Item Search

NameAudit NamePluginCategory
1.1.3 Configure Secure Password Policy - Minimum Password LengthCIS F5 Networks v1.0.0 L1F5

IDENTIFICATION AND AUTHENTICATION

1.1.3 Configure Secure Password Policy - Required UppercaseCIS F5 Networks v1.0.0 L1F5

IDENTIFICATION AND AUTHENTICATION

1.1.5.3.1 Set 'Windows Firewall: Public: Outbound connections' to 'Allow (default)'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.5.3.2 Set 'Windows Firewall: Public: Apply local firewall rules' to 'Yes (default)'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.5.3.4 Set 'Windows Firewall: Public: Logging: Log dropped packets' to 'Yes'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.5.3.6 Set 'Windows Firewall: Public: Allow unicast response' to 'No'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.1.1 Configure 'Set IP Stateless Autoconfiguration Limits State'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.3.1.1 Configure 'Turn off access to the Store'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.3.1.9 Set 'Turn off printing over HTTP' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.3.2.4 Set 'Do not enumerate connected users on domain-joined computers' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.2.3.11 Set 'Select update server:' to 'Enabled:Search Managed Server'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.4.2.1.3 Set 'Configure use of passwords for fixed data drives' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.9 Set 'Allow data recovery agent' to 'True'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.12 Set 'Configure storage of BitLocker recovery information to AD DS:' to 'Backup recovery passwords and key packages'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.14 Set 'Omit recovery options from the BitLocker setup wizard' to 'True'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.16 Set 'Require use of smart cards on fixed data drives' to 'True'CIS Windows 8 L1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.17 Configure 'Deny write access to fixed drives not protected by BitLocker'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.1 Set 'Configure use of hardware-based encryption for operating system drives' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.3 Set 'Configure use of passwords for operating system drives' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.4 Set 'Recovery Key' to 'Do not allow 256-bit recovery key'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.8 Set 'Restrict encryption algorithms and cipher suites allowed for hardware-based encryption' to 'False'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.12 Set 'Configure storage of BitLocker recovery information to AD DS:' to 'Store recovery passwords and key packages'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.18 Set 'Configure TPM startup PIN:' to 'Require startup PIN with TPM'CIS Windows 8 L1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.28 Set 'Minimum characters:' to 'Enabled:7 or more characters'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.2.4.2.2.29 Configure 'Allow network unlock at startup'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.3.9 Set 'Allow data recovery agent' to 'True'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.3.10 Set 'Choose how BitLocker-protected removable drives can be recovered' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.3.13 Set 'Save BitLocker recovery information to AD DS for removable data drives' to 'False'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.3.15 Set 'Configure use of smart cards on removable data drives' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.3.18 Set 'Allow access to BitLocker-protected removable data drives from earlier versions of Windows' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.5.4 Set 'Always prompt for password upon connection' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.2.4.6.4 Set 'Disallow WinRM from storing RunAs credentials' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.2.4.7.8 Set 'No auto-restart with logged on users for scheduled automatic updates installations' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

1.2.4.7.9 Set 'Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

1.2.4.9 Set 'Turn off Data Execution Prevention for Explorer' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.4.12 Configure 'Allow deployment operations in special profiles'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.4.16 Set 'Allow Remote Shell Access' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.7.2 Ensure GDM login banner is configuredCIS Debian Linux 12 v1.1.0 L1 WorkstationUnix

ACCESS CONTROL

1.7.2 Ensure GDM login banner is configuredCIS Debian Linux 12 v1.1.0 L1 ServerUnix

ACCESS CONTROL

2.4.5 Disable Remote LoginCIS Apple OSX 10.9 L1 v1.3.0Unix

ACCESS CONTROL

2.6 Ensure External Users' Terminal Access is DisabledCIS F5 Networks v1.0.0 L1F5

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.13 Configure 'Turn off toast notifications on the lock screen'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

4.5 Ensure minimum SSH Encryption algorithm is set to aes128-cbcCIS F5 Networks v1.0.0 L1F5

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.8 Ensure access SSH to CLI interface is restricted to needed IP addresses onlyCIS F5 Networks v1.0.0 L1F5

ACCESS CONTROL, CONFIGURATION MANAGEMENT

5.2 Ensure to exclude inode information from ETags HTTP HeaderCIS F5 Networks v1.0.0 L1F5

ACCESS CONTROL, CONFIGURATION MANAGEMENT

5.3 Ensure port lockdown for self IP is setCIS F5 Networks v1.0.0 L1F5

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.1 Ensure that SNMP access is allowed to trusted agents IPs onlyCIS F5 Networks v1.0.0 L1F5

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.7.1.2 (BL) Ensure 'Prevent installation of devices that match any of these device IDs: Prevent installation of devices that match any of these device IDs' is set to 'PCI\CC_0C0A'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.9.7.1.2 (BL) Ensure 'Prevent installation of devices that match any of these device IDs: Prevent installation of devices that match any of these device IDs' is set to 'PCI\CC_0C0A'CIS Microsoft Windows 10 Stand-alone v4.0.0 BLWindows

MEDIA PROTECTION

18.9.7.1.6 (L1) Ensure 'Prevent installation of devices that match any of these device IDs: Prevent installation of devices that match any of these device IDs' is set to 'PCI\CC_0C0A'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION