Item Search

NameAudit NamePluginCategory
1.1.8 Ensure that the etcd pod specification file ownership is set to root:rootCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

ACCESS CONTROL

1.2.5 Ensure Exec Timeout for Remote Administrative Sessions (VTY) is set to less than 10CIS Cisco NX-OS v1.2.0 L1Cisco

CONFIGURATION MANAGEMENT, MAINTENANCE

2.2.2 Ensure administrator password retries and lockout time are configuredCIS Fortigate 7.0.x v1.4.0 L1FortiGate

ACCESS CONTROL

3.5 Ensure the SQL Server's MSSQL Service Account is Not an AdministratorCIS Microsoft SQL Server 2025 v1.0.0 L1 Database Engine WindowsWindows

ACCESS CONTROL

3.5 Ensure the SQL Server's MSSQL Service Account is Not an AdministratorCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine WindowsWindows

ACCESS CONTROL

3.6 Ensure the SQL Server's SQLAgent Service Account is Not an AdministratorCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS WindowsWindows

ACCESS CONTROL

3.6 Ensure the SQL Server's SQLAgent Service Account is Not an AdministratorCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.7 Ensure the SQL Server's Full-Text Service Account is Not an AdministratorCIS Microsoft SQL Server 2025 v1.0.0 L1 Database Engine WindowsWindows

ACCESS CONTROL

3.14 Ensure 'Control Server' permission is not grantedCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

4.1.4 Ensure that default service accounts are not actively usedCIS Google Kubernetes Engine GKE Autopilot v2.0.0 L1GCP

ACCESS CONTROL

4.1.4 Ensure that default service accounts are not actively usedCIS Google Kubernetes Engine GKE v2.0.0 L1 GCPGCP

ACCESS CONTROL

4.3.1 Ensure sudo is installedCIS CentOS Linux 7 v4.0.0 L1 ServerUnix

ACCESS CONTROL

4.3.5 Ensure re-authentication for privilege escalation is not disabled globallyCIS CentOS Linux 7 v4.0.0 L1 ServerUnix

ACCESS CONTROL

4.7 Ensure the set_user extension is installedCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

4.7 Ensure the set_user extension is installedCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

4.8 Ensure the set_user extension is installedCIS PostgreSQL 13 v1.3.0 L1 Database PostgreSQLDBPostgreSQLDB

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Rocky Linux 8 v3.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Rocky Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.1 Privilege escalation: sudoCIS IBM AIX 7.1 L2 v2.1.0Unix

ACCESS CONTROL

5.2.6 Ensure sudo authentication timeout is configured correctlyCIS Oracle Linux 9 v2.0.0 L1 WorkstationUnix

ACCESS CONTROL

5.2.6 Ensure sudo authentication timeout is configured correctlyCIS Red Hat Enterprise Linux 9 v2.0.0 L1 ServerUnix

ACCESS CONTROL

5.2.6 Ensure sudo timestamp_timeout is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

ACCESS CONTROL

5.3.1 Ensure that Azure Admin Accounts Are Not Used for Daily OperationsCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

5.3.4 Ensure users must provide password for escalationCIS CentOS Linux 8 Server L2 v2.0.0Unix

ACCESS CONTROL

5.3.4 Ensure users must provide password for escalationCIS Fedora 28 Family Linux Server L2 v2.0.0Unix

ACCESS CONTROL

5.3.5 Ensure re-authentication for privilege escalation is not disabled globallyCIS CentOS Linux 8 Server L1 v2.0.0Unix

ACCESS CONTROL

5.3.5 Ensure re-authentication for privilege escalation is not disabled globallyCIS Fedora 28 Family Linux Server L1 v2.0.0Unix

ACCESS CONTROL

5.3.5 Ensure re-authentication for privilege escalation is not disabled globallyCIS Fedora 28 Family Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.3.6 Ensure 'Tenant Creator' Role Assignments are Periodically ReviewedCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

ACCESS CONTROL

5.5 Ensure the 'root' Account Is DisabledCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

ACCESS CONTROL

5.5 Ensure the "root" Account Is DisabledCIS Apple macOS 12.0 Monterey v4.0.0 L1Unix

ACCESS CONTROL

5.6 Adding authorised users in cron.allowCIS IBM AIX 7.1 L1 v2.1.0Unix

ACCESS CONTROL

9.7 Verify No UID 0 Accounts Exist Other than rootCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL

18.4.1 Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

ACCESS CONTROL

18.9.90.2 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled'CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DCWindows

ACCESS CONTROL

18.10.4.2 (L1) Ensure 'Not allow per-user unsigned packages to install by default (requires explicitly allow per install)' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.4.2 (L1) Ensure 'Not allow per-user unsigned packages to install by default (requires explicitly allow per install)' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NGWindows

CONFIGURATION MANAGEMENT

18.10.4.2 Ensure 'Not allow per-user unsigned packages to install by default (requires explicitly allow per install)' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.10.4.2 Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.4.2 Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.10.4.2 Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

CONFIGURATION MANAGEMENT

18.10.4.3 (L1) Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 NGWindows

CONFIGURATION MANAGEMENT

18.10.4.3 Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.10.81.2 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled'CIS Windows Server 2012 DC L1 v3.0.0Windows

ACCESS CONTROL

18.10.81.2 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled'CIS Windows Server 2012 MS L1 v3.0.0Windows

ACCESS CONTROL

55.4 Ensure 'Block Non Admin User Install' is set to 'Allow'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

CONFIGURATION MANAGEMENT