Item Search

NameAudit NamePluginCategory
1.1 Ensure Latest SQL Server Cumulative and Security Updates are InstalledCIS SQL Server 2017 Database L1 AWS RDS v1.3.0MS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.1 Ensure Latest SQL Server Service Packs and Hotfixes are InstalledCIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

CONFIGURATION MANAGEMENT

1.12 UBTU-24-100310CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.257 ALMA-09-032470CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

2.1 Ensure 'Ad Hoc Distributed Queries' Server Configuration Option is set to '0'CIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

SYSTEM AND INFORMATION INTEGRITY

2.4 Ensure 'Database Mail XPs' Server Configuration Option is set to '0'CIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure 'Database Mail XPs' Server Configuration Option is set to '0'CIS SQL Server 2017 Database L1 AWS RDS v1.3.0MS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.7 Ensure 'Remote Admin Connections' Server Configuration Option is set to '0'CIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.8 Ensure 'Scan For Startup Procs' Server Configuration Option is set to '0'CIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

CONFIGURATION MANAGEMENT

2.8 Ensure 'Scan For Startup Procs' Server Configuration Option is set to '0'CIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.11 Ensure SQL Server is configured to use non-standard portsCIS SQL Server 2017 Database L1 AWS RDS v1.3.0MS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.15 Ensure 'xp_cmdshell' Server Configuration Option is set to '0'CIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.3 Ensure 'Orphaned Users' are Dropped From SQL Server DatabasesCIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

ACCESS CONTROL

3.4 Ensure SQL Authentication is not used in contained databasesCIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

ACCESS CONTROL

3.6 Ensure the SQL Server's SQLAgent Service Account is Not an AdministratorCIS SQL Server 2017 Database L1 AWS RDS v1.3.0MS_SQLDB

ACCESS CONTROL

3.10 Ensure Windows local groups are not SQL LoginsCIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

ACCESS CONTROL

5.1 Ensure 'Maximum number of error log files' is set to greater than or equal to '12'CIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

AUDIT AND ACCOUNTABILITY

5.2 Ensure 'Default Trace Enabled' Server Configuration Option is set to '1'CIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

AUDIT AND ACCOUNTABILITY

5.4 Ensure 'SQL Server Audit' is set to capture both 'failed' and 'successful logins' - 'AUDIT_CHANGE_GROUP'CIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

AUDIT AND ACCOUNTABILITY

5.4 Ensure 'SQL Server Audit' is set to capture both 'failed' and 'successful logins' - SUCCESSFUL_LOGIN_GROUPCIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

AUDIT AND ACCOUNTABILITY

6.2 Ensure 'CLR Assembly Permission Set' is set to 'SAFE_ACCESS' for All CLR AssembliesCIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.2 Ensure Log Files Are Stored on a Non-System PartitionCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

AUDIT AND ACCOUNTABILITY

6.2.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.9 Ensure events that modify /etc/NetworkManager directory are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.11 Ensure events that modify /etc/group information are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.12 Ensure events that modify /etc/group information are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.12 Ensure events that modify /etc/group information are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.13 Ensure events that modify /etc/passwd information are collectedCIS Debian Linux 13 v1.1.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.13 Ensure events that modify /etc/passwd information are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.15 Ensure events that modify /etc/pam.d/ information are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.16 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Debian Linux 13 v1.1.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.16 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.16 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.16 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.2 Ensure actions as another user are always loggedCIS Oracle Linux 10 v1.0.0 L2 WorkstationUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.3.3.2 Ensure actions as another user are always loggedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.3.3.2 Ensure actions as another user are always loggedCIS Rocky Linux 10 v1.0.0 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.3.3.2 Ensure actions as another user are always loggedCIS AlmaLinux OS 10 v1.0.0 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Rocky Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

8.1.7 Unset the Service Name for Plaintext Communication (SVCENAME)CIS IBM DB2 12.1 v1.0.0 Linux OS Level 1Unix

PLANNING, SYSTEM AND SERVICES ACQUISITION

8.1.7 Unset the Service Name for Plaintext Communication (SVCENAME)CIS IBM DB2 11 v1.2.0 Linux OS Level 1Unix

PLANNING, SYSTEM AND SERVICES ACQUISITION

18.9.14.2 (L1) Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT

CNTR-K8-002000 - The Kubernetes API server must have the ValidatingAdmissionWebhook enabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

O19C-00-005800 - Oracle Database must off-load audit data to a separate log management facility; this must be continuous and in near-real-time for systems with a network connection to the storage facility, and weekly or more often for stand-alone systems.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O19C-00-005800 - Oracle Database must off-load audit data to a separate log management facility; this must be continuous and in near-real-time for systems with a network connection to the storage facility, and weekly or more often for stand-alone systems.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

SOL-11.1-090280 - The operating system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION