Item Search

NameAudit NamePluginCategory
1.6.1.2 Ensure the SELinux state is enforcing - sestatusCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.3 Ensure SELinux policy is configuredCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

1.6.1.3 Ensure SELinux policy is configured - /etc/selinux/configCIS Aliyun Linux 2 L2 v1.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure all AppArmor Profiles are enforcing - unconfinedCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

ACCESS CONTROL

1.6.1.5 Ensure the SELinux mode is enforcing - configCIS CentOS 6 Server L2 v3.0.0Unix

ACCESS CONTROL

1.6.2.1 Ensure AppArmor is enabled in the bootloader configuration - security=apparmorCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.6.2.1 Ensure AppArmor is enabled in the bootloader configuration - security=apparmorCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.2.2 Ensure all AppArmor Profiles are enforcing - 0 processes are unconfinedCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.6.2.2 Ensure all AppArmor Profiles are enforcing - profiles loadedCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.6.3 Ensure SELinux or AppArmor are installedCIS Debian 8 Workstation L2 v2.0.2Unix

ACCESS CONTROL

1.6.3 Ensure SELinux or AppArmor are installedCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.7.1.2 Ensure AppArmor is enabled in the bootloader configuration - security=apparmorCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.2 Ensure SELinux is not disabled in bootloader configuration - enforcingCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - 0 processes are unconfinedCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.4 Ensure all AppArmor Profiles are enforcing - 0 processes are unconfinedCIS Debian Family Server L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.4 Ensure all AppArmor Profiles are enforcing - 0 processes are unconfinedCIS Debian Family Workstation L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.4 Ensure all AppArmor Profiles are enforcing - profiles loadedCIS Debian Family Server L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.4 Ensure the SELinux mode is enforcing or permissive - getenforceCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

2.2.48 (L1) Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Windows Server 2012 R2 DC L1 v3.0.0Windows

ACCESS CONTROL

2.3.10.11 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL

2.3.10.12 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows Server 2019 v5.0.0 L1 MSWindows

ACCESS CONTROL

2.3.10.12 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

ACCESS CONTROL

4.4 Ensure logrotate assigns appropriate permissionsCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

4.4 Ensure logrotate assigns appropriate permissionsCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

4.4 Ensure logrotate assigns appropriate permissionsCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

4.4 Ensure logrotate assigns appropriate permissionsCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

4.11.30.1 Ensure 'Prevent users from sharing files within their profile. (User)' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v5.0.0 L1Windows

ACCESS CONTROL

5.1 Use secure RealmsCIS Apache Tomcat 8 L2 v1.1.0Unix

ACCESS CONTROL

5.3.1 Ensure permissions on /etc/ssh/sshd_config are configuredCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.4.3 Ensure default group for the root account is GID 0CIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.1.1 Audit system file permissionsCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

6.2.5 Ensure users own their home directoriesCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.9 Ensure users own their home directoriesCIS Aliyun Linux 2 L1 v1.0.0Unix

ACCESS CONTROL

6.2.17 Ensure shadow group is emptyCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.20 Ensure shadow group is empty - /etc/groupCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.20 Ensure shadow group is empty - /etc/groupCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.20 Ensure shadow group is empty - /etc/passwdCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

7.6 Ensure directory in logging.properties is a secure location - check application log directory is secureCIS Apache Tomcat 9 L1 v1.2.0Unix

ACCESS CONTROL

7.6 Ensure directory in logging.properties is a secure location - check application log directory is secureCIS Apache Tomcat 9 L1 v1.2.0 MiddlewareUnix

ACCESS CONTROL

7.6 Ensure directory in logging.properties is a secure location - check prefix application nameCIS Apache Tomcat 8 L1 v1.1.0 MiddlewareUnix

ACCESS CONTROL

8.1 Restrict runtime access to sensitive packagesCIS Apache Tomcat 8 L1 v1.1.0Unix

ACCESS CONTROL

8.1 Restrict runtime access to sensitive packagesCIS Apache Tomcat 8 L1 v1.1.0 MiddlewareUnix

ACCESS CONTROL

10.19 Setting Security Lifecycle Listener (check for umask present in startup)CIS Apache Tomcat 7 L1 v1.1.0 MiddlewareUnix

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 NGWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

ACCESS CONTROL

55.3 Ensure 'Allow Shared User App Data' is set to 'Block'CIS Microsoft Intune for Windows 11 v5.0.0 L2Windows

ACCESS CONTROL