Item Search

NameAudit NamePluginCategory
1.3 Disable all management related services on WAN portCIS Fortigate 7.0.x v1.3.0 L1FortiGate

ACCESS CONTROL, CONFIGURATION MANAGEMENT

2.1 (L1) Ensure NTP time synchronization is configured properlyCIS VMware ESXi 7.0 v1.5.0 L1VMware

AUDIT AND ACCOUNTABILITY

2.1.4 Ensure correct system time is configured through NTPCIS Fortigate 7.0.x v1.3.0 L1FortiGate

AUDIT AND ACCOUNTABILITY

2.1.6 Ensure the latest firmware is installedCIS Fortigate 7.0.x v1.3.0 L2FortiGate

SECURITY ASSESSMENT AND AUTHORIZATION, RISK ASSESSMENT

2.4.3 Ensure admin accounts with different privileges have their correct profiles assignedCIS Fortigate 7.0.x v1.3.0 L1FortiGate

ACCESS CONTROL

2.4.8 Virtual patching on the local-in management interfaceCIS Fortigate 7.0.x v1.3.0 L1FortiGate

SECURITY ASSESSMENT AND AUTHORIZATION, RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.5.1 Ensure High Availability configuration is enabledCIS Fortigate 7.0.x v1.3.0 L2FortiGate

ACCESS CONTROL, CONFIGURATION MANAGEMENT

2.5.3 Ensure HA Reserved Management Interface is configuredCIS Fortigate 7.0.x v1.3.0 L1FortiGate

ACCESS CONTROL, CONFIGURATION MANAGEMENT

2.6 (L1) Ensure dvfilter API is not configured if not usedCIS VMware ESXi 7.0 v1.5.0 L1VMware

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

3.3 (L1) Ensure remote logging is configured for ESXi hostsCIS VMware ESXi 7.0 v1.5.0 L1VMware

AUDIT AND ACCOUNTABILITY

3.4 Ensure logging is enabled on all firewall policiesCIS Fortigate 7.0.x v1.3.0 L1FortiGate

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

4.1.1 Detect Botnet connectionsCIS Fortigate 7.0.x v1.3.0 L2FortiGate

SYSTEM AND INFORMATION INTEGRITY

4.2.1 Ensure Antivirus Definition Push Updates are ConfiguredCIS Fortigate 7.0.x v1.3.0 L2FortiGate

SYSTEM AND INFORMATION INTEGRITY

4.3.4 Ensure 'disableIssChecking' issuer claim is set to 'false' in the RP (Relying Party)CIS IBM WebSphere Liberty v1.0.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.4 (L1) Ensure account lockout is set to 15 minutesCIS VMware ESXi 7.0 v1.5.0 L1VMware

ACCESS CONTROL

4.7 (L1) Ensure only authorized users and groups belong to the esxAdminsGroup groupCIS VMware ESXi 7.0 v1.5.0 L1VMware

ACCESS CONTROL

5.1.1 Enable Compromised Host QuarantineCIS Fortigate 7.0.x v1.3.0 L1FortiGate

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2 (L1) Ensure the ESXi shell is disabledCIS VMware ESXi 7.0 v1.5.0 L1VMware

CONFIGURATION MANAGEMENT

5.2.1.1 Ensure Security Fabric is ConfiguredCIS Fortigate 7.0.x v1.3.0 L2FortiGate

CONFIGURATION MANAGEMENT

5.4 (L1) Ensure CIM access is limitedCIS VMware ESXi 7.0 v1.5.0 L1VMware

CONFIGURATION MANAGEMENT

5.5 (L1) Ensure Normal Lockdown mode is enabledCIS VMware ESXi 7.0 v1.5.0 L1VMware

ACCESS CONTROL

7.3.1 Centralized Logging and ReportingCIS Fortigate 7.0.x v1.3.0 L2FortiGate

AUDIT AND ACCOUNTABILITY

7.5 (L1) Ensure port groups are not configured to VLAN values reserved by upstream physical switchesCIS VMware ESXi 7.0 v1.5.0 L1VMware

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.6 (L1) Ensure port groups are not configured to VLAN 4095 and 0 except for Virtual Guest Tagging (VGT)CIS VMware ESXi 7.0 v1.5.0 L1VMware

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

8.2 Block Reported Web ForgeriesCIS Mozilla Firefox 102 ESR Linux L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

8.2 Block Reported Web ForgeriesCIS Mozilla Firefox 102 ESR Windows L1 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

8.2.2 (L2) Ensure unnecessary CD/DVD devices are disconnectedCIS VMware ESXi 7.0 v1.5.0 L2VMware

CONFIGURATION MANAGEMENT

8.2.8 (L1) Ensure PCI and PCIe device passthrough is disabledCIS VMware ESXi 7.0 v1.5.0 L1VMware

CONFIGURATION MANAGEMENT

8.4.1 (L1) Ensure access to VMs through the dvfilter network APIs is configured correctlyCIS VMware ESXi 7.0 v1.5.0 L1VMware

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

8.4.4 (L2) Ensure Guest Host Interaction Protocol Handler is set to disabledCIS VMware ESXi 7.0 v1.5.0 L2VMware

CONFIGURATION MANAGEMENT

8.4.5 (L2) Ensure Unity Taskbar is disabledCIS VMware ESXi 7.0 v1.5.0 L2VMware

CONFIGURATION MANAGEMENT

8.4.6 (L2) Ensure Unity Active is disabledCIS VMware ESXi 7.0 v1.5.0 L2VMware

CONFIGURATION MANAGEMENT

8.4.11 (L2) Ensure Shell Action is disabledCIS VMware ESXi 7.0 v1.5.0 L2VMware

CONFIGURATION MANAGEMENT

8.4.13 (L2) Ensure Trash Folder State is disabledCIS VMware ESXi 7.0 v1.5.0 L2VMware

CONFIGURATION MANAGEMENT

8.4.24 (L1) Ensure VM Console Paste operations are disabledCIS VMware ESXi 7.0 v1.5.0 L1VMware

CONFIGURATION MANAGEMENT

8.7.2 (L2) Ensure host information is not sent to guestsCIS VMware ESXi 7.0 v1.5.0 L2VMware

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

BIND-9X-001400 - On a BIND 9.x server for zones split between the external and internal sides of a network, the RRs for the external hosts must be separate from the RRs for the internal hosts.DISA BIND 9.x STIG v2r3Unix

CONFIGURATION MANAGEMENT

EX13-EG-000310 - Exchange software must be installed on a separate partition from the OS.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000620 - Exchange software must be installed on a separate partition from the OS.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r5Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-ED-000230 - Exchange software must be installed on a separate partition from the OS.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

VCLU-80-000070 The vCenter Lookup service must set an inactive timeout for sessions.DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r1Unix

ACCESS CONTROL

VCSA-80-000057 - vCenter Server plugins must be verified.DISA VMware vSphere 8.0 vCenter STIG v2r2VMware

CONFIGURATION MANAGEMENT

VCST-80-000070 The vCenter STS service must set an inactive timeout for sessions.DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) STIG v2r1Unix

ACCESS CONTROL

VCUI-67-000026 - vSphere UI must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the web server.DISA STIG VMware vSphere 6.7 UI Tomcat v1r3Unix

AUDIT AND ACCOUNTABILITY

WA000-WWA066 A22 - The HTTP request line must be limited.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA066 A22 - The HTTP request line must be limited.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00612 A22 - The sites error logs must log the correct format.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WA00615 A22 - System logging must be enabled.DISA STIG Apache Site 2.2 Unix v1r11Unix

AUDIT AND ACCOUNTABILITY

WBSP-AS-000090 - The WebSphere Application Server users WebSphere auditor role must be configured in accordance with System Security Plan.DISA IBM WebSphere Traditional 9 STIG v1r1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

WBSP-AS-000090 - The WebSphere Application Server users WebSphere auditor role must be configured in accordance with System Security Plan.DISA IBM WebSphere Traditional 9 STIG v1r1 MiddlewareUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY