Item Search

NameAudit NamePluginCategory
1.2 Ensure Single-Function Member Servers are UsedCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.2 Ensure the latest software package is installedCIS NGINX v3.0.0 L1 LoadbalancerUnix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.2.2 Ensure the latest software package is installedCIS NGINX v3.0.0 L1 ProxyUnix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.2.2 Ensure the latest software package is installedCIS NGINX v3.0.0 L1 WebserverUnix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.2.10 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.4 Remove all non-essential services from the host - DPKGCIS Docker 1.12.0 v1.0.0 L1 LinuxUnix

CONFIGURATION MANAGEMENT

1.4 Remove all non-essential services from the host - RPMCIS Docker 1.12.0 v1.0.0 L1 LinuxUnix

CONFIGURATION MANAGEMENT

1.303 OL08-00-040100CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

2.2 Ensure 'CLR Enabled' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT

2.3.2 Ensure rsh client is not installed - rsh-redone-clientCIS Debian 9 Server L1 v1.0.1Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.6 Ensure 'Remote Access' Server Configuration Option is set to '0'CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.11 Ensure SQL Server is configured to use non-standard portsCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.14 Ensure centralized and remote logging is configuredCIS Docker v1.8.0 L2 OS LinuxUnix

AUDIT AND ACCOUNTABILITY

2.15 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databasesCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT, MAINTENANCE

3.3.1 Ensure Information Protection sensitivity label policies are publishedCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

RISK ASSESSMENT

3.3.1 Ensure Information Protection sensitivity label policies are publishedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

RISK ASSESSMENT

3.4 (L1) Host must deactivate SLPCIS VMware ESXi 8.0 v1.3.0 L1 VMwareVMware

CONFIGURATION MANAGEMENT

3.4 Ensure SQL Authentication is not used in contained databasesCIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.4 Ensure SQL Authentication is not used in contained databasesCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.6 Ensure the SQL Server's SQLAgent Service Account is Not an AdministratorCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS WindowsWindows

ACCESS CONTROL

3.8 Ensure only the default permissions specified by Microsoft are granted to the public server roleCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

3.8 Ensure only the default permissions specified by Microsoft are granted to the public server roleCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

3.10 Ensure Windows local groups are not SQL LoginsCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

4.2 Ensure 'CHECK_EXPIRATION' Option is set to 'ON' for All SQL Authenticated Logins Within the Sysadmin RoleCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

4.2 Ensure 'CHECK_EXPIRATION' Option is set to 'ON' for All SQL Authenticated Logins Within the Sysadmin RoleCIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

ACCESS CONTROL

4.10 Do not store secrets in DockerfilesCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

5.1 Ensure 'Maximum number of error log files' is set to greater than or equal to '12'CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

5.2 Ensure 'Default Trace Enabled' Server Configuration Option is set to '1'CIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

5.3 Ensure 'Login Auditing' is set to 'failed logins'CIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

6.3.3.14 Ensure events that modify /etc/shadow and /etc/gshadow are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.25 Ensure rename file deletion events by users are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.8 Audit AutoFillCIS Apple macOS 26 Tahoe v1.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.8 Audit AutoFillCIS Apple macOS 15.0 Sequoia v2.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.8 Audit AutoFillCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.5.1 (L1) Host SSH daemon, if enabled, must use FIPS 140-2/140-3 validated ciphersCIS VMware ESXi 8.0 v1.3.0 L1 UnixUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Set Password Expiration Parameters on Active Accounts - Check MAXWEEKS is set to 13CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Password Expiration Parameters on Active Accounts - Check MINWEEKS is set to 1CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Password Expiration Parameters on Active Accounts - Check WARNWEEKS is set to 4CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.2.9 Audit AutoFillCIS Apple macOS 12.0 Monterey v4.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

8.5.4 Ensure users dialing in can't bypass the lobbyCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

8.5.4 Ensure users dialing in can't bypass the lobbyCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL

18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higherCIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

CONFIGURATION MANAGEMENT

18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higherCIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

CONFIGURATION MANAGEMENT

ALMA-09-018720 - The firewalld service on AlmaLinux OS 9 must be active.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

DG0097-ORACLE11 - Plans and procedures for testing DBMS installations, upgrades and patches should be defined and followed prior to production implementation.DISA STIG Oracle 11 Installation v9r1 LinuxUnix
DG0097-ORACLE11 - Plans and procedures for testing DBMS installations, upgrades and patches should be defined and followed prior to production implementation.DISA STIG Oracle 11 Installation v9r1 WindowsWindows
DG0138-ORACLE11 - Access grants to sensitive data should be restricted to authorized user roles.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
OL09-00-000220 - OL 9 must have the firewalld package installed.DISA Oracle Linux 9 STIG v1r6Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

RHEL-09-251015 - The firewalld service on RHEL 9 must be active.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

WG170 IIS6 - Each readable web document directory must contain a default, home, index or equivalent file. - 'EnableDefaultDoc set to True'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT