Item Search

NameAudit NamePluginCategory
1.1 Set 'Allow software to run or install even if the signature is invalid' to 'Disabled'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.1.2 Ensure mounting of freevxfs filesystems is disabledCIS Amazon Linux v2.1.0 L2Unix

CONFIGURATION MANAGEMENT

1.1.3 Configure Secure Password Policy - EnsurePassword MemoryCIS F5 Networks v1.0.0 L1F5

IDENTIFICATION AND AUTHENTICATION

1.1.3 Configure Secure Password Policy - Maximum DurationCIS F5 Networks v1.0.0 L1F5

IDENTIFICATION AND AUTHENTICATION

1.1.3 Configure Secure Password Policy - Required NumericCIS F5 Networks v1.0.0 L1F5

IDENTIFICATION AND AUTHENTICATION

1.1.3 Configure Secure Password Policy - User LockoutCIS F5 Networks v1.0.0 L1F5

IDENTIFICATION AND AUTHENTICATION

1.2 Set 'Prevent Bypassing SmartScreen Filter Warnings' to 'Enabled'CIS IE 9 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

1.3 Enable 'Prevent users from bypassing SmartScreen Filter's application reputation warnings about files that are not commonly downloaded'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.6.1.1 Ensure SELinux is not disabled in bootloader configuration - selinux = 0CIS Amazon Linux v2.1.0 L2Unix

ACCESS CONTROL

1.6.2 Ensure SELinux is installedCIS Amazon Linux v2.1.0 L2Unix

ACCESS CONTROL

2.1 Ensure that Remote Radius is used for Authentication OnlyCIS F5 Networks v1.0.0 L2F5

ACCESS CONTROL

2.4 Ensure External Users' role is set to 'No Access'CIS F5 Networks v1.0.0 L2F5

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.1.1.2 Ensure system is disabled when audit logs are full - 'action_mail_acct is configured'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.4 Ensure events that modify date and time information are collected - adjtimexCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.4 Ensure events that modify date and time information are collected - time-changeCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - auditctl setxattr/lsetxattr/fsetxattr/removexattrCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - auditctl b64 EPERMCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - b64 EPERMCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.13 Ensure successful file system mounts are collected - mountsCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure file deletion events by users are collected - auditctlCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure file deletion events by users are collected - b64CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - auditctl init_module/delete_moduleCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - auditctl insmodCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - rmmodCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.18 Ensure the audit configuration is immutableCIS Amazon Linux v2.1.0 L2Unix

CONFIGURATION MANAGEMENT

4.2 Ensure 'Idle timeout' is less than or equal to 10 minutes for SSH connectionsCIS F5 Networks v1.0.0 L1F5

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.4 Ensure 'Idle timeout' is less than or equal to 10 minutes for serial console sessionsCIS F5 Networks v1.0.0 L1F5

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.2 Ensure minimum SNMP version is set to V3 for agent accessCIS F5 Networks v1.0.0 L1F5

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

7.1 Set 'Restrict File Download' to 'Enabled' - explorer.exeCIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

7.2 Set 'Notification bar' to 'Enabled' -explorer.exeCIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

7.4 Set 'Consistent Mime Handling' to 'Enabled' - iexplore.exeCIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

7.8 Set 'MK Protocol Security Restriction' to 'Enabled' - explorer.exeCIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

8.1.2 Set 'Allow drag and drop or copy and paste files' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

8.1.6 Set 'Allow script- initiated windows without size or position constraints' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

8.1.8 Set 'Download signed ActiveX controls' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

8.1.9 Set 'Download unsigned ActiveX controls' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

8.2.1 Set 'Intranet Sites: Include all network paths (UNCs)' to 'Disabled'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

8.3.5 Set 'Allow file downloads' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

8.3.11 Set 'Automatic prompting for file downloads' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

8.3.12 Set 'Download signed ActiveX controls' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.15 Set 'Initialize and script ActiveX controls not marked as safe' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.22 Set 'Run .NET Framework- reliant components signed with Authenticode' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.26 Set 'Software channel permissions' to 'Enabled:High safety'CIS IE 9 v1.0.0Windows

ACCESS CONTROL

8.3.29 Set 'Web sites in less privileged Web content zones can navigate into this zone' to 'Enabled:Disable'CIS IE 9 v1.0.0Windows

ACCESS CONTROL

8.4.1 Set 'Use SmartScreen Filter' to 'Enabled:Enable'CIS IE 9 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

8.7.2 Set 'Use SmartScreen Filter' to 'Enabled:Enable'CIS IE 9 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

8.11 Set 'Security Zones: Use only machine settings' to 'Enabled'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

9.2 Set 'Disable the Advanced page' to 'Enabled'CIS IE 11 v1.0.0Windows

CONFIGURATION MANAGEMENT

9.14 Set 'Turn on the auto-complete feature for user names and passwords on forms' to 'Disabled'CIS IE 11 v1.0.0Windows

CONFIGURATION MANAGEMENT

9.15 Set 'Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows' to 'Enabled'CIS IE 11 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION