Item Search

NameAudit NamePluginCategory
1.1.2 Ensure separate partition exists for /tmpCIS SUSE Linux Enterprise Server 11 L2 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.2 Ensure separate partition exists for /tmpCIS SUSE Linux Enterprise Workstation 11 L2 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.12 Ensure separate partition exists for /var/log/auditCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.12 Ensure separate partition exists for /var/log/auditCIS Debian Family Workstation L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.16 Ensure separate partition exists for /var/log/auditCIS Fedora 19 Family Linux Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.16 Ensure separate partition exists for /var/log/auditCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.2 Ensure Snowflake SCIM integration is configured to automatically provision and deprovision users and groups (i.e. roles)CIS Snowflake Foundations v1.0.0 L2Snowflake

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 Ensure 'Deny log on through Remote Desktop Services' is set to 'Guests'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 Ensure 'Deny log on through Remote Desktop Services' to include 'Guests, Local account'CIS Microsoft Windows 11 Enterprise v5.0.1 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 Ensure 'Deny log on through Remote Desktop Services' to include 'Guests, Local account'CIS Microsoft Windows 11 Enterprise v5.0.1 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 Ensure 'Deny log on through Remote Desktop Services' to include 'Guests'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.9.4 Ensure Writing Tools Is DisabledAirWatch - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.9.4 Ensure Writing Tools Is DisabledMobileIron - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.10.4 Ensure Writing Tools Is DisabledAirWatch - CIS Apple iOS 26 v1.0.0 L1 Institution OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.1.1 Secure Home FoldersCIS Apple OSX 10.9 L1 v1.3.0Unix

CONFIGURATION MANAGEMENT

5.1.2 Minimize user access to Container Image repositoriesCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

5.1.2 Minimize user access to Container Image repositoriesCIS Google Kubernetes Engine GKE v1.9.0 L2 GCPGCP

ACCESS CONTROL, MEDIA PROTECTION

5.1.3 Minimize cluster access to read-only for Container Image repositoriesCIS Google Kubernetes Engine GKE v1.9.0 L2 GCPGCP

ACCESS CONTROL, MEDIA PROTECTION

5.1.3 Minimize cluster access to read-only for Container Image repositoriesCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

5.1.4.1 (L2) Ensure the ability to join devices to Entra is restrictedCIS Microsoft 365 Foundations v6.0.1 L2 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.1 (L2) Ensure the ability to join devices to Entra is restrictedCIS Microsoft 365 Foundations v6.0.1 L2 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.5.2 (L1) Ensure the admin consent workflow is enabledCIS Microsoft 365 Foundations v6.0.1 L1 E3microsoft_azure

CONFIGURATION MANAGEMENT

5.1.5.2 (L1) Ensure the admin consent workflow is enabledCIS Microsoft 365 Foundations v6.0.1 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

5.1.8.1 (L1) Ensure that password hash sync is enabled for hybrid deploymentsCIS Microsoft 365 Foundations v6.0.1 L1 E5microsoft_azure

ACCESS CONTROL

5.2.1 Ensure GKE clusters are not running using the Compute Engine default service accountCIS Google Kubernetes Engine GKE Autopilot v1.3.0 L2GCP

IDENTIFICATION AND AUTHENTICATION

5.2.1 Ensure GKE clusters are not running using the Compute Engine default service accountCIS Google Kubernetes Engine GKE v1.9.0 L1 GCPGCP

IDENTIFICATION AND AUTHENTICATION

5.2.2.5 (L2) Ensure 'Phishing-resistant MFA strength' is required for AdministratorsCIS Microsoft 365 Foundations v6.0.1 L2 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

6.20 Ensure Web tier Security Group has no inbound rules for CIDR of 0 (Global Allow)CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

6.21 Create the App tier ELB Security Group and ensure only accepts HTTP/HTTPSCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

6.23 Ensure App tier Security Group has no inbound rules for CIDR of 0 (Global Allow)CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

6.25 Ensure Data tier Security Group has no inbound rules for CIDR of 0 (Global Allow)CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

7.3.2 (L2) Ensure OneDrive sync is restricted for unmanaged devicesCIS Microsoft 365 Foundations v6.0.1 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT

7.3.2 (L2) Ensure OneDrive sync is restricted for unmanaged devicesCIS Microsoft 365 Foundations v6.0.1 L2 E5microsoft_azure

CONFIGURATION MANAGEMENT

10.1 Ensure SELinux Is Enabled in Enforcing Mode - config fileCIS BIND DNS v1.0.0 L2 Caching Only Name ServerUnix

ACCESS CONTROL

10.1 Ensure SELinux Is Enabled in Enforcing Mode - config fileCIS BIND DNS v1.0.0 L2 Authoritative Name ServerUnix

ACCESS CONTROL

10.1 Ensure SELinux Is Enabled in Enforcing Mode - current modeCIS BIND DNS v1.0.0 L2 Caching Only Name ServerUnix

ACCESS CONTROL

10.1 Ensure SELinux Is Enabled in Enforcing Mode - current modeCIS BIND DNS v1.0.0 L2 Authoritative Name ServerUnix

ACCESS CONTROL

19.7.8.3 (L1) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L2 BL NGWindows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows Server 2019 v4.0.0 L2 DCWindows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L2 BL NGWindows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L2 NGWindows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

19.7.8.3 (L2) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows Server 2025 Stand-alone v1.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

19.7.8.3 Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.0.0 L2 DCWindows

CONFIGURATION MANAGEMENT

O365-OU-000006 - The junk email protection level must be set to No Automatic Filtering.DISA STIG Microsoft Office 365 ProPlus v3r4Windows

CONFIGURATION MANAGEMENT