Item Search

NameAudit NamePluginCategory
2.1 Ensure Only Necessary Authentication and Authorization Modules Are Enabled - 'auth*'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

CONFIGURATION MANAGEMENT

2.1 Ensure Only Necessary Authentication and Authorization Modules Are Enabled - 'Loaded ldap* modules'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

CONFIGURATION MANAGEMENT

2.1 Ensure that authentication is enabled for Cassandra databasesCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

2.2.5 Ensure 'OS_ROLES' Is Set to 'FALSE'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

2.2.8 Ensure 'REMOTE_OS_AUTHENT' Is Set to 'FALSE'CIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

IDENTIFICATION AND AUTHENTICATION

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

4.3 Ensure 'DBA_USERS.AUTHENTICATION_TYPE' Is Not Set to 'EXTERNAL' for Any UserCIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

IDENTIFICATION AND AUTHENTICATION

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/at.deny'CIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - at.denyCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

5.2.12 Ensure SSH PermitUserEnvironment is disabledCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

5.2.17 Ensure SSH LoginGraceTime is set to one minute or lessCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.4.1.1 Ensure password expiration is 90 days or less - login.defsCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.3 Ensure password expiration warning days is 7 or more - login.defsCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.4.2 Ensure system accounts are securedCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate UIDs existCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate UIDs existCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

6.2.19 Ensure no duplicate group names existCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

Accounts: Guest account statusMSCT Windows 10 1809 v1.0.0Windows

ACCESS CONTROL

Allow log on locallyMSCT Windows 10 v2004 v1.0.0Windows

ACCESS CONTROL

Allow log on locallyMSCT Windows Server 1903 DC v1.19.9Windows

ACCESS CONTROL

Allow log on through Remote Desktop ServicesMSCT Windows Server 1903 DC v1.19.9Windows

ACCESS CONTROL

Allow log on through Remote Desktop ServicesMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Allow log on through Remote Desktop ServicesMSCT Windows Server v20H2 DC v1.0.0Windows

ACCESS CONTROL

Deny access to this computer from the networkMSCT Windows 10 v2004 v1.0.0Windows

ACCESS CONTROL

Deny access to this computer from the networkMSCT Windows 10 v20H2 v1.0.0Windows

ACCESS CONTROL

Deny access to this computer from the networkMSCT Windows 10 v21H2 v1.0.0Windows

ACCESS CONTROL

Deny access to this computer from the networkMSCT Windows Server v1909 MS v1.0.0Windows

ACCESS CONTROL

Deny access to this computer from the networkMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Deny log on as a batch jobMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Deny log on locallyMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Deny log on locallyMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows 10 1903 v1.19.9Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows 10 v20H2 v1.0.0Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Ensure password expiration is 365 days or lessTenable Cisco Firepower Management Center OS Best Practices AuditUnix

IDENTIFICATION AND AUTHENTICATION

Ensure password expiration warning days is 7 or moreTenable Cisco Firepower Management Center OS Best Practices AuditUnix

IDENTIFICATION AND AUTHENTICATION

Ensure password fields are not emptyTenable Cisco Firepower Management Center OS Best Practices AuditUnix

IDENTIFICATION AND AUTHENTICATION

Generate security auditsMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Generate security auditsMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows 10 v2004 v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows Server v2004 DC v1.0.0Windows

ACCESS CONTROL

Microsoft network server: Disconnect clients when logon hours expireMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Modify an object labelMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Modify an object labelMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Network security: Allow Local System to use computer identity for NTLMMSCT Windows Server 2012 R2 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: Force logoff when logon hours expireMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Network security: Force logoff when logon hours expireMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL