Item Search

NameAudit NamePluginCategory
1.6.1.1 Ensure SELinux is not disabled in bootloader configuration - selinuxCIS Aliyun Linux 2 L2 v1.0.0Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcing - /etc/selinux/configCIS Aliyun Linux 2 L2 v1.0.0Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcing - sestatusCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.3 Ensure SELinux policy is configuredCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.6.1.4 Ensure all AppArmor Profiles are enforcing - loadedCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure the SELinux mode is enforcing or permissive - configCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure the SELinux mode is enforcing or permissive - getenforceCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

1.6.1.7 Ensure SETroubleshoot is not installedCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

1.6.2.2 Ensure all AppArmor Profiles are enforcing - complain modeCIS Debian 9 Server L2 v1.0.1Unix

ACCESS CONTROL

1.7.1.1 Ensure SELinux is installedCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.2 Ensure AppArmor is enabled in the bootloader configuration - apparmor=1CIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.2 Ensure AppArmor is enabled in the bootloader configuration - apparmor=1CIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.2 Ensure AppArmor is enabled in the bootloader configuration - security=apparmorCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - 0 processes are unconfinedCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - profiles loadedCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.3 Ensure all AppArmor Profiles are in enforce or complain mode - profiles loadedCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.4 Ensure all AppArmor Profiles are enforcing - complain modeCIS Debian Family Server L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.4 Ensure all AppArmor Profiles are enforcing - profiles loadedCIS Debian Family Workstation L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.7 Ensure SETroubleshoot is not installedCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

ACCESS CONTROL

2.3.10.11 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL NGWindows

ACCESS CONTROL

2.3.10.11 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

ACCESS CONTROL

2.3.10.11 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

ACCESS CONTROL

2.3.10.11 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

ACCESS CONTROL

2.3.10.11 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL

2.3.10.12 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

ACCESS CONTROL

5.2.2 Ensure permissions on SSH private host key files are configuredCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

5.2.2 Ensure permissions on SSH private host key files are configuredCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

5.3.2 Ensure permissions on SSH private host key files are configuredCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/pam.d/common-sessionCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.1.1 Audit system file permissionsCIS Debian Family Server L2 v1.0.0Unix

ACCESS CONTROL

6.1.1 Audit system file permissionsCIS Debian 9 Workstation L2 v1.0.1Unix

ACCESS CONTROL

6.1.10 Ensure no world writable files existCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

7.4 Ensure directory in context.xml is a secure location - configurationCIS Apache Tomcat 8 L1 v1.1.0Unix

ACCESS CONTROL

7.4 Ensure directory in context.xml is a secure location - configurationCIS Apache Tomcat 8 L1 v1.1.0 MiddlewareUnix

ACCESS CONTROL

7.6 Ensure directory in logging.properties is a secure location - check prefix application nameCIS Apache Tomcat 9 L1 v1.2.0Unix

ACCESS CONTROL

10.4 Set Default umask for Users - /etc/profile.d/*CIS Debian Linux 7 L1 v1.0.0Unix

ACCESS CONTROL

10.19 Setting Security Lifecycle Listener (check for umask uncommented in startup)CIS Apache Tomcat 7 L1 v1.1.0Unix

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 BLWindows

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows Server 2022 v5.1.0 L2 DCWindows

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows Server 2022 v5.1.0 L2 MSWindows

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BLWindows

ACCESS CONTROL

18.10.4.1 Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL NGWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 NGWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 L1 MSWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

ACCESS CONTROL

19.7.26.1 Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

ACCESS CONTROL