Item Search

NameAudit NamePluginCategory
1.1.6 Ensure separate partition exists for /varCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.6 Ensure separate partition exists for /varCIS Debian Family Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.10 Ensure separate partition exists for /varCIS Fedora 19 Family Linux Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.10 Ensure separate partition exists for /varCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.12 Ensure separate partition exists for /var/log/auditCIS Ubuntu Linux 18.04 LXD Host L2 Workstation v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.3.1 (L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'CIS Microsoft 365 Foundations v6.0.1 L1 E3microsoft_azure

IDENTIFICATION AND AUTHENTICATION

1.3.1 (L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'CIS Microsoft 365 Foundations v6.0.1 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

1.130 (L1) Ensure 'Standalone Sidebar Enabled' is set to 'Disabled'CIS Microsoft Intune for Edge v1.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.131 (L1) Ensure 'Standalone Sidebar Enabled' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

2.6.1.1 Audit iCloud KeychainCIS Apple macOS 11.0 Big Sur v4.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.1.1 Audit iCloud KeychainCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.1.2 Audit iCloud KeychainCIS Apple macOS 10.14 v2.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.2 iCloud keychainCIS Apple macOS 10.13 L2 v1.1.0Unix

ACCESS CONTROL

2.7 Ensure monitoring and alerting exist for SCIM token creationCIS Snowflake Foundations v1.0.0 L1Snowflake

AUDIT AND ACCOUNTABILITY

2.7.2 iCloud keychainCIS Apple macOS 10.12 L2 v1.2.0Unix

ACCESS CONTROL

4.1.9 Ensure upstream server traffic is authenticated with a client certificateCIS NGINX v3.0.0 L1 ProxyUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.9 Ensure upstream server traffic is authenticated with a client certificateCIS NGINX v3.0.0 L1 LoadbalancerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.2.2.1 (L1) Ensure multifactor authentication is enabled for all users in administrative rolesCIS Microsoft 365 Foundations v6.0.1 L1 E3microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.2.1 (L1) Ensure multifactor authentication is enabled for all users in administrative rolesCIS Microsoft 365 Foundations v6.0.1 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.3.2 Ensure that guest users are reviewed on a regular basisCIS Microsoft Azure Foundations v5.0.0 L1microsoft_azure

ACCESS CONTROL

5.4.3 Ensure clusters are created with Private Endpoint Enabled and Public Access DisabledCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.6.4 Ensure clusters are created with Private Endpoint Enabled and Public Access DisabledCIS Google Kubernetes Engine GKE v1.9.0 L2 GCPGCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.17 Use a Web-Tier ELB Security Group to accept only HTTP/HTTPSCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

8.1.5.2 Ensure Advanced Threat Protection Alerts for Storage Accounts Are MonitoredCIS Microsoft Azure Foundations v5.0.0 L2microsoft_azure

AUDIT AND ACCOUNTABILITY

8.3.10 Ensure that Azure Key Vault Managed HSM is used when requiredCIS Microsoft Azure Foundations v5.0.0 L2microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION

19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

AIOS-12-005600 - Apple iOS must not allow non-DoD applications to access DoD data.MobileIron - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-12-012600 - Apple iOS must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-12-012700 - Apple iOS must not allow unmanaged apps to read contacts from managed contacts accounts.MobileIron - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-012600 - Apple iOS/iPadOS must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-012700 - Apple iOS/iPadOS must not allow unmanaged apps to read contacts from managed contacts accounts.MobileIron - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-14-010700 - Apple iOS/iPadOS must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS/iPadOS 14 v1r3MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-15-012300 - Apple iOS/iPadOS 15 must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-012400 - Apple iOS/iPadOS 15 must not allow unmanaged apps to read contacts from managed contacts accounts.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-16-012300 - Apple iOS/iPadOS 16 must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-16-712300 - Apple iOS/iPadOS 16 must not allow managed apps to write contacts to unmanaged contacts accounts.AirWatch - DISA Apple iOS/iPadOS 16 BYOAD v1r2MDM

CONFIGURATION MANAGEMENT

AIOS-16-712300 - Apple iOS/iPadOS 16 must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS/iPadOS BYOAD 16 v1r2MDM

CONFIGURATION MANAGEMENT

AIOS-16-712400 - Apple iOS/iPadOS 16 must not allow unmanaged apps to read contacts from managed contacts accounts.AirWatch - DISA Apple iOS/iPadOS 16 BYOAD v1r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-012300 - Apple iOS/iPadOS 17 must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-712300 - Apple iOS/iPadOS 17 must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-712400 - Apple iOS/iPadOS 17 must not allow unmanaged apps to read contacts from managed contacts accounts.MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2MDM

CONFIGURATION MANAGEMENT

AIOS-18-012300 - Apple iOS/iPadOS 18 must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS/iPadOS 18 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-18-012400 - Apple iOS/iPadOS 18 must not allow unmanaged apps to read contacts from managed contacts accounts.MobileIron - DISA Apple iOS/iPadOS 18 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-26-012300 - Apple iOS/iPadOS 26 must not allow managed apps to write contacts to unmanaged contacts accounts.MobileIron - DISA Apple iOS/iPadOS 26 v1r2MDM

CONFIGURATION MANAGEMENT

CIS_Apple_macOS_12.0_Monterey_Cloud-tailored_v1.1.0_L1.audit from CIS Apple macOS 12.0 Monterey Cloud-tailored Benchmark v1.1.0CIS Apple macOS 12.0 Monterey Cloud-tailored v1.1.0 L1Unix
CIS_Apple_macOS_13.0_Ventura_Cloud-tailored_v1.1.0_L1.audit from CIS Apple macOS 13.0 Ventura Cloud-tailored Benchmark v1.1.0CIS Apple macOS 13.0 Ventura Cloud-tailored v1.1.0 L1Unix
CIS_Apple_macOS_13.0_Ventura_Cloud-tailored_v1.1.0_L2.audit from CIS Apple macOS 13.0 Ventura Cloud-tailored Benchmark v1.1.0CIS Apple macOS 13.0 Ventura Cloud-tailored v1.1.0 L2Unix
DTAM137 - McAfee VirusScan On-Access General Policies Artemis sensitivity level must be configured to medium or higher - ArtemisEnabledDISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

DTAM137 - McAfee VirusScan On-Access Scanner General Settings Artemis Heuristic network check for suspicious files must be enabled and set to sensitivity level Medium or higher - ArtemisEnabledDISA McAfee VirusScan 8.8 Local Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

SYMP-AG-000610 - Symantec ProxySG providing content filtering must detect use of network services that have not been authorized or approved by the ISSM and ISSO, at a minimum.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

SYSTEM AND INFORMATION INTEGRITY