Item Search

NameAudit NamePluginCategory
1.1 Ensure single sign-on (SSO) is configured for your account / organizationCIS Snowflake Foundations v1.0.0 L1Snowflake

ACCESS CONTROL

1.3.10 (L2) Ensure 'Default setting for third-party storage partitioning' is set to 'Enabled: Block third-party storage partitioning from being enabled.'CIS Microsoft Edge v3.0.0 L2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.7 Ensure authentication key pairs are rotated every 180 daysCIS Snowflake Foundations v1.0.0 L1Snowflake

IDENTIFICATION AND AUTHENTICATION

1.9.1 Ensure 'Enable Gamer Mode' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.10 Limit the number of users with ACCOUNTADMIN and SECURITYADMINCIS Snowflake Foundations v1.0.0 L1Snowflake

ACCESS CONTROL

1.10.1 (L1) Ensure 'Allow Basic authentication for HTTP' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.11 Ensure that all users granted the ACCOUNTADMIN role have an email address assignedCIS Snowflake Foundations v1.0.0 L1Snowflake

ACCESS CONTROL

1.11.2 (L1) Ensure 'Guided Switch Enabled' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.12 Ensure that no users have ACCOUNTADMIN or SECURITYADMIN as the default roleCIS Snowflake Foundations v1.0.0 L1Snowflake

ACCESS CONTROL

1.13 Ensure that the ACCOUNTADMIN or SECURITYADMIN role is not granted to any custom roleCIS Snowflake Foundations v1.0.0 L1Snowflake

ACCESS CONTROL

1.14 Ensure that Snowflake tasks are not owned by the ACCOUNTADMIN or SECURITYADMIN rolesCIS Snowflake Foundations v1.0.0 L1Snowflake

ACCESS CONTROL

1.18.1 (L1) Ensure 'Enable startup boost' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.25.1 (L1) Ensure 'Configure Microsoft Defender SmartScreen' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.25.2 (L1) Ensure 'Configure Microsoft Defender SmartScreen to block potentially unwanted apps' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.33 (L1) Ensure 'Allow importing of autofill form data' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.35 (L1) Ensure 'Allow importing of home page settings' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.37 (L1) Ensure 'Allow importing of saved passwords' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.38 (L1) Ensure 'Allow importing of search engine settings' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.40 (L2) Ensure 'Allow or block audio capture' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.43 (L1) Ensure 'Allow personalization of ads, Microsoft Edge, search, news and other Microsoft services by sending browsing history, favorites and collections, usage and other browsing data to Microsoft' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.48 (L1) Ensure 'Allow user feedback' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.57 (L1) Ensure 'Block tracking of users' web-browsing activity' is set to 'Enabled: Balanced (Blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)' or higherCIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.63 (L1) Ensure 'Configure browser process code integrity guard setting' is set to 'Enabled: Enable code integrity guard enforcement in the browser process.'CIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.65 (L2) Ensure 'Configure Online Text To Speech' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.71 (L1) Ensure 'Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode' is set to 'Enabled: Do not send form data or headers'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.82 (L1) Ensure 'Edge 3P SERP Telemetry Enabled' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.83 (L1) Ensure 'Edge Wallet E-Tree Enabled' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.86 (L1) Ensure 'Enable browser legacy extension point blocking' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.90 (L1) Ensure 'Enable Discover access to page contents for AAD profiles' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.91 (L2) Ensure 'Enable Drop feature in Microsoft Edge' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.104 (L1) Ensure 'Enable upload files from mobile in Microsoft Edge desktop' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.106 (L1) Ensure 'Enable warnings for insecure forms' is set to 'Enabled'CIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.116 (L1) Ensure 'Manage exposure of local IP addresses by WebRTC' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.117 (L1) Ensure 'Notify a user that a browser restart is recommended or required for pending updates' is set to 'Enabled: Required - Show a recurring prompt to the user indicating that a restart is required'CIS Microsoft Edge v3.0.0 L1Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.125 (L1) Ensure 'Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.133 (L1) Ensure 'Wait for Internet Explorer mode tabs to completely unload before ending the browser session' is set to 'Disabled'CIS Microsoft Edge v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

3.1.1 (L1) Ensure 'Update policy override default' is set to 'Enabled: Always allow updates (recommended)'CIS Microsoft Edge v3.0.0 L1Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

3.2 (L2) Ensure 'AutoFill web forms: Credit cards' is 'Disabled'CIS MacOS Safari v2.0.0 L2Unix

CONFIGURATION MANAGEMENT

3.3 (L2) Ensure 'AutoFill web forms: Other forms' is 'Disabled'CIS MacOS Safari v2.0.0 L2Unix

CONFIGURATION MANAGEMENT

3.3.1 (L1) Ensure 'Auto-update check period override' is set to any value except '0'CIS Microsoft Edge v3.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

4.1.5 Ensure events that modify user/group information are collected - 'auditctl /etc/group'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify user/group information are collected - 'auditctl /etc/security/opasswd'CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.6 Ensure events that modify the system's network environment are collected - auditctl /etc/hostsCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.6 Ensure events that modify the system's network environment are collected - auditctl issueCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.6 Ensure events that modify the system's network environment are collected - issue.netCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.7 Ensure events that modify the system's Mandatory Access Controls are collected - /etc/selinuxCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.8 Ensure login and logout events are collected - /var/run/faillock/CIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.9 Ensure session initiation information is collected - auditctl wtmpCIS Amazon Linux v2.1.0 L2Unix

AUDIT AND ACCOUNTABILITY

6.2 (L2) Ensure 'Enable JavaScript' is 'Disabled'CIS MacOS Safari v2.0.0 L2Unix

CONFIGURATION MANAGEMENT

10.1 (L1) Ensure 'Show full website address' is 'Enabled'CIS MacOS Safari v2.0.0 L1Unix

CONFIGURATION MANAGEMENT