Item Search

NameAudit NamePluginCategory
1.1.3 Ensure 'Enable Log on High DP Load' is enabledCIS Palo Alto Firewall 10 v1.3.0 L1Palo_Alto

AUDIT AND ACCOUNTABILITY

1.1.3 Ensure 'Enable Log on High DP Load' is enabledCIS Palo Alto Firewall 11 v1.2.0 L1Palo_Alto

AUDIT AND ACCOUNTABILITY

1.2 Use Dedicated Least Privileged Account for MySQL Daemon/ServiceCIS MySQL 5.6 Community Linux OS L1 v2.0.0Unix

ACCESS CONTROL

1.2.4 Disable the rhnsd DaemonCIS Red Hat Enterprise Linux 5 L2 v2.2.1Unix

SYSTEM AND INFORMATION INTEGRITY

1.50 EX19-MB-000146CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

2.5 Do not use the aufs storage driverCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

2.5 Do not use the aufs storage driverCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

2.5 Do not use the aufs storage driverCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

2.5 Ensure aufs storage driver is not usedCIS Docker Community Edition v1.1.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

2.6 Ensure Password Complexity is Configured - validate_password_mixed_case_countCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.6 Ensure Password Complexity is Configured - validate_password_policyCIS MySQL 5.6 Community Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.6 Ensure Password Complexity is Configured - validate_password_special_char_countCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.7 Ensure Password Complexity is Configured - validate_password_dictionary_fileCIS MySQL 5.7 Community Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.7 Ensure Password Complexity is Configured - validate_password_lengthCIS MySQL 5.7 Enterprise Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.7 Ensure Password Complexity is Configured - validate_password_number_countCIS MySQL 5.7 Community Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.7 Ensure Password Complexity is Configured - validate_password_number_countCIS MySQL 5.7 Enterprise Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.7 Ensure Password Complexity is Configured - validate_password_policyCIS MySQL 5.7 Enterprise Database L1 v2.0.0MySQLDB

IDENTIFICATION AND AUTHENTICATION

2.9 Ensure Legacy EFI Is Valid and Updating - validCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

SYSTEM AND SERVICES ACQUISITION

2.14 Ensure 'sa' Login Account is set to 'Disabled'CIS SQL Server 2008 R2 DB Engine L1 v1.7.0MS_SQLDB

ACCESS CONTROL

5.1.5 Ensure No World Writable Files Exist in the System FolderCIS Apple macOS 12.0 Monterey Cloud-tailored v1.1.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

5.1.6 Ensure No World Writable Folders Exist in the System FolderCIS Apple macOS 15.0 Sequoia v2.1.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

5.1.6 Ensure No World Writable Folders Exist in the System FolderCIS Apple macOS 26 Tahoe v1.1.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

5.1.6 Ensure No World Writable Folders Exist in the System FolderCIS Apple macOS 13.0 Ventura v4.0.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

5.1.6 Ensure No World Writable Folders Exist in the System FolderCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

ACCESS CONTROL, MEDIA PROTECTION

6.1 Perform regular security audits of your host system and containersCIS Docker 1.12.0 v1.0.0 L1 DockerUnix
6.1 Perform regular security audits of your host system and containersCIS Docker 1.11.0 v1.0.0 L1 DockerUnix
7.2 Ensure Asymmetric Key Size is set to 'greater than or equal to 2048' in non-system databasesCIS SQL Server 2017 Database L1 DB v1.3.0MS_SQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Ensure Asymmetric Key Size is set to 'greater than or equal to 2048' in non-system databasesCIS SQL Server 2017 Database L1 AWS RDS v1.3.0MS_SQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

11.2 Ensure Apache Processes Run in the httpd_t Confined Context - httpdCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v128 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v136 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v142 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v151 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v132 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v134 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v137 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v127 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v133 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v135 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v138 v1.0.0Windows
Automatically open downloaded MHT or MHTML files from the web in Internet Explorer modeMSCT Edge v139 v1.0.0Windows
CASA-FW-000290 - The Cisco ASA must be configured to restrict it from accepting outbound packets that contain an illegitimate address in the source address field via an egress filter or by enabling Unicast Reverse Path Forwarding (uRPF) - ACLDISA STIG Cisco ASA FW v2r1Cisco

CONFIGURATION MANAGEMENT

CASA-FW-000290 - The Cisco ASA must be configured to restrict it from accepting outbound packets that contain an illegitimate address in the source address field via an egress filter or by enabling Unicast Reverse Path Forwarding (uRPF) - network-objectDISA STIG Cisco ASA FW v2r1Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000310 - The Cisco perimeter switch must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA Cisco NX OS Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000480 - The Exchange tarpitting interval must be set.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-ED-000135 - The Exchange tarpitting interval must be set.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

SQL6-D0-018200 - Applications must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

WA000-WWA050 W22 - All interactive programs must be placed in a designated directory with appropriate permissions. - 'AddHandler'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WA000-WWA050 W22 - All interactive programs must be placed in a designated directory with appropriate permissions. - 'SetHandler'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG170 IIS6 - Each readable web document directory must contain a default, home, index or equivalent file. - 'DefaultDoc'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT