Item Search

NameAudit NamePluginCategory
2.1 Ensure 'Ad Hoc Distributed Queries' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Ensure 'Ad Hoc Distributed Queries' Server Configuration Option is set to '0'CIS SQL Server 2017 Database L1 AWS RDS v1.3.0MS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Ensure 'Ad Hoc Distributed Queries' Server Configuration Option is set to '0'CIS SQL Server 2017 Database L1 DB v1.3.0MS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Ensure 'Ad Hoc Distributed Queries' Server Configuration Option is set to '0'CIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.13 Ensure the 'sa' Login Account is set to 'Disabled'CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

2.13 Ensure the 'sa' Login Account is set to 'Disabled'CIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

2.13 Ensure the 'sa' Login Account is set to 'Disabled'CIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

2.13 Ensure the 'sa' Login Account is set to 'Disabled'CIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

2.13 Ensure the 'sa' Login Account is set to 'Disabled'CIS Microsoft SQL Server 2025 v1.0.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

2.14 Ensure the 'sa' Login Account has been renamedCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.1 Ensure Security Auditing Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.1 Ensure Security Auditing Is EnabledCIS Apple macOS 26 Tahoe v1.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.1 Ensure Security Auditing Is EnabledCIS Apple macOS 15.0 Sequoia Cloud-tailored v1.0.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.1 Ensure Security Auditing Is EnabledCIS Apple macOS 15.0 Sequoia v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.2 Ensure CONNECT permissions on the 'guest' user is Revoked within all SQL Server databasesCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

3.3 Ensure Auto-Scaling Launch Configuration for Web-Tier is configured to use an approved Amazon Machine ImageCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

CONFIGURATION MANAGEMENT

3.4 Ensure Auto-Scaling Launch Configuration for App-Tier is configured to use an approved Amazon Machine ImageCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

CONFIGURATION MANAGEMENT

3.127 - IPSec Exemptions are limited.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

4.6 Ensure that a log metric filter for the Cloudwatch group assigned to the "VPC Flow Logs" is createdCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

AUDIT AND ACCOUNTABILITY

5.1 Ensure unauthorized API calls are monitoredCIS Amazon Web Services Foundations v7.0.0 L2amazon_aws

AUDIT AND ACCOUNTABILITY

5.8 Ensure an agent for AWS Cloudwatch Logs is installed within Auto-Scaling Group for Web-TierCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

AUDIT AND ACCOUNTABILITY

6.1.1 Audit Show All Filename ExtensionsCIS Apple macOS 15.0 Sequoia v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.1 Audit Show All Filename ExtensionsCIS Apple macOS 26 Tahoe v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.1 Audit Show All Filename ExtensionsCIS Apple macOS 13.0 Ventura v4.0.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.1 Audit Show All Filename ExtensionsCIS Apple macOS 14.0 Sonoma v3.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.1 Ensure EBS volume encryption is enabled in all regionsCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.2 Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration portsCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.32 Ensure Auto-Scaling Launch Configuration for Web Tier is configured to use the Web Tier Security GroupCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

ACCESS CONTROL

7.6 Ensure that the swarm manager auto-lock key is rotated periodicallyCIS Docker v1.8.0 L1 Docker SwarmUnix

IDENTIFICATION AND AUTHENTICATION

8.1.11 Ensure that non-deprecated Microsoft Cloud Security Benchmark policies are not set to 'Disabled'CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

ARBA-VN-000721 - The Remote Access VPN Gateway must terminate remote access network connections after an organization-defined time period.DISA HPE Aruba Networking AOS VPN STIG v1r1ArubaOS

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-002440 - Amazon Linux 2023 must restrict the use of the "su" command.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL

ESXI-70-000091 - The ESXi host must be configured with an appropriate maximum password age.DISA VMware vSphere 7.0 ESXi STIG v1r4 VMwareVMware

CONFIGURATION MANAGEMENT

ESXI-80-000227 - The ESXi host must be configured with an appropriate maximum password age.DISA VMware vSphere 8.0 ESXi STIG v2r4 VMwareVMware

CONFIGURATION MANAGEMENT

ESXI-80-000227 - The ESXi host must be configured with an appropriate maximum password age.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

CONFIGURATION MANAGEMENT

ESXi: esxi-8.api-soap-timeoutVMware vSphere Security Configuration and Hardening GuideVMware

CONFIGURATION MANAGEMENT

ESXi: esxi-8.host-client-session-timeoutVMware vSphere Security Configuration and Hardening GuideVMware

ACCESS CONTROL

ESXi: esxi-8.timekeeping-sourcesVMware vSphere Security Configuration and Hardening GuideVMware

AUDIT AND ACCOUNTABILITY

RHEV: Clusters Memory BalooningTenable RedHat Enterprise VirtualizationRHEV
RHEV: Hosts - Update requiredTenable RedHat Enterprise VirtualizationRHEV
RHEV: Storage Domains - Backup storageTenable RedHat Enterprise VirtualizationRHEV
RHEV: VMs copy/paste featureTenable RedHat Enterprise VirtualizationRHEV
RHEV: VMs file transfer featureTenable RedHat Enterprise VirtualizationRHEV
Routing Protocol Security - Periodically change route authentication keys in accordance with your organization's security policyJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

Routing Protocol Security - Select the strongest algorithm that is supported by your equipment and your neighbors - BGPJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Routing Protocol Security - Select the strongest algorithm that is supported by your equipment and your neighbors - OSPFJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Routing Protocol Security - Select the strongest algorithm that is supported by your equipment and your neighbors - RIPJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

SQL2-00-010400 - SQL Server auditing configuration maximum file size must be configured to reduce the likelihood of storage capacity being exceeded, while meeting organization-defined auditing requirements - 'max_files'DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

AUDIT AND ACCOUNTABILITY

SQL2-00-010400 - SQL Server auditing configuration maximum file size must be configured to reduce the likelihood of storage capacity being exceeded, while meeting organization-defined auditing requirements - 'max_size'DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

AUDIT AND ACCOUNTABILITY

WBSP-AS-001080 - The WebSphere Application Server must provide security extensions to extend the SOAP protocol and provide secure authentication when accessing sensitive data.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION