Item Search

NameAudit NamePluginCategory
1.7.5 Ensure GDM screen locks cannot be overriddenCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

1.7.5 Ensure GDM screen locks cannot be overriddenCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 WorkstationUnix

ACCESS CONTROL

1.8.4 Ensure GDM screen locks when the user is idleCIS Red Hat Enterprise Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

1.8.4 Ensure GDM screen locks when the user is idleCIS Rocky Linux 9 v2.0.0 L1 ServerUnix

ACCESS CONTROL

1.8.5 Ensure GDM screen locks cannot be overriddenCIS Red Hat Enterprise Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

1.8.5 Ensure GDM screen locks cannot be overriddenCIS SUSE Linux Enterprise 15 v2.0.1 L1 WorkstationUnix

ACCESS CONTROL

1.8.5 Ensure GDM screen locks cannot be overriddenCIS AlmaLinux OS 8 Server L1 v3.0.0Unix

ACCESS CONTROL

2.1.1.1.4 Set 'seconds' for 'ip ssh timeout' for 60 seconds or lessCIS Cisco IOS XE 17.x v2.2.0 L1Cisco

ACCESS CONTROL

2.3.7.4 (L1) Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

ACCESS CONTROL

2.3.7.4 (L1) Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 NGWindows

ACCESS CONTROL

2.3.7.4 (L1) Ensure 'Interactive logon: Machine inactivity limit' is set to '900 or fewer second(s), but not 0'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MSWindows

ACCESS CONTROL

2.3.7.7 (L1) Ensure 'Interactive logon: Smart card removal behavior' is set to 'Lock Workstation' or higherCIS Microsoft Windows Server 2022 Stand-alone v1.0.0 L1 MSWindows

ACCESS CONTROL

2.3.7.8 (L1) Ensure 'Interactive logon: Smart card removal behavior' is set to 'Lock Workstation' or higherCIS Microsoft Windows 10 Stand-alone v4.0.0 L1 NGWindows

ACCESS CONTROL

2.3.7.9 (L1) Ensure 'Interactive logon: Smart card removal behavior' is set to 'Lock Workstation' or higherCIS Microsoft Windows Server 2019 v4.0.0 L1 MSWindows

ACCESS CONTROL

2.7.1 Ensure Screen Saver Corners Are SecureCIS Apple macOS 14.0 Sonoma v2.1.0 L2Unix

ACCESS CONTROL

4.5.3.2 Ensure default user shell timeout is configuredCIS Red Hat EL8 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.2.2.4 (L1) Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative usersCIS Microsoft 365 Foundations v5.0.0 L1 E3microsoft_azure

ACCESS CONTROL

5.2.16 Ensure SSH Idle Timeout Interval is configured - ClientAliveIntervalCIS Debian 8 Workstation L1 v2.0.2Unix

ACCESS CONTROL

5.4.3.2 Ensure default user shell timeout is configuredCIS Rocky Linux 9 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.4.3.2 Ensure default user shell timeout is configuredCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

ACCESS CONTROL

5.4.3.2 Ensure default user shell timeout is configuredCIS SUSE Linux Enterprise 15 v2.0.1 L1 WorkstationUnix

ACCESS CONTROL

5.4.5 Ensure default user shell timeout is 900 seconds or less - /etc/bashrcCIS Debian 8 Workstation L2 v2.0.2Unix

ACCESS CONTROL

5.4.5 Ensure default user shell timeout is 900 seconds or less - /etc/profileCIS Debian 8 Server L2 v2.0.2Unix

ACCESS CONTROL

5.4.5 Ensure default user shell timeout is 900 seconds or less - /etc/profile.d/*.shCIS Debian 8 Server L2 v2.0.2Unix

ACCESS CONTROL

5.5 Ensure a Separate Timestamp Is Enabled for Each User/tty ComboCIS Apple macOS 15.0 Sequoia v1.1.0 L1Unix

ACCESS CONTROL

5.7 Ensure an Administrator Account Cannot Login to Another User's Active and Locked SessionCIS Apple macOS 13.0 Ventura v3.1.0 L1Unix

ACCESS CONTROL

5.7 Ensure an Administrator Account Cannot Login to Another User's Active and Locked SessionCIS Apple macOS 14.0 Sonoma v2.1.0 L1Unix

ACCESS CONTROL

7.2.3 Ensure all groups in /etc/passwd exist in /etc/groupCIS Red Hat Enterprise Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL, MEDIA PROTECTION

7.2.3 Ensure all groups in /etc/passwd exist in /etc/groupCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

7.2.3 Ensure all groups in /etc/passwd exist in /etc/groupCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 WorkstationUnix

ACCESS CONTROL, MEDIA PROTECTION

7.2.3 Ensure all groups in /etc/passwd exist in /etc/groupCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

18.5.10 (L1) Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires' is set to 'Enabled: 5 or fewer seconds'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 NGWindows

ACCESS CONTROL

Big Sur - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Big Sur v1.4.0 - 800-171Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Big Sur - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Big Sur v1.4.0 - 800-53r5 LowUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Big Sur - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Big Sur v1.4.0 - 800-53r5 HighUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Big Sur - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Big Sur v1.4.0 - 800-53r5 ModerateUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Catalina - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Catalina v1.5.0 - 800-53r4 LowUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Catalina - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Catalina v1.5.0 - 800-171Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Catalina - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Catalina v1.5.0 - 800-53r5 LowUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Catalina - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Catalina v1.5.0 - CNSSI 1253Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

JUSX-DM-000039 - The Juniper SRX Services Gateway must allow only the information system security manager (ISSM) (or administrators/roles appointed by the ISSM) to select which auditable events are to be generated and forwarded to the syslog and/or local logs - or administrators/roles appointed by the ISSM to select which auditable events are to be generated and forwarded to the syslog and/or local logs.DISA Juniper SRX Services Gateway NDM v3r2Juniper

ACCESS CONTROL, CONFIGURATION MANAGEMENT

JUSX-DM-000097 - The Juniper SRX Services Gateway must be configured to use a centralized authentication server to authenticate privileged users for remote and nonlocal access for device management.DISA Juniper SRX Services Gateway NDM v3r2Juniper

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Monterey - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Monterey v1.0.0 - 800-53r4 HighUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Monterey - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Monterey v1.0.0 - 800-53r4 LowUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Monterey - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Monterey v1.0.0 - 800-53r5 HighUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Monterey - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Monterey v1.0.0 - 800-53r5 ModerateUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Monterey - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Monterey v1.0.0 - 800-171Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Monterey - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Monterey v1.0.0 - 800-53r4 ModerateUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Monterey - Configure System to Audit All Failed Program Execution on the SystemNIST macOS Monterey v1.0.0 - 800-53r5 LowUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

SLES-15-030030 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.DISA SUSE Linux Enterprise Server 15 STIG v2r4Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY