Item Search

NameAudit NamePluginCategory
1.1.1.8 Ensure usb-storage kernel module is not availableCIS Oracle Linux 9 v2.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.1.8 Ensure usb-storage kernel module is not availableCIS Red Hat Enterprise Linux 7 v4.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.1.8 Ensure usb-storage kernel module is not availableCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.1.8 Ensure usb-storage kernel module is not availableCIS Red Hat Enterprise Linux 9 v2.0.0 L1 ServerUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.1.8 Ensure usb-storage kernel module is not availableCIS Red Hat Enterprise Linux 9 v2.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.1.8 Ensure usb-storage kernel module is not availableCIS Rocky Linux 9 v2.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.1.9 Ensure usb-storage kernel module is not availableCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 ServerUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.1.9 Ensure usb-storage kernel module is not availableCIS Ubuntu Linux 20.04 LTS v3.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.1.9 Ensure usb-storage is disabledCIS Amazon Linux 2023 v1.0.0 L1 ServerUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.8.4 Ensure GDM automount is configuredCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION, MEDIA PROTECTION

1.13.4 Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Defender Antivirus v1.0.0 L1 WorkstationWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.13.4 Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Defender Antivirus v1.0.0 L1 ServerWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.13.5 Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Defender Antivirus v1.0.0 L1 ServerWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.13.5 Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Defender Antivirus v1.0.0 L1 WorkstationWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS Rocky Linux 9 v2.0.0 L1 ServerUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS Rocky Linux 9 v2.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS Linux Mint 22 v1.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS Red Hat Enterprise Linux 8 v4.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS SUSE Linux Enterprise 15 v2.0.1 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS Oracle Linux 10 v1.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure autofs services are not in useCIS Oracle Linux 8 v4.0.0 L2 WorkstationUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.2.1 Ensure autofs services are not in useCIS FreeBSD 14 v1.0.1 L1Unix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.2.1 Ensure autofs services are not in useCIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.9.7.1.3 (L1) Ensure 'Display a custom message when installation is prevented by a policy setting' is set to 'Enabled: <Text>'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL, MEDIA PROTECTION

18.10.9.3.2 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION

18.10.9.3.4 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Password' is set to 'Enabled: Do not allow 48-digit recovery password'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION

18.10.9.3.6 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION

18.10.10.3.2 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 BLWindows

MEDIA PROTECTION

18.10.10.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 BLWindows

MEDIA PROTECTION

18.10.10.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

MEDIA PROTECTION

18.10.10.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.10.3.2 Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

MEDIA PROTECTION

18.10.10.3.3 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'CIS Microsoft Windows 10 Enterprise v5.0.0 BLWindows

MEDIA PROTECTION

18.10.10.3.3 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.10.3.4 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Password' is set to 'Enabled: Do not allow 48-digit recovery password'CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

MEDIA PROTECTION

18.10.10.3.5 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.10.3.5 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL NGWindows

MEDIA PROTECTION

18.10.10.3.6 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True'CIS Microsoft Windows 10 Stand-alone v4.0.0 BLWindows

MEDIA PROTECTION

18.10.10.3.6 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True'CIS Microsoft Windows 11 Stand-alone v5.0.0 BLWindows

MEDIA PROTECTION

18.10.10.3.6 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2 BLWindows

MEDIA PROTECTION

18.10.10.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages'CIS Microsoft Windows 11 Enterprise v5.1.0 BLWindows

MEDIA PROTECTION

18.10.10.3.8 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages'CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

MEDIA PROTECTION

18.10.10.3.9 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for removable data drives' is set to 'Enabled: False'CIS Microsoft Windows 10 Enterprise v5.0.0 BLWindows

MEDIA PROTECTION

18.10.43.13.2 (L1) Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MSWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.3 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BLWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.3 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NGWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.3 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 NGWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.3 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 DCWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY