Item Search

NameAudit NamePluginCategory
1.1.3.1.5 Set 'Accounts: Guest account status' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.3.1.6 Set 'Accounts: Limit local account use of blank passwords to console logon only' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

1.1.3.11.3 Configure Network access: Shares that can be accessed anonymouslyCIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.21 Set 'Deny log on locally' to 'Guests'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.29 Set 'Deny log on as a batch job' to 'Guests'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.35 Set 'Generate security audits' to 'Local Service, Network Service'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.36 Set 'Allow log on locally' to 'Administrators, Users'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

2.2.16 Ensure 'Deny access to this computer from the network' to include 'Guests, Local account'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.2.19 Ensure 'Deny log on locally' to include 'Guests'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.3.1.1 Ensure 'Accounts: Administrator account status' is set to 'Disabled'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.3.1.1 Ensure 'Accounts: Administrator account status' is set to 'Disabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.3.1.2 Ensure 'Accounts: Guest account status' is set to 'Disabled'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.3.1.4 Configure 'Accounts: Rename administrator account'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.3.7.6 Ensure 'Interactive logon: Prompt user to change password before expiration' is set to 'between 5 and 14 days'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

IDENTIFICATION AND AUTHENTICATION

2.3.10.2 (L1) Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT

2.3.10.3 Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts and shares' is set to 'Enabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.3.11.1 Ensure 'Network security: Allow Local System to use computer identity for NTLM' is set to 'Enabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

IDENTIFICATION AND AUTHENTICATION

2.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iOS 10 v2.0.0 End User Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

2.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 v1.0.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT

3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

ACCESS CONTROL

3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/at.allow'CIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/at.deny'CIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - cron.denyCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

5.4.1.4 Ensure inactive password lock is 30 days or less - useraddCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

ACCESS CONTROL

5.4.2 Ensure system accounts are non-loginCIS Debian 8 Workstation L1 v2.0.2Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile.d/*.shCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate UIDs existCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.19 Ensure no duplicate group names existCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.19 Ensure no duplicate group names existCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

Accounts: Limit local account use of blank passwords to console logon onlyMSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Accounts: Limit local account use of blank passwords to console logon onlyMSCT Windows Server 2019 DC v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Accounts: Limit local account use of blank passwords to console logon onlyMSCT Windows Server v20H2 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Deny access to this computer from the networkMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

Ensure at/cron is restricted to authorized users - cron.allowTenable Cisco Firepower Management Center OS Best Practices AuditUnix

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows 10 v20H2 v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts and sharesMSCT Windows 10 1909 v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts and sharesMSCT Windows 10 v20H2 v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts and sharesMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts and sharesMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts and sharesMSCT Windows Server 2019 DC v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts and sharesMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop.MSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL