Item Search

NameAudit NamePluginCategory
1.12 Ensure 'Smart Lock' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L2MDM

ACCESS CONTROL

1.12 Ensure 'Smart Lock' is set to 'Disabled'AirWatch - CIS Google Android v1.6.0 L2MDM

ACCESS CONTROL

1.20 Ensure an account-level authentication policy has been configured to restrict allowed provider accounts for Workload Identify Federation (WIF)CIS Snowflake Foundations v2.0.0 L2Snowflake

IDENTIFICATION AND AUTHENTICATION

1.24 CISC-ND-001410CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT IICisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

1.24 EX19-ED-000113CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.37 EX19-MB-000128CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.39 CISC-ND-001410CIS Cisco NX OS Switch NDM STIG v1.1.0 CAT IICisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

1.161 SOL-11.1-070060CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.1.3 Ensure Organizations management account is not used for workloadsCIS Amazon Web Services Foundations v7.0.0 L2amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

2.3.3.9 Ensure Media Sharing Is DisabledCIS Apple macOS 26 Tahoe v1.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.7 Lock Out Accounts if Not Currently in UseCIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL

2.7 Lock Out Accounts if Not Currently in UseCIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.8 Ensure IAM password policy requires minimum length of 14 or greaterCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

IDENTIFICATION AND AUTHENTICATION

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L2 MySQL RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Community Server 8.0 v1.2.0 L2 MySQL RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Community Server 8.4 v1.1.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L2 MySQL RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Enterprise Edition 8.4 v1.1.0 L2 MySQL RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Community Server 9.7 v1.0.0 L2 MySQL RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL

2.11 Lock Out Accounts if Not Currently in UseCIS Oracle MySQL Enterprise Edition 8.4 v1.1.0 L2 MySQL RDBMS MySQLDBMySQLDB

ACCESS CONTROL

2.16 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databasesCIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

CONFIGURATION MANAGEMENT

2.18 Ensure that IAM External Access Analyzer is enabled for all regionsCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

ACCESS CONTROL, MEDIA PROTECTION

3.2.1 Ensure that encryption-at-rest is enabled for RDS instancesCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2 Ensure CloudTrail log file validation is enabledCIS Amazon Web Services Foundations v7.0.0 L2amazon_aws

AUDIT AND ACCOUNTABILITY

5.7 Ensure disabling or scheduled deletion of customer created CMKs is monitoredCIS Amazon Web Services Foundations v7.0.0 L2amazon_aws

AUDIT AND ACCOUNTABILITY

5.11 Ensure Network Access Control List (NACL) changes are monitoredCIS Amazon Web Services Foundations v7.0.0 L2amazon_aws

AUDIT AND ACCOUNTABILITY

6.1 Ensure Root Domain Alias Record Points to ELBCIS Amazon Web Services Three-tier Web Architecture L2 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

6.17 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actionsCIS Palo Alto Firewall 10 v1.3.0 L1Palo_Alto

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.18 Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actionsCIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto

ACCESS CONTROL, CONFIGURATION MANAGEMENT

6.27 Ensure EC2 instances within Web Tier have no Elastic / Public IP addresses associatedCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

6.29 Ensure EC2 instances within Data Tier have no Elastic / Public IP addresses associatedCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

9.23 Find Un-owned Files and DirectoriesCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

9.24 Find Files and Directories with Extended AttributesCIS Solaris 11.2 L1 v1.1.0Unix
9.24 Find Un-owned Files and DirectoriesCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

9.24 Find Un-owned Files and DirectoriesCIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL

DTAM100 - McAfee VirusScan On-Access Default Processes Policies must be configured to use only one scanning policy for all processes, unless the use of Low-Risk Processes/High-Risk Processes has been documented with, and approved by, the IAO/IAM.DISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

DTAM100 - McAfee VirusScan On-Access Scanner All Processes settings must be configured to use only one scanning policy for all processes, unless the use of Low-Risk Processes/High-Risk Processes has been documented with, and approved by, the IAO/IAM.DISA McAfee VirusScan 8.8 Local Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

Maximum password ageMSCT Windows 10 v1507 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Maximum password ageMSCT Windows 10 1803 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Maximum password ageMSCT Windows 10 1809 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Maximum password ageMSCT Windows Server 2012 R2 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Maximum password ageMSCT Windows Server 2019 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Maximum password ageMSCT Windows Server 2019 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Maximum password ageMSCT Windows Server 2012 R2 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Maximum password ageMSCT Windows Server 2016 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Maximum password ageMSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-070060 - Groups assigned to users must exist in the /etc/group file.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT