Item Search

NameAudit NamePluginCategory
1.4 (L2) Ensure the default value of individual salt per vm is configuredCIS VMware ESXi 7.0 v1.5.0 L2VMware

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.38 OL09-00-000220CIS Oracle Linux 9 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.142 ALMA-09-018720CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.252 ALMA-09-031700CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.2 Configure Security Auditing Flags per local organizational requirements - 'audit successful/failed file deletion events'CIS Apple macOS 10.13 L2 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

3.3 Ensure Auto-Scaling Launch Configuration for Web-Tier is configured to use an approved Amazon Machine ImageCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

CONFIGURATION MANAGEMENT

3.4 Ensure 'slow_query_log' Has Appropriate PermissionsCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.4 Ensure 'slow_query_log' Has Appropriate PermissionsCIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.4 Ensure 'slow_query_log' Has Appropriate PermissionsCIS Oracle MySQL Community Server 9.7 v1.0.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.4 Ensure 'slow_query_log' Has Appropriate PermissionsCIS Oracle MySQL Community Server 8.0 v1.2.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.4 Ensure Auto-Scaling Launch Configuration for App-Tier is configured to use an approved Amazon Machine ImageCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

CONFIGURATION MANAGEMENT

3.6 Ensure 'general_log_file' Has Appropriate PermissionsCIS Oracle MySQL Enterprise Edition 8.4 v1.1.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.6 Ensure 'general_log_file' Has Appropriate PermissionsCIS Oracle MySQL Enterprise Edition 9.7 v1.0.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.6 Ensure 'general_log_file' Has Appropriate PermissionsCIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

5.4.1.2 Ensure password expiration is 365 days or lessCIS SUSE Linux Enterprise 12 v3.2.1 L1 ServerUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.1.5 Ensure the Guest Home Folder Does Not ExistCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.1.5 Ensure the Guest Home Folder Does Not ExistCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.2.3.1 Ensure modification of the /etc/sudoers file is collectedCIS Debian Linux 13 v1.1.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.6 Ensure events that modify /etc/issue and /etc/issue.net are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.6 Ensure events that modify /etc/issue and /etc/issue.net are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.17 Ensure events that modify /etc/pam.conf and /etc/pam.d/ information are collectedCIS Debian Linux 13 v1.1.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.22 Ensure unlink file deletion events by users are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.23 Ensure login and logout events are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.31 Ensure kernel "delete_module" loading unloading and modification is collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.31 Ensure kernel module loading unloading and modification is collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.9 Ensure events that modify /etc/NetworkManager directory are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.9 Ensure events that modify /etc/NetworkManager directory are collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.12 Ensure events that modify /etc/group information are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.13 Ensure events that modify /etc/passwd information are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.15 Ensure events that modify /etc/security/opasswd are collectedCIS Rocky Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.16 Ensure events that modify /etc/nsswitch.conf file are collectedCIS AlmaLinux OS 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.16 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.21 Ensure successful file system mounts are collectedCIS Rocky Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.21 Ensure successful file system mounts are collectedCIS Rocky Linux 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.21 Ensure successful file system mounts are collectedCIS AlmaLinux OS 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.31 Ensure kernel module loading unloading and modification is collectedCIS AlmaLinux OS 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.31 Ensure kernel module loading unloading and modification is collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.32 Ensure kernel "init_module" and "finit_module" loading unloading and modification is collectedCIS Oracle Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.32 Ensure kernel "init_module" and "finit_module" loading unloading and modification is collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.32 Ensure kernel "init_module" and "finit_module" loading unloading and modification is collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.3.34 Ensure kernel query_module loading unloading and modification is collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.34 Ensure kernel query_module loading unloading and modification is collectedCIS Rocky Linux 10 v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

7.1 Ensure 'Symmetric Key encryption algorithm' is set to 'AES_128' or higher in non-system databasesCIS SQL Server 2017 Database L1 DB v1.3.0MS_SQLDB

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

BIND-9X-001590 - On the BIND 9.x server, a zone file must not include resource records that resolve to a fully qualified domain name residing in another zone.DISA BIND 9.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

EP11-00-004820 - When using command-line tools such as psql, users must use a logon method that does not expose the password.EDB PostgreSQL Advanced Server v11 DB Audit v2r4PostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

EPAS-00-004800 - When using command-line tools such as psql, users must use a logon method that does not expose the password.EnterpriseDB PostgreSQL Advanced Server DB v2r1PostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

F5BI-DN-300030 - The validity period for the RRSIGs covering the DS RR for a zones delegated children must be no less than two days and no more than one week.DISA F5 BIG-IP TMOS DNS STIG v1r1F5

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-251010 - RHEL 9 must have the firewalld package installed.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

RHEL-10-200530 - RHEL 10 must have the "firewalld" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT