Item Search

NameAudit NamePluginCategory
1.1 Use the Latest OS Release - Check if Solaris 10 10/09 release is installedCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

1.3 Install Solaris Encryption Kit - Check if Package SUNWcry is installedCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

1.3.3 (L2) Ensure 'Control use of JavaScript JIT' is set to 'Enabled: Do not allow any site to run JavaScript JIT'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.3.9 (L1) Ensure 'Default geolocation setting' is set to 'Enabled: Don't allow any site to track users' physical location'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.8.2 (L2) Ensure 'Configure extension management settings' is set to 'Enabled: *'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.16 Ensure that Snowflake stored procedures are not owned by the ACCOUNTADMIN or SECURITYADMIN rolesCIS Snowflake Foundations v1.0.0 L1Snowflake

ACCESS CONTROL

1.25.3 (L1) Ensure 'Enable Microsoft Defender SmartScreen DNS requests' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.29 (L2) Ensure 'Allow features to download assets from the Asset Delivery Service' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.39 (L1) Ensure 'Allow managed extensions to use the Enterprise Hardware Platform API' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.44 (L1) Ensure 'Allow queries to a Browser Network Time service' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

AUDIT AND ACCOUNTABILITY

1.46 (L1) Ensure 'Allow the audio sandbox to run' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.51 (L2) Ensure 'Allow users to proceed from the HTTPS warning page' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.53 (L2) Ensure 'AutoLaunch Protocols Component Enabled' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.54 (L1) Ensure 'Automatically import another browser's data and settings at first run' is set to 'Enabled: Disables automatic import, and the import section of the first-run experience is skipped'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.55 (L1) Ensure 'Automatically open downloaded MHT or MHTML files from the web in Internet Explorer mode' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.58 (L2) Ensure 'Browser sign-in settings' is set to 'Enabled: Disable browser sign-in'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.61 (L1) Ensure 'Clear history for IE and IE mode every time you exit' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.67 (L2) Ensure 'Configure Speech Recognition' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.68 (L1) Ensure 'Configure the list of names that will bypass the HSTS policy check' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.70 (L1) Ensure 'Configure the Share experience' is set to 'Enabled: Don't allow using the Share experience'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.85 (L1) Ensure 'Enable AutoFill for payment instructions' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.87 (L1) Ensure 'Enable component updates in Microsoft Edge' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.89 (L1) Ensure 'Enable deleting browser and download history' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.94 (L2) Ensure 'Enable guest mode' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.97 (L1) Ensure 'Enable resolution of navigation errors using a web service' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.99 (L1) Ensure 'Enable security warnings for command-line flags' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.115 (L2) Ensure 'Live captions allowed' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.124 (L1) Ensure 'Show the Reload in Internet Explorer mode button in the toolbar' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.134 (L1) Ensure 'Wallet Donation Enabled' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

2.1.3 Disable Local Graphical Login Environment - Make sure that /application/graphical-login/cde-login is disabledCIS Solaris 10 L1 v5.2Unix
2.2.2 Disable NIS Server Daemons - Make sure that /network/nis/xfr is disabledCIS Solaris 10 L1 v5.2Unix
2.2.8 Disable Volume Manager - Make sure that system/filesystem/volfs is disabledCIS Solaris 10 L1 v5.2Unix
2.2.9 Disable Samba Support - Make sure that /etc/sfw/smb.conf does not exist. Note this check is only applicable for Solaris 10 >= 11/06CIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

2.2.11 Disable Apache services - Make sure that network/http:apache2 is disabled.CIS Solaris 10 L1 v5.2Unix
2.2.12 Disable Solaris Volume Manager Services - Make sure that /system/metainit is disabled - Solaris 10 <= 11/06CIS Solaris 10 L1 v5.2Unix
2.2.12 Disable Solaris Volume Manager Services - Make sure that system/mdmonitor is disabled - Solaris 10 >= 8/07CIS Solaris 10 L1 v5.2Unix
2.2.14 Disable Local RPC Port Mapping Service - Make sure that network/rpc/bind is disabled.CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that application/x11/x11-server only allows local connections (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/finger:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/login:rlogin is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/metamed:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that system/system-log only allows local connections (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.9 Ensure monitoring and alerting exists for sessions from unsupported Snowflake Connector for Python and JDBC and ODBC driversCIS Snowflake Foundations v1.0.0 L2Snowflake

AUDIT AND ACCOUNTABILITY

3.1.10 Set Interval for Scanning IRE_CACHE - Check ip_ire_arp_interval value. Expected value: 60000.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.11 Ignore ICMP Redirect Messages - Check ip_ignore_redirect value. Expected value: 1.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.5 Ensure that the REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_CREATION account parameter is set to trueCIS Snowflake Foundations v1.0.0 L1Snowflake

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

4.6 Ensure that the REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_OPERATION account parameter is set to trueCIS Snowflake Foundations v1.0.0 L1Snowflake

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

4.7 Ensure that all external stages have storage integrationsCIS Snowflake Foundations v1.0.0 L1Snowflake

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

4.11 Ensure that row-access policies are configured for sensitive dataCIS Snowflake Foundations v1.0.0 L2Snowflake

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

11.1 (L1) Ensure 'Show Status Bar' is not 'Hidden'CIS MacOS Safari v2.0.0 L1Unix

CONFIGURATION MANAGEMENT