Item Search

NameAudit NamePluginCategory
1.1.2 Ensure separate partition exists for /tmpCIS SUSE Linux Enterprise Server 11 L2 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.2 Ensure separate partition exists for /tmpCIS SUSE Linux Enterprise Workstation 11 L2 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.12 Ensure separate partition exists for /var/log/auditCIS Debian Family Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.12 Ensure separate partition exists for /var/log/auditCIS Debian Family Workstation L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.16 Ensure separate partition exists for /var/log/auditCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.16 Ensure separate partition exists for /var/log/auditCIS Fedora 19 Family Linux Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.2 Ensure Snowflake SCIM integration is configured to automatically provision and deprovision users and groups (i.e. roles)CIS Snowflake Foundations v2.0.0 L2Snowflake

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 Ensure 'Deny log on through Remote Desktop Services' is set to 'Guests'CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 Ensure 'Deny log on through Remote Desktop Services' to include 'Guests, Local account'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.19 Ensure 'Deny log on through Remote Desktop Services' to include 'Guests, Local account'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.26 Ensure 'Deny log on through Remote Desktop Services' is set to 'Guests, Local account' (MS only)CIS Microsoft Windows Server 2019 v5.0.0 L1 MSWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.9.4 Ensure Writing Tools Is DisabledAirWatch - CIS Apple iOS 26 Benchmark v1.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.1.2.2 Ensure users cannot register applicationsCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.1.2.2 Ensure users cannot register applicationsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.1.4.1 Ensure the ability to join devices to Entra is restrictedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.1 Ensure the ability to join devices to Entra is restrictedCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.5.2 Ensure the admin consent workflow is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

5.1.5.2 Ensure the admin consent workflow is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

6.20 Ensure Web tier Security Group has no inbound rules for CIDR of 0 (Global Allow)CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

6.21 Create the App tier ELB Security Group and ensure only accepts HTTP/HTTPSCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

6.23 Ensure App tier Security Group has no inbound rules for CIDR of 0 (Global Allow)CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

6.25 Ensure Data tier Security Group has no inbound rules for CIDR of 0 (Global Allow)CIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND COMMUNICATIONS PROTECTION

10.1 Ensure SELinux Is Enabled in Enforcing Mode - config fileCIS BIND DNS v1.0.0 L2 Caching Only Name ServerUnix

ACCESS CONTROL

10.1 Ensure SELinux Is Enabled in Enforcing Mode - config fileCIS BIND DNS v1.0.0 L2 Authoritative Name ServerUnix

ACCESS CONTROL

10.1 Ensure SELinux Is Enabled in Enforcing Mode - current modeCIS BIND DNS v1.0.0 L2 Caching Only Name ServerUnix

ACCESS CONTROL

10.1 Ensure SELinux Is Enabled in Enforcing Mode - current modeCIS BIND DNS v1.0.0 L2 Authoritative Name ServerUnix

ACCESS CONTROL

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 NGWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

19.7.8.2 Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

19.7.8.3 (L1) Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

19.7.8.3 Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L2 DCWindows

CONFIGURATION MANAGEMENT

19.7.8.3 Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L2 DCWindows

CONFIGURATION MANAGEMENT

19.7.8.3 Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L2 MSWindows

CONFIGURATION MANAGEMENT

19.7.8.3 Ensure 'Do not use diagnostic data for tailored experiences' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2Windows

CONFIGURATION MANAGEMENT

Ensure that the 'max_allowed_packet' database flag for a Cloud Databases Mysql instance is setTenable Best Practices RackSpace v2.0.0Rackspace

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure that the 'max_connect_errors' database flag for a Cloud Databases Mysql instance is setTenable Best Practices RackSpace v2.0.0Rackspace

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure that the 'max_connections' database flag for a Cloud Databases Mysql instance is setTenable Best Practices RackSpace v2.0.0Rackspace

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure that the 'max_user_connections' database flag for a Cloud Databases Mysql instance is setTenable Best Practices RackSpace v2.0.0Rackspace

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure that the 'sql_mode' database flag for a Cloud Databases Mysql instance is setTenable Best Practices RackSpace v2.0.0Rackspace

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure that the 'wait_timeout' database flag for a Cloud Databases Mysql instance is setTenable Best Practices RackSpace v2.0.0Rackspace

SYSTEM AND COMMUNICATIONS PROTECTION

O365-OU-000006 - The junk email protection level must be set to No Automatic Filtering.DISA Microsoft Office 365 ProPlus STIG v3r5Windows

CONFIGURATION MANAGEMENT