Item Search

NameAudit NamePluginCategory
1.2.1.8 Ensure 'Scripted Window Security Restrictions' is set to Enabled - exprwd.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.8 Ensure 'Scripted Window Security Restrictions' is set to Enabled - spDesign.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.9 Ensure 'Local Machine Zone Lockdown Security' is set to Enabled - excel.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.9 Ensure 'Local Machine Zone Lockdown Security' is set to Enabled - outlook.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.9 Ensure 'Local Machine Zone Lockdown Security' is set to Enabled - spDesign.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.3.1 Ensure 'Block Flash activation in Office documents' is set to 'Enabled: Block all activation'CIS Microsoft Office Enterprise v1.2.0 L1Windows

CONFIGURATION MANAGEMENT

2.3.9.5 (L1) Ensure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client' or higherCIS Microsoft Windows Server 2019 Stand-alone v2.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.9.5 (L1) Ensure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client' or higher (MS only)CIS Microsoft Windows Server 2016 v3.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.9.5 (L1) Ensure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client' or higher (MS only)CIS Microsoft Windows Server 2025 v1.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.9.5 Ensure 'Microsoft network server: Server SPN target name validation level' is set to 'Accept if provided by client' or higher (MS only)CIS Microsoft Windows Server 2019 STIG v3.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.4 Configure TCP Wrappers - enable tcp_wrappers for inetdCIS Solaris 10 L1 v5.2Unix
2.4 Configure TCP Wrappers - enable tcp_wrappers for rpc/bind. Note: This check is recommended by CIS, but not required.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Configure TCP Wrappers - Make sure that /etc/hosts.deny does exist.CIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

2.11.1.2 Ensure 'Disable UI Extending from Documents and Templates' is set to Enabled - AccessCIS Microsoft Office 2016 v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.11.1.2 Ensure 'Disable UI Extending from Documents and Templates' is set to Enabled - WordCIS Microsoft Office 2016 v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.17.1 Ensure 'Prevent Users From Changing Permissions on Rights Managed Content' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

ACCESS CONTROL

2.17.3 Ensure 'Always Require Users to Connect to Verify Permission' is set to EnabledCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

2.22.1 Ensure 'Block Opening of Pre-Release Versions of File Formats New to PowerPoint ...' is set to EnabledCIS Microsoft Office 2016 v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.24.1.2 Ensure 'Enable Customer Experience Improvement Program' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

2.24.1.3 Ensure 'Allow including screenshot with Office Feedback' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

2.24.1.4 Ensure 'Send Office Feedback' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

2.25.6 Ensure 'Protect Document Metadata for Password Protected Files' is set to EnabledCIS Microsoft Office 2016 v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.25.7 Ensure 'Load Controls in Forms3' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

2.25.10 Ensure 'Disable Password to Open UI' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.25.13 Ensure 'ActiveX Control Initialization' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

2.27.1.1 Ensure 'Disable Internet Fax Feature' is set to EnabledCIS Microsoft Office 2016 v1.1.0Windows

ACCESS CONTROL

2.29.2 Ensure 'Legacy Format Signatures' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.35.3.1 Ensure 'Open Office Documents as Read/Write While Browsing' is set to DisabledCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

3.3 Enable Stack Protection - Makes sure 'noexec_user_stack_log' is set to 1 in /etc/system. Note: Only applicable if NX bit is set.CIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.3 Enable Debug Level Daemon Logging - Check if daemon.debug is set to /var/log/connlogCIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.3 Enable Debug Level Daemon Logging - Check if permissions for /var/log/connlog are OK.CIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.3 Enable Debug Level Daemon Logging/4.4 Capture syslog AUTH Messages - Check if svc:/system/system-log is onlineCIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.4 Capture syslog AUTH Messages - Check if auth.info is set to var/log/authlogCIS Solaris 10 L1 v5.2Unix
7.2 Set Password Expiration Parameters on Active Accounts - Check MAXWEEKS is set to 13CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Password Expiration Parameters on Active Accounts - Check MINWEEKS is set to 1CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Password Expiration Parameters on Active Accounts - Check WARNWEEKS is set to 4CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - Check DICTIONDBDIR is set to /var/passwdCIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - Check MAXREPEATS is set to 0CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - Check MINDIFF is set to 3CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - Check MINLOWER is set to 1CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - Check NAMECHECK is set to YESCIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - Check PASSLENGTH is set to 8CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - MINALPHA is set to 2CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - MINNONALPHA is set to 1CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.8 Set 'mesg n' as Default for All Users in /etc/.loginCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

7.8 Set 'mesg n' as Default for All Users in /etc/profileCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

7.9 Lock Inactive User Accounts - Check if definact is set to 35.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

8.2 Create Warning Banner for CDE Users - Check if 'Dtlogin*greeting.labelString' is not set to default string.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

8.2 Create Warning Banner for CDE Users - Check if file permissions for files under /etc/dt/config/*/Xresources are OK.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

18.8.53.1.2 (L2) Ensure 'Enable Windows NTP Server' is set to 'Disabled' (MS only)CIS Microsoft Windows Server 2008 Member Server Level 2 v3.3.1Windows

AUDIT AND ACCOUNTABILITY