Item Search

NameAudit NamePluginCategory
1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS AlmaLinux OS 8 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

1.3.1.4 Ensure the SELinux mode is not disabledCIS AlmaLinux OS 10 v1.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.3.1.5 Ensure the SELinux mode is enforcingCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

SYSTEM AND INFORMATION INTEGRITY

1.3.1.5 Ensure the SELinux mode is enforcingCIS Oracle Linux 10 v1.0.0 L2 WorkstationUnix

SYSTEM AND INFORMATION INTEGRITY

1.3.1.5 Ensure the SELinux mode is enforcingCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

SYSTEM AND INFORMATION INTEGRITY

1.3.1.5 Ensure the SELinux mode is enforcingCIS AlmaLinux OS 8 v4.0.0 L2 ServerUnix

SYSTEM AND INFORMATION INTEGRITY

1.3.1.5 Ensure the SELinux mode is not disabledCIS SUSE Linux Enterprise 16 v1.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.4.2 Ensure access to bootloader config is configuredCIS AlmaLinux OS 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

1.4.2 Ensure access to bootloader config is configuredCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

1.4.2 Ensure access to bootloader config is configuredCIS AlmaLinux OS 8 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.5.5 Ensure kernel.dmesg_restrict is configuredCIS AlmaLinux OS 10 v1.0.0 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL

1.6.1.1 Ensure SELinux is enabled in the bootloader configuration - security=selinuxCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.1 Ensure SELinux is enabled in the bootloader configuration - security=selinuxCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.1 Ensure SELinux is enabled in the bootloader configuration - selinux = 1CIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcing - /etc/selinux/configCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.4 Ensure no unconfined daemons existCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.3 Ensure SELinux or AppArmor are installedCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.7.1.2 Ensure SELinux is not disabled in bootloader configuration - selinuxCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.5 Ensure the SELinux mode is enforcing - getenforceCIS Fedora 19 Family Linux Server L2 v1.0.0Unix

ACCESS CONTROL

1.8.1.6 Ensure permissions on /etc/issue.net are configuredCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

ACCESS CONTROL

2.2.48 (L1) Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Windows Server 2012 MS L1 v3.0.0Windows

ACCESS CONTROL

2.3.10.11 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows 11 Enterprise v5.0.1 L1 BLWindows

ACCESS CONTROL

4.11.31.1 (L1) Ensure 'Prevent users from sharing files within their profile. (User)' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v4.0.0 L1Windows

ACCESS CONTROL

5.1.2 Ensure access to SSH private host key files is configuredCIS AlmaLinux OS 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

5.1.2 Ensure permissions on /etc/crontab are configuredCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.1.4 Ensure access to SSH private host key files is configuredCIS Oracle Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

5.1.4 Ensure permissions on /etc/cron.daily are configuredCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.1.6 Ensure permissions on /etc/cron.monthly are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

5.2.1 Ensure permissions on /etc/ssh/sshd_config are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

5.2.3 Ensure permissions on SSH public host key files are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

5.4.3.3 Ensure default user umask is configuredCIS Oracle Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/login.defsCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.1.1 Audit system file permissionsCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

ACCESS CONTROL

6.1.6 Ensure permissions on /etc/passwd- are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

6.1.7 Ensure permissions on /etc/shadow- are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

6.1.8 Ensure permissions on /etc/group- are configuredCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

6.2.4.3 Ensure audit log files owner is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

6.2.4.3 Ensure audit log files owner is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

6.2.8 Ensure users' dot files are not group or world writableCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.17 Ensure shadow group is emptyCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.3.4.3 Ensure audit log files owner is configuredCIS Oracle Linux 8 v4.0.0 L2 WorkstationUnix

CONFIGURATION MANAGEMENT

6.3.4.3 Ensure audit log files owner is configuredCIS AlmaLinux OS 10 v1.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

6.3.4.5 Ensure audit configuration files mode is configuredCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

7.1.11 Ensure world writable files and directories are securedCIS Oracle Linux 8 v4.0.0 L1 ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

7.1.11 Ensure world writable files and directories are securedCIS AlmaLinux OS 10 v1.0.0 L1 WorkstationUnix

SYSTEM AND COMMUNICATIONS PROTECTION

7.2.8 Ensure local interactive user home directories are configuredCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

10.3 Ensure the named_t Process Type is Not in Permissive ModeCIS BIND DNS v1.0.0 L2 Caching Only Name ServerUnix

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2Windows

ACCESS CONTROL