Item Search

NameAudit NamePluginCategory
1.2.2 Ensure the latest software package is installedCIS NGINX v3.0.0 L1 WebserverUnix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.2.10 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Ensure 'Protect RE' Firewall Filter includes explicit terms for all Management ServicesCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.2 Ensure rsh client is not installed - rsh-redone-clientCIS Debian 9 Server L1 v1.0.1Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

4.2.1 Ensure IS-IS neighbor authentication is set to MD5CIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

4.4 Rebuild the images to include security patchesCIS Docker 1.6 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

6.2.3.6 Ensure events that modify /etc/issue and /etc/issue.net are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.21 Ensure login and logout events are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.22 Ensure session initiation information is collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.25 Ensure successful and unsuccessful attempts to use the chcon command are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.25 Ensure successful and unsuccessful attempts to use the chcon command are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.26 Ensure events that modify the system's Mandatory Access Controls are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.26 Ensure events that modify the system's Mandatory Access Controls are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.27 Ensure successful and unsuccessful attempts to use the chcon command are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.28 Ensure successful and unsuccessful attempts to use the setfacl command are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

6.2.3.28 Ensure successful and unsuccessful attempts to use the usermod command are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.29 Ensure successful and unsuccessful attempts to use the chacl command are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

6.2.3.33 Ensure kernel "delete_module" loading unloading and modification is collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.1 Ensure modification of the /etc/sudoers file is collectedCIS Oracle Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.1 Ensure modification of the /etc/sudoers file is collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.6 Ensure events that modify /etc/issue and /etc/issue.net are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.6 Ensure events that modify /etc/issue and /etc/issue.net are collectedCIS Rocky Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.6 Ensure events that modify /etc/issue and /etc/issue.net are collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.8 Ensure events that modify /etc/sysconfig/network and /etc/NetworkManager/system-connections/ are collectedCIS Oracle Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.8 Ensure events that modify /etc/sysconfig/network and /etc/NetworkManager/system-connections/ are collectedCIS Rocky Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.14 Ensure events that modify /etc/shadow and /etc/gshadow are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.17 Ensure events that modify /etc/pam.conf and /etc/pam.d/ information are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.17 Ensure events that modify /etc/pam.conf and /etc/pam.d/ information are collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.24 Ensure unlink file deletion events by users are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.25 Ensure rename file deletion events by users are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.25 Ensure rename file deletion events by users are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.25 Ensure rename file deletion events by users are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.26 Ensure events that modify the system's Mandatory Access Controls are collectedCIS Oracle Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.26 Ensure events that modify the system's Mandatory Access Controls are collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.28 Ensure successful and unsuccessful attempts to use the setfacl command are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

6.3.3.28 Ensure successful and unsuccessful attempts to use the setfacl command are collectedCIS Rocky Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

6.3.3.28 Ensure successful and unsuccessful attempts to use the setfacl command are collectedCIS Rocky Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

6.3.3.29 Ensure successful and unsuccessful attempts to use the chacl command are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

6.3.8 Audit AutoFillCIS Apple macOS 26 Tahoe v1.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.8 Audit AutoFillCIS Apple macOS 15.0 Sequoia v2.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.8 Audit AutoFillCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Set Password Expiration Parameters on Active Accounts - Check MAXWEEKS is set to 13CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.2.9 Audit AutoFillCIS Apple macOS 12.0 Monterey v4.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

8.5.4 Ensure users dialing in can't bypass the lobbyCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL

JUEX-NM-000130 - The Juniper EX switch must be configured to produce audit records containing information to establish when (date and time) the events occurred.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000600 - The Juniper EX switch must be configured to off-load audit records onto a different system than the system being audited.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUSX-AG-000147 - The Juniper SRX Services Gateway Firewall must generate an alert that can be forwarded to, at a minimum, the ISSO and ISSM when threats identified by authoritative sources are detected.DISA Juniper SRX Services Gateway ALG v3r3Juniper

SYSTEM AND INFORMATION INTEGRITY

JUSX-DM-000111 - The Juniper SRX Services Gateway must use and securely configure SNMPv3 if SNMP is enabled.DISA Juniper SRX Services Gateway NDM v3r3Juniper

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

Management Services Security - Community strings and USM passwords should be difficult to guess and should follow a password policyJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

VCPG-67-000004 - VMware Postgres must be configured to overwrite older logs when necessary.DISA STIG VMware vSphere 6.7 PostgreSQL v1r2Unix

AUDIT AND ACCOUNTABILITY