windows 11 Enterprise v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

18.10.44.4 (L1) Ensure 'Allow files to download and save to the host operating system from Microsoft Defender Application Guard' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

Catalina - Disable Apple Filing Protocol SharingNIST macOS Catalina v1.5.0 - All ProfilesUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Apple Filing Protocol SharingNIST macOS Catalina v1.5.0 - CNSSI 1253Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Enforce Apple Mobile File IntegrityNIST macOS Catalina v1.5.0 - 800-53r5 HighUnix

SYSTEM AND INFORMATION INTEGRITY

Catalina - Enforce Apple Mobile File IntegrityNIST macOS Catalina v1.5.0 - All ProfilesUnix

SYSTEM AND INFORMATION INTEGRITY

CIS_Palo_Alto_Firewall_9_Benchmark_v1.1.0_L1.audit from CIS Palo Alto Firewall 9 Benchmark v1.1.0CIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto
CIS_Palo_Alto_Firewall_10_Benchmark_v1.2.0_L1.audit from CIS Palo Alto Firewall 10 Benchmark v1.2.0CIS Palo Alto Firewall 10 v1.2.0 L1Palo_Alto
Monterey - Enforce Enrollment in Mobile Device ManagementNIST macOS Monterey v1.0.0 - 800-53r5 HighUnix

CONFIGURATION MANAGEMENT