Item Search

NameAudit NamePluginCategory
1.1.9 Ensure that the Container Network Interface file permissions are set to 600 or more restrictiveCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

ACCESS CONTROL, MEDIA PROTECTION

1.35 SOL-11.1-020030CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.35 SOL-11.1-020030CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.37 SOL-11.1-020050CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.38 SOL-11.1-020080CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.99 WN16-CC-000060CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IIIWindows

CONFIGURATION MANAGEMENT

1.99 WN16-CC-000060CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.99 WN19-CC-000050CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.99 WN22-CC-000050CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.99 WN22-CC-000050CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IIIWindows

CONFIGURATION MANAGEMENT

1.111 WN11-CC-000030CIS Microsoft Windows 11 STIG v1.2.0 CAT IIIWindows

CONFIGURATION MANAGEMENT

1.192 WN22-MS-000020CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

3.061 - Unencrypted remote access is permitted to system services.DISA Windows Vista STIG v6r41Windows

ACCESS CONTROL

4.1.4 If proxy kubeconfig file exists ensure ownership is set to root:rootCIS Kubernetes v1.20 Benchmark v1.0.1 L1 WorkerUnix

ACCESS CONTROL

4.1.7 Ensure that the certificate authorities file permissions are set to 600 or more restrictiveCIS Kubernetes v1.20 Benchmark v1.0.1 L1 WorkerUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.8 Ensure that the client certificate authorities file ownership is set to root:rootCIS Kubernetes v1.23 Benchmark v1.0.1 L1 WorkerUnix

ACCESS CONTROL

4.1.9 If the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictiveCIS Kubernetes v1.23 Benchmark v1.0.1 L1 WorkerUnix

ACCESS CONTROL, MEDIA PROTECTION

4.2.3 Ensure that the --client-ca-file argument is set as appropriateCIS Kubernetes v1.20 Benchmark v1.0.1 L1 WorkerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.9 Ensure that the --event-qps argument is set to 0 or a level which ensures appropriate event captureCIS Kubernetes v1.23 Benchmark v1.0.1 L2 WorkerUnix

AUDIT AND ACCOUNTABILITY

5.1.3 Enforce Binary Authorization for trusted GKE container image deploymentsCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

CONFIGURATION MANAGEMENT

5.2.4 Minimize the admission of containers wishing to share the host IPC namespaceCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.9 Minimize the admission of containers with capabilities assignedCIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

CONFIGURATION MANAGEMENT

5.2.10 Minimize the admission of containers with capabilities assignedCIS Kubernetes v1.23 Benchmark v1.0.1 L2 MasterUnix

CONFIGURATION MANAGEMENT

5.3.2 Ensure that all Namespaces have Network Policies definedCIS Kubernetes v1.20 Benchmark v1.0.1 L2 MasterUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.5.1.6 Ensure shadow file is configured to use only encrypted representations of passwordsCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.7.2 Enable Linux auditd logging for Container Optimized OS GKE nodesCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

5.9.1 Use CMEK protected StorageClasses for GKE Persistent Disk volumesCIS Google Kubernetes Engine GKE v2.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

CIS_Kubernetes_v1.1.0_Level_1.audit from CIS Kubernetes Benchmark v1.1.0CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix
CIS_Kubernetes_v1.1.0_Level_2.audit from CIS Kubernetes Benchmark v1.1.0CIS Kubernetes 1.7.0 Benchmark v1.1.0 L2Unix
CIS_Kubernetes_v1.2.0_Level_1.audit from CIS Kubernetes Benchmark v1.2.0CIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix
CIS_Kubernetes_v1.2.0_Level_2.audit from CIS Kubernetes Benchmark v1.2.0CIS Kubernetes 1.8 Benchmark v1.2.0 L2Unix
CIS_Kubernetes_v1.3.0_Level_2.audit from CIS Kubernetes Benchmark v1.3.0CIS Kubernetes 1.11 Benchmark v1.3.0 L2Unix
CIS_Kubernetes_v1.4.1_Level_2.audit from CIS Kubernetes Benchmark v1.4.1CIS Kubernetes 1.13 Benchmark v1.4.1 L2Unix

CONFIGURATION MANAGEMENT

CIS_Kubernetes_v1.20_v1.0.1_Level_2_Worker.audit from CIS Kubernetes v1.20 Benchmark v1.0.1CIS Kubernetes v1.20 Benchmark v1.0.1 L2 WorkerUnix

CONFIGURATION MANAGEMENT

CIS_Kubernetes_v1.23_v1.0.1_Level_2_Master.audit from CIS Kubernetes v1.23 Benchmark v1.0.1CIS Kubernetes v1.23 Benchmark v1.0.1 L2 MasterUnix

CONFIGURATION MANAGEMENT

CIS_Kubernetes_v1.24_v1.0.0_Level_1_Master.audit from CIS Kubernetes v1.24 Benchmark v1.0.0CIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

CONFIGURATION MANAGEMENT

SOL-11.1-020030 - The operating system must protect audit tools from unauthorized access.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020050 - The operating system must protect audit tools from unauthorized deletion.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SQL6-D0-004700 - SQL Server must initiate session auditing upon startup.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

VCPG-67-000022 - Rsyslog must be configured to monitor VMware Postgres logs - firstDISA STIG VMware vSphere 6.7 PostgreSQL v1r2Unix

AUDIT AND ACCOUNTABILITY

WN11-CC-000030 - The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN12-RG-000003-MS - Local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000037 - IPv6 source routing must be configured to the highest protection level.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000041 - The system must be configured to limit how often keep-alive packets are sent.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000047 - IPv6 TCP data retransmissions must be configured to prevent resources from becoming exhausted.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000049 - The system must generate an audit event when the audit log reaches a percentage of full threshold.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

AUDIT AND ACCOUNTABILITY

WN19-CC-000050 - Windows Server 2019 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN25-CC-000050 - Windows Server 2025 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-CC-000050 - Windows Server 2025 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT

WN25-MS-000020 - Windows Server 2025 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers.DISA Microsoft Windows Server 2025 STIG v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION