1.2 Enable SSH (/etc/ssh/sshd_config) | CIS FreeBSD v1.0.5 | Unix | CONFIGURATION MANAGEMENT |
1.4.1 - Remote command lockdown - 'rlogin mode 000' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | ACCESS CONTROL |
1.5.3 Ensure address space layout randomization (ASLR) is enabled - sysctl | CIS Debian 9 Server L1 v1.0.1 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
1.6.2 Ensure address space layout randomization (ASLR) is enabled - sysctl | CIS Debian Family Server L1 v1.0.0 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
1.7.9 - Miscellaneous Enhancements - AIX Auditing - '/audit directory exists' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | AUDIT AND ACCOUNTABILITY |
1.11 Windows Oracle Registry Key Setting - 'Set OSAUTH_PREFIX_DOMAIN registry value to TRUE' | CIS v1.1.0 Oracle 11g OS Windows Level 1 | Windows | CONFIGURATION MANAGEMENT |
2.2 Set 'Specify use of ActiveX Installer Service for installation of ActiveX controls' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
2.3 Set 'Turn on ActiveX Filtering' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
2.3.2 - /etc/mail/sendmail.cf - permissions and ownership - '/etc/mail/sendmail.cf root:system 640' | CIS AIX 5.3/6.1 L1 v1.1.0 | Unix | ACCESS CONTROL |
2.4 Set 'Turn off ActiveX opt-in prompt' to 'Disabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
2.06 listener.ora - 'Use IP addresses rather than hostnames' | CIS v1.1.0 Oracle 11g OS Windows Level 2 | Windows | CONFIGURATION MANAGEMENT |
2.10.2 - TCP Wrappers - creating a hosts.deny file - creation - '/etc/hosts.deny root:system 600' | CIS AIX 5.3/6.1 L1 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
2.10.3 - TCP Wrappers - creating a hosts.allow file - creation - '/etc/hosts.allow root:system 600' | CIS AIX 5.3/6.1 L1 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
2.11 listener.ora - 'Change standard ports' | CIS v1.1.0 Oracle 11g OS Windows Level 2 | Windows | CONFIGURATION MANAGEMENT |
2.12.7 - Miscellaneous Config - Block talk/write - '/etc/profile contains mesg n' | CIS AIX 5.3/6.1 L2 v1.1.0 | Unix | CONFIGURATION MANAGEMENT |
2.13 Service or SID name - 'Non-default' | CIS v1.1.0 Oracle 11g OS L1 | Unix | CONFIGURATION MANAGEMENT |
3.1.12 Enable instance health monitoring - 'health_mon = on' | CIS IBM DB2 OS L2 v1.2.0 | Unix | CONFIGURATION MANAGEMENT |
3.1.13 Retain fenced model processes - 'keepfenced = no' | CIS IBM DB2 OS L2 v1.2.0 | Unix | CONFIGURATION MANAGEMENT |
3.1.18 Secure permissions for the secondary archive log location - LOGARCHMETH2 OS Permissions | CIS IBM DB2 v10 v1.1.0 Windows OS Level 1 | Windows | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
3.1.20 Secure permissions for the log mirror location - MIRRORLOGPATH OS Permissions | CIS IBM DB2 v10 v1.1.0 Windows OS Level 1 | Windows | AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
3.3.2 Set a generic system name - 'db2system value' | CIS IBM DB2 OS L2 v1.2.0 | Unix | CONFIGURATION MANAGEMENT |
3.4 Set 'Days to keep pages in History' to '40' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
3.6 Configure 'Allow deleting browsing history on exit' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
4.02 init.ora - 'global_names = TRUE' | CIS v1.1.0 Oracle 11g OS L1 | Unix | CONFIGURATION MANAGEMENT |
4.09 init.ora - 'Avoid using utl_file_dir parameters' | CIS v1.1.0 Oracle 11g OS L1 | Unix | CONFIGURATION MANAGEMENT |
5.3.19 Make the Audit Configuration Immutable - -e 2 | CIS Red Hat Enterprise Linux 5 L2 v2.2.1 | Unix | AUDIT AND ACCOUNTABILITY |
5.4 Set permissions on system log files (/var/log/ppp.lo*) | CIS FreeBSD v1.0.5 | Unix | CONFIGURATION MANAGEMENT |
5.26 sqlnet.ora - 'ssl_server_dn_match = YES' | CIS v1.1.0 Oracle 11g OS L2 | Unix | CONFIGURATION MANAGEMENT |
6.2 Configure 'Turn off URL Suggestions' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
6.3 Configure 'Prevent participation in the Customer Experience Improvement Program' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
6.4 Configure 'Turn on Suggested Sites' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
6.6 User home directories should be kept private | CIS FreeBSD v1.0.5 | Unix | CONFIGURATION MANAGEMENT |
7.5 Create warning banners for the system (/etc/motd permissions) | CIS FreeBSD v1.0.5 | Unix | CONFIGURATION MANAGEMENT |
7.5 Set 'MK Protocol Security Restriction' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
7.7 Prevent X server from listening on port 6000/tcp (Solaris 9) | CIS Solaris 9 v1.3 | Unix | CONFIGURATION MANAGEMENT |
7.7 Set 'Restrict File Download' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.1.3 Set 'Protected Mode' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
8.1.16 Set 'Automatic prompting for file downloads' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.1.23 Set 'Status bar updates via script' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.2.3 Set 'Intranet Sites: Include all network paths (UNCs)' to 'Disabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.3.2 Set 'Allow drag and drop or copy and paste files' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.3.10 Set 'Protected Mode' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
8.3.13 Set 'Automatic prompting for file downloads' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.3.20 Set 'Use Pop-up Blocker' to 'Enabled:Enable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.3.34 Set 'Include local directory path when uploading files to a server' to 'Enabled:Disable' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.7 No user dot-files should be world writable | CIS FreeBSD v1.0.5 | Unix | CONFIGURATION MANAGEMENT |
8.12 Set 'Security Zones: Do not allow users to add/delete sites' to 'Enabled' | CIS IE 10 v1.1.0 | Windows | CONFIGURATION MANAGEMENT |
8.13 Set 'mesg n' as default for all users in /etc/profile | CIS Solaris 9 v1.3 | Unix | CONFIGURATION MANAGEMENT |
List crash dumps | TNS Citrix Hypervisor | Unix | CONFIGURATION MANAGEMENT |
XenServer - List crash dumps | TNS Citrix XenServer | Unix | CONFIGURATION MANAGEMENT |