Item Search

NameAudit NamePluginCategory
1.1 Remove extraneous files and directories - /conf/Catalina/localhost/manager.xmlCIS Apache Tomcat 8 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

1.1 Remove extraneous files and directories - /webapps/js-examplesCIS Apache Tomcat 8 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

1.1 Remove extraneous files and directories - /webapps/servlet-exampleCIS Apache Tomcat 8 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

1.1 Remove extraneous files and directories - /webapps/tomcat-docsCIS Apache Tomcat 8 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

1.1 Remove extraneous files and directories - CATALINA_HOME/server/webapps/managerCIS Apache Tomcat 8 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

1.1 Remove extraneous files and directories - CATALINA_HOME/webapps/ROOT/adminCIS Apache Tomcat 8 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

1.1.6 - AirWatch - Disable Access to Control Center on Lock ScreenAirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

1.1.6 - MobileIron - Disable Access to Control Center on Lock ScreenMobileIron - CIS Apple iOS 9 v1.0.0 L2MDM

ACCESS CONTROL

1.1.6 Ensure that the --insecure-bind-address argument is not setCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.10 - MobileIron - Turn off Auto-Join for all Wi-Fi networksMobileIron - CIS Apple iOS 8 v1.0.0 L2MDM

ACCESS CONTROL

1.1.16 - AirWatch - Disable View in Lock Screen for apps when device is lockedAirWatch - CIS Apple iOS 9 v1.0.0 L2MDM

ACCESS CONTROL

1.1.16 - MobileIron - Disable 'developer options' - 'USB Debug'MobileIron - CIS Google Android 4 v1.0.0 L1MDM

ACCESS CONTROL

1.1.16 - MobileIron - Disable View in Lock Screen for apps when device is lockedMobileIron - CIS Apple iOS 9 v1.0.0 L2MDM

ACCESS CONTROL

1.2.1 - AirWatch - Disable JavaScriptAirWatch - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

1.2.1 - MobileIron - Disable JavaScript - 'Samsung SAFE'MobileIron - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

1.2.2 - AirWatch - Enable Fraudulent Website WarningAirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

1.2.5 - AirWatch - Disable Auto Fill for Credit Card InformationAirWatch - CIS Apple iOS 8 v1.0.0 L2MDM

ACCESS CONTROL

1.2.7 - AirWatch - Disable 'Remember passwords'AirWatch - CIS Google Android 4 v1.0.0 L1MDM

ACCESS CONTROL

2.1.3 Ensure discard services are not enabled - discard-dgramCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.6 Ensure rsh server is not enabled - rexecCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.9 Ensure Telnet is disabledCIS Check Point Firewall L1 v1.1.0CheckPoint

CONFIGURATION MANAGEMENT

2.2.3 Ensure Avahi Server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.8 Ensure DNS Server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.3.16.1 Ensure 'System settings: Optional subsystems' is set to 'Defined: (blank)'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT

2.4.3 Disable Screen SharingCIS Apple macOS 10.12 L1 v1.2.0Unix

CONFIGURATION MANAGEMENT

2.4.8 Disable File Sharing - SMBCIS Apple macOS 10.13 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.4.9 Disable Remote ManagementCIS Apple macOS 10.13 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.6 Ensure TLS authentication for Docker daemon is configured --tlskeyCIS Docker Community Edition v1.1.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1.5 Ensure that the --insecure-port argument is set to 0CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

3.1.14 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

ACCESS CONTROL

3.2 Ensure that MongoDB only listens for network connections on authorized interfacesCIS MongoDB 3.2 L1 Unix Audit v1.0.0Unix

CONFIGURATION MANAGEMENT

3.2 Ensure that MongoDB only listens for network connections on authorized interfacesCIS MongoDB 3.2 L1 Windows Audit v1.0.0Windows

CONFIGURATION MANAGEMENT

3.2 Restrict Recursive Queries - Authoritative Name ServerCIS BIND DNS v3.0.1 Authoritative Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.3 Disable DAS discoverabilityCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS WindowsWindows

CONFIGURATION MANAGEMENT

3.3.4 Prevent execution of expired tasksCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS WindowsWindows

CONFIGURATION MANAGEMENT

3.3.7 Disable unused task schedulerCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS WindowsWindows

CONFIGURATION MANAGEMENT

3.5.4 Ensure TIPC is disabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

4.5 Ensure nfs server is not runningCIS Apple macOS 10.13 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

5.1.4 Ensure talk server is not enabledCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.1.7 Ensure tftp-server is not enabledCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.2 Ensure chargen is not enabledCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.7 Ensure privileged ports are not mapped within containersCIS Docker Community Edition v1.1.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

8.2.6 Accept Remote rsyslog Messages Only on Designated Log Hosts - InputTCPServerRun - Syslog ServerCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

9.4 Remove Default DatabasesCIS IBM DB2 v10 v1.1.0 Windows OS Level 2Windows

CONFIGURATION MANAGEMENT

13.10 Check for Presence of User .rhosts FilesCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

18.5.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Windows 7 Workstation Level 2 v3.2.0Windows

CONFIGURATION MANAGEMENT

18.8.37.1 Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

IDENTIFICATION AND AUTHENTICATION

18.9.59.3.3.4 Ensure 'Do not allow supported Plug and Play device redirection' is set to 'Enabled'CIS Windows 7 Workstation Level 2 v3.2.0Windows

CONFIGURATION MANAGEMENT

Ensure talk server is not enabled - ntalkTenable Cisco Firepower Management Center OS Best Practices AuditUnix

CONFIGURATION MANAGEMENT

Restrict Unauthenticated RPC clientsMSCT Windows Server 2019 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION