Item Search

NameAudit NamePluginCategory
1.2 Ensure the container host has been HardenedCIS Docker Community Edition v1.1.0 L1 Linux Host OSUnix

CONFIGURATION MANAGEMENT

1.4 Harden the container hostCIS Docker 1.6 v1.0.0 L1 LinuxUnix

CONFIGURATION MANAGEMENT

2.2.4.7.5 Ensure 'Turn off file validation' is set to 'Disabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

2.2.14 Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.14 Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.14 Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.14 Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.14 Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.14 Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 NGWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.16 Ensure 'Deny log on as a batch job' to include 'Guests'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.16 Ensure 'Deny log on as a batch job' to include 'Guests'CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.16 Ensure 'Deny log on as a batch job' to include 'Guests'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.16 Ensure 'Deny log on as a batch job' to include 'Guests'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 (L1) Ensure 'Debug programs' is set to 'Administrators'CIS Windows Server 2012 R2 DC L1 v3.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.2.19 (L1) Ensure 'Debug programs' is set to 'Administrators'CIS Windows Server 2012 R2 MS L1 v3.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.2.19 (L1) Ensure 'Debug programs' is set to 'Administrators'CIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MSWindows

SYSTEM AND INFORMATION INTEGRITY

2.2.19 (L1) Ensure 'Debug programs' is set to 'Administrators'CIS Windows Server 2012 MS L1 v3.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.2.19 (L1) Ensure 'Debug programs' is set to 'Administrators'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DCWindows

SYSTEM AND INFORMATION INTEGRITY

2.2.19 Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.20 (L1) Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows Server 2016 v4.0.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.20 (L1) Ensure 'Debug programs' is set to 'Administrators'CIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.21 (L1) Ensure 'Deny log on as a batch job' to include 'Guests'CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

2.2.22 (L1) Ensure 'Deny log on as a batch job' to include 'Guests'CIS Windows Server 2012 DC L1 v3.0.0Windows

ACCESS CONTROL

2.2.22 (L1) Ensure 'Deny log on as a batch job' to include 'Guests'CIS Microsoft Windows Server 2008 R2 Domain Controller Level 1 v3.3.1Windows

ACCESS CONTROL

2.2.22 (L1) Ensure 'Deny log on as a batch job' to include 'Guests'CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

2.2.22 Ensure 'Deny log on as a batch job' to include 'Guests'CIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.5.4.1 Ensure 'Do not allow Home Page URL to be set in folder Properties' is set to 'Enabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

CONFIGURATION MANAGEMENT

2.11.8.7.4 Ensure 'Turn off file validation' is set to 'Disabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

5.1 Ensure that WildFire file size upload limits are maximizedCIS Palo Alto Firewall 11 v1.2.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.1 Ensure that WildFire file size upload limits are maximizedCIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.1.2.1 Ensure 'Per-user MFA' is disabledCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

CONFIGURATION MANAGEMENT

18.3.1 (L1) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled' (MS only)CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

18.4.1 (L1) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL

18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOLCIS Microsoft Windows 8.1 v2.4.1 L1Windows

RISK ASSESSMENT

18.9.7.1.2 Ensure 'Prevent installation of devices that match any of these device IDs: Prevent installation of devices that match any of these device IDs' is set to 'PCI\CC_0C0A'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BLWindows

MEDIA PROTECTION

18.9.38.2 Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated' (MS only)CIS Microsoft Windows Server 2019 v5.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.9.38.2 Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated' (MS only)CIS Microsoft Windows Server 2025 v2.1.0 L2 MSWindows

CONFIGURATION MANAGEMENT

CIS_NGINX_v3.0.0_L1_Loadbalancer.audit from CIS NGINX 3.0.0CIS NGINX v3.0.0 L1 LoadbalancerUnix
CIS_NGINX_v3.0.0_L2_Proxy.audit from CIS NGINX 3.0.0CIS NGINX v3.0.0 L2 ProxyUnix
CIS_NGINX_v3.0.0_L2_Webserver.audit from CIS NGINX 3.0.0CIS NGINX v3.0.0 L2 WebserverUnix
Require that application add-ins are signed by Trusted Publisher - requireaddinsig - ms projectMSCT Microsoft 365 Apps for Enterprise 2112 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Require that application add-ins are signed by Trusted Publisher - requireaddinsig - ms projectMicrosoft 365 Apps for Enterprise 2306 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

WN22-MS-000120 - Windows Server 2022 Deny log on through Remote Desktop Services user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems.DISA Microsoft Windows Server 2022 STIG v2r10Windows

ACCESS CONTROL

WN22-MS-000120 - Windows Server 2022 Deny log on through Remote Desktop Services user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL

WN22-MS-000130 - Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL

WN22-MS-000130 - Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems.DISA Microsoft Windows Server 2022 STIG v2r10Windows

ACCESS CONTROL

WN25-MS-000040 - Windows Server 2025 must restrict unauthenticated Remote Procedure Call (RPC) clients from connecting to the RPC server on domain-joined member servers and stand-alone or nondomain-joined systems.DISA Microsoft Windows Server 2025 STIG v1r1Windows

IDENTIFICATION AND AUTHENTICATION

WN25-MS-000060 - Windows Server 2025 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and stand-alone or nondomain-joined systems.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL

WN25-MS-000130 - The Windows Server 2025 'Enable computer and user accounts to be trusted for delegation' user right must not be assigned to any groups or accounts on domain-joined member servers and stand-alone or nondomain-joined systems.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL