Item Search

NameAudit NamePluginCategory
1.1.2 Ensure only trusted users are allowed to control Docker daemonCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.4.1.1 Ensure 'aaa local authentication max failed attempts' is set to less than or equal to '3'CIS Cisco ASA 9.x Firewall L1 v1.1.0Cisco

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.2.12 Ensure 'SSL_CERT_REVOCATION' Is Set To 'REQUIRED'CIS Oracle Database 23ai v1.1.0 L1 RDBMS On Linux Host OS UnixUnix

ACCESS CONTROL

2.2.12 Ensure 'SSL_CERT_REVOCATION' Is Set To 'REQUIRED'CIS Oracle Database 23ai v1.1.0 L1 RDBMS On Windows Server Host OS WindowsWindows

ACCESS CONTROL

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.23 Benchmark v1.0.1 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v1.24 Benchmark v1.0.0 L2 MasterUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.7 Ensure that a unique Certificate Authority is used for etcdCIS Kubernetes v2.0.1 L2 Master NodeUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.15 Ensure containers are restricted from acquiring new privilegesCIS Docker v1.8.0 L1 OS LinuxUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.20 Ensure access to AWSCloudShellFullAccess is restrictedCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

4.1.8 Avoid binding RBAC roles to unauthenticated users and groupsCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

4.3 (L1) Ensure the maximum failed login attempts is set to 5CIS VMware ESXi 7.0 v1.5.0 L1VMware

ACCESS CONTROL

4.4.2.1.2 Ensure password failed attempts lockout is configuredCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

ACCESS CONTROL

4.4.2.1.4 Ensure password failed attempts lockout includes root accountCIS CentOS Linux 7 v4.0.0 L2 ServerUnix

ACCESS CONTROL

5.1.6.1 Ensure that collaboration invitations are sent to allowed domains onlyCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.6.1 Ensure that collaboration invitations are sent to allowed domains onlyCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.2.2.2 Ensure pam_faillock module is enabledCIS Linux Mint 22 v1.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.3.2 Ensure system accounts are securedCIS Google Container-Optimized OS v1.2.0 L2 ServerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.3.2.1.1 Ensure password failed attempts lockout is configuredCIS AlmaLinux OS 10 v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.2.1.2 Ensure password unlock time is configuredCIS Rocky Linux 10 v1.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.3.2.1.3 Ensure password failed attempts lockout includes root accountCIS Rocky Linux 10 v1.0.0 L2 WorkstationUnix

ACCESS CONTROL

5.3.2.1.3 Ensure password failed attempts lockout includes root accountCIS SUSE Linux Enterprise 15 v2.0.1 L2 ServerUnix

ACCESS CONTROL

5.3.2.1.3 Ensure password failed attempts lockout includes root accountCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Red Hat Enterprise Linux 8 v4.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Rocky Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.1 Ensure password failed attempts lockout is configuredCIS AlmaLinux OS 8 v4.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS Debian Linux 13 v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS Rocky Linux 9 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.2 Ensure password unlock time is configuredCIS AlmaLinux OS 9 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.3.1.3 Ensure password failed attempts lockout includes root accountCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 WorkstationUnix

ACCESS CONTROL

5.3.3.1.3 Ensure password failed attempts lockout includes root accountCIS AlmaLinux OS 8 v4.0.0 L2 ServerUnix

ACCESS CONTROL

5.3.3.1.3 Ensure password failed attempts lockout includes root accountCIS AlmaLinux OS 8 v4.0.0 L2 WorkstationUnix

ACCESS CONTROL

5.3.4 Ensure approval is required for Global Administrator role activationCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.3.5 Ensure approval is required for Privileged Role Administrator activationCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.5.2 Ensure lockout for failed password attempts is configuredCIS Fedora 28 Family Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Debian 8 Server L1 v2.0.2Unix

ACCESS CONTROL

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Debian 8 Workstation L1 v2.0.2Unix

ACCESS CONTROL

7.1 Ensure authentication file permissions are set correctlyCIS MongoDB 3.6 L1 Unix Audit v1.1.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

7.1 Ensure authentication file permissions are set correctlyCIS MongoDB 3.6 L1 Windows Audit v1.1.0Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

8.3.1 Ensure that the Expiration Date is Set for all Keys in Key Vaults using RBACCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

8.3.2 Ensure that the Expiration Date is set for All Keys in Key Vaults using access policies (legacy)CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

8.3.3 Ensure that the Expiration Date is set for All Secrets in Key Vaults using RBACCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

8.3.4 Ensure that the Expiration Date is set for All Secrets in Key Vaults using access policies (legacy)CIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

9.2 Check for Duplicate User NamesCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL

9.3.1.2 Ensure That Storage Account Access keys are Periodically RegeneratedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MAINTENANCE

9.13 Check Groups in passwdCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL