Item Search

NameAudit NamePluginCategory
1.99 PHTN-40-000237CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.100 WN16-CC-000070CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.100 WN19-CC-000060CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.100 WN22-CC-000060CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.101 WN10-CC-000020CIS Microsoft Windows 10 STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.104 WN10-CC-000035CIS Microsoft Windows 10 STIG v1.0.0 CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.2 Ensure that the kubelet kubeconfig file ownership is set to root:rootCIS Google Kubernetes Engine GKE v2.0.0 L1 UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.1.4 Ensure that the kubelet configuration file ownership is set to root:rootCIS Google Kubernetes Engine GKE v2.0.0 L1 UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.1 Ensure the cluster-admin ClusterRole is only used when requiredCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

ACCESS CONTROL

4.3.1 Enable NetworkPolicy enforcement with GKE Dataplane V2 or CalicoCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

SYSTEM AND COMMUNICATIONS PROTECTION

4.6.1 Use namespaces to separate workload administration and resource governanceCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

SYSTEM AND COMMUNICATIONS PROTECTION

4.6.1 Use namespaces to separate workload administration and resource governanceCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L1GCP

SYSTEM AND COMMUNICATIONS PROTECTION

4.6.4 Avoid deploying workloads in the default namespaceCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2GCP

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

5.1.1 Enable Artifact Analysis scanning for Artifact Registry container imagesCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2GCP

RISK ASSESSMENT

5.1.2 Grant least privilege IAM access to Artifact Registry repositoriesCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

5.2.1 Use custom least privilege service accounts for GKE node poolsCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

IDENTIFICATION AND AUTHENTICATION

5.3.2 Ensure that all Namespaces have Network Policies definedCIS Red Hat OpenShift Container Platform v1.9.0 L2 OpenShiftOpenShift

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.1 Enable VPC Flow Logs and Intranode VisibilityCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

5.4.4 Ensure private GKE nodes are configured without external IP addressesCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.5.5 Verify Shielded GKE Nodes are enabled for GKE clustersCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

CONFIGURATION MANAGEMENT

5.6.5 Ensure private GKE nodes are configured without external IP addressesCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-09-000200 - The Google Android Pie must be configured to not allow passwords that include more than two repeating or sequential characters - CharactersAirWatch - DISA Google Android 9.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-10-000200 - Google Android 10 must be configured to not allow passwords that include more than two repeating or sequential characters - CharactersAirWatch - DISA Google Android 10.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-10-000200 - Google Android 10 must be configured to not allow passwords that include more than two repeating or sequential characters - NumbersAirWatch - DISA Google Android 10.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-11-000200 - Google Android 11 must be configured to not allow passwords that include more than two repeating or sequential characters - AlphanumericMobileIron - DISA Google Android 11 COBO v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-11-000200 - Google Android 11 must be configured to not allow passwords that include more than two repeating or sequential characters - AlphanumericMobileIron - DISA Google Android 11 COPE v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-11-000200 - Google Android 11 must be configured to not allow passwords that include more than two repeating or sequential characters - CharactersAirWatch - DISA Google Android 11 COPE v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-11-000200 - Google Android 11 must be configured to not allow passwords that include more than two repeating or sequential characters - NumbersAirWatch - DISA Google Android 11 COBO v2r1MDM

CONFIGURATION MANAGEMENT

HONW-09-000200 - The Honeywell Mobility Edge Android Pie device must be configured to not allow passwords that include more than two repeating or sequential characters - Minimum complex charactersMobileIron - DISA Honeywell Android 9.x COBO v1r2MDM

CONFIGURATION MANAGEMENT

MOTS-11-000200 - Motorola Solutions Android 11 must be configured to not allow passwords that include more than two repeating or sequential characters - NumbersAirWatch - DISA Motorola Solutions Android 11 COBO v1r3MDM

CONFIGURATION MANAGEMENT

MSFT-11-000200 - Microsoft Android 11 must be configured to not allow passwords that include more than two repeating or sequential characters - CharactersAirWatch - DISA Microsoft Android 11 COBO v1r2MDM

CONFIGURATION MANAGEMENT

MSFT-11-000200 - Microsoft Android 11 must be configured to not allow passwords that include more than two repeating or sequential characters - NumbersAirWatch - DISA Microsoft Android 11 COBO v1r2MDM

CONFIGURATION MANAGEMENT

PHTN-40-000237 - The Photon operating system must configure AIDE to detect changes to baseline configurations.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT

VCFL-67-000027 - Rsyslog must be configured to monitor and ship vSphere Client log files - accessDISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

AUDIT AND ACCOUNTABILITY

VCFL-67-000027 - Rsyslog must be configured to monitor and ship vSphere Client log files - runtimeDISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

AUDIT AND ACCOUNTABILITY

VCUI-67-000027 - vSphere UI log files must be moved to a permanent repository in accordance with site policy - accessDISA STIG VMware vSphere 6.7 UI Tomcat v1r3Unix

AUDIT AND ACCOUNTABILITY

WN10-CC-000020 - IPv6 source routing must be configured to highest protection.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN10-CC-000038 - WDigest Authentication must be disabled.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN16-CC-000070 - Windows Server 2016 must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Microsoft Windows Server 2016 STIG v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN19-CC-000060 - Windows Server 2019 must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Microsoft Windows Server 2019 STIG v3r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN22-CC-000060 - Windows Server 2022 must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Microsoft Windows Server 2022 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-CC-000060 - Windows Server 2025 must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Microsoft Windows Server 2025 STIG v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

ZEBR-10-000200 - Zebra Android 10 must be configured to not allow passwords that include more than two repeating or sequential characters - CharactersAirWatch - DISA Zebra Android 10 COBO v1r2MDM

CONFIGURATION MANAGEMENT

ZEBR-10-000200 - Zebra Android 10 must be configured to not allow passwords that include more than two repeating or sequential characters - Minimum complex charactersMobileIron - DISA Zebra Android 10 COPE v1r2MDM

CONFIGURATION MANAGEMENT

ZEBR-10-000200 - Zebra Android 10 must be configured to not allow passwords that include more than two repeating or sequential characters - Minimum complex charactersMobileIron - DISA Zebra Android 10 COBO v1r2MDM

CONFIGURATION MANAGEMENT

ZEBR-10-000200 - Zebra Android 10 must be configured to not allow passwords that include more than two repeating or sequential characters - NumbersAirWatch - DISA Zebra Android 10 COBO v1r2MDM

CONFIGURATION MANAGEMENT

ZEBR-10-000200 - Zebra Android 10 must be configured to not allow passwords that include more than two repeating or sequential characters - TypeMobileIron - DISA Zebra Android 10 COPE v1r2MDM

CONFIGURATION MANAGEMENT

ZEBR-11-000200 - Zebra Android 11 must be configured to not allow passwords that include more than four repeating or sequential characters - Minimum complex charactersMobileIron - DISA Zebra Android 11 COBO STIG v1r4MDM

CONFIGURATION MANAGEMENT

ZEBR-11-000200 - Zebra Android 11 must be configured to not allow passwords that include more than four repeating or sequential characters - NumbersAirWatch - DISA Zebra Android 11 COBO STIG v1r4MDM

CONFIGURATION MANAGEMENT

ZEBR-11-000200 - Zebra Android 11 must be configured to not allow passwords that include more than four repeating or sequential characters - TypeMobileIron - DISA Zebra Android 11 COBO STIG v1r4MDM

CONFIGURATION MANAGEMENT