Item Search

NameAudit NamePluginCategory
1.4 Verify That the MYSQL_PWD Environment Variable Is Not In UseCIS MySQL 5.6 Community Linux OS L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.29 (L2) Configure 'Log on as a service'CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

ACCESS CONTROL

2.2.29 Configure 'Log on as a service'CIS Windows 7 Workstation Level 2 v3.2.0Windows

ACCESS CONTROL

5.7 Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT

5.42 (L2) Ensure 'WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc)' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

5.42 (L2) Ensure 'WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc)' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L2 BL NGWindows

CONFIGURATION MANAGEMENT

5.42 (L2) Ensure 'WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc)' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

5.42 (L2) Ensure 'WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc)' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L2 BL NGWindows

CONFIGURATION MANAGEMENT

17.7.3 Ensure 'Audit Audit Policy Change' is set to include 'Success and Failure' (STIG only)CIS Microsoft Windows Server 2019 STIG v3.0.0 STIG MSWindows

AUDIT AND ACCOUNTABILITY

18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGONCIS Microsoft Windows 8.1 v2.4.1 L1Windows

RISK ASSESSMENT

18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGONCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOLCIS Microsoft Windows 8.1 v2.4.1 L1Windows

RISK ASSESSMENT

18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOLCIS Azure Compute Microsoft Windows Server 2022 v1.0.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

18.10.9.3.3 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION

18.10.10.1.3 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'CIS Microsoft Windows 11 Stand-alone v4.0.0 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.3.8 (BL) Ensure 'Configure use of passwords for removable data drives' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v4.0.0 BLWindows

IDENTIFICATION AND AUTHENTICATION

18.10.10.3.8 (BL) Ensure 'Configure use of passwords for removable data drives' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BLWindows

IDENTIFICATION AND AUTHENTICATION

18.10.37.1 (L2) Ensure 'Turn off location' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

18.10.37.1 (L2) Ensure 'Turn off location' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L2 NGWindows

CONFIGURATION MANAGEMENT

18.10.37.1 (L2) Ensure 'Turn off location' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

18.10.93.4.1 (L1) Ensure 'Manage preview builds' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.10.93.4.1 (L1) Ensure 'Manage preview builds' is set to 'Disabled'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.10.93.4.1 (L1) Ensure 'Manage preview builds' is set to 'Disabled'CIS Microsoft Windows Server 2019 v4.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT

81.37 (L2) Ensure 'WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc)' is set to 'Disabled'CIS Microsoft Intune for Windows 11 v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

CIS_AlmaLinux_OS_8_Workstation_L2_v3.0.0.audit from CIS AlmaLinux OS 8 Benchmark v3.0.0CIS AlmaLinux OS 8 Workstation L2 v3.0.0Unix
CIS_Amazon_Linux_2_STIG_v2.0.0_L2_Server.audit from CIS Amazon Linux 2 STIG Benchmark v2.0.0CIS Amazon Linux 2 STIG v2.0.0 L2 ServerUnix
CIS_CentOS_8_Server_L2_v2.0.0.audit from CIS CentOS Linux 8 Benchmark v2.0.0CIS CentOS Linux 8 Server L2 v2.0.0Unix
CIS_Microsoft_Exchange_Server_2019_v1.0.0_Level_1_Mailbox.audit from CIS Microsoft Exchange Server 2019 Benchmark v1.0.0CIS Microsoft Exchange Server 2019 L1 Mailbox v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

CIS_Microsoft_Exchange_Server_2019_v1.0.0_Level_2_Mailbox.audit from CIS Microsoft Exchange Server 2019 Benchmark v1.0.0CIS Microsoft Exchange Server 2019 L2 Mailbox v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

CIS_Mozilla_Firefox_38_ESR_v1.0.0_Linux_Level1.audit for CIS Mozilla Firefox 38 ESR v1.0.0CIS Mozilla Firefox 38 ESR Linux L1 v1.0.0Unix
CIS_Mozilla_Firefox_38_ESR_v1.0.0_Windows_Level2.audit for CIS Mozilla Firefox 38 ESR v1.0.0CIS Mozilla Firefox 38 ESR Windows L2 v1.0.0Windows
CIS_Mozilla_Firefox_102_ESR_v1.0.0_Linux_Level1.audit for CIS Mozilla Firefox 102 ESR v1.0.0CIS Mozilla Firefox 102 ESR Linux L1 v1.0.0Unix
CIS_MySQL_5.6_Community_Benchmark_v2.0.0_LEVEL_2_DB.audit from CIS Oracle MySQL 5.6 Community Edition BenchmarkCIS MySQL 5.6 Community Database L2 v2.0.0MySQLDB
CIS_MySQL_5.7_Community_Benchmark_v2.0.0_Level_2_OS_Linux.audit from CIS Oracle MySQL 5.7 Community Edition BenchmarkCIS MySQL 5.7 Community Linux OS L2 v2.0.0Unix
CIS_MySQL_5.7_Community_Benchmark_v2.0.0_Level_2_OS_MS.audit from CIS Oracle MySQL 5.7 Community Edition BenchmarkCIS MySQL 5.7 Community Windows OS L2 v2.0.0Windows
CIS_MySQL_8.0_Community_Benchmark_v1.1.0_Level_2_OS_Linux.audit from CIS Oracle MySQL 8.0 Community Edition BenchmarkCIS MySQL 8.0 Community Linux OS L2 v1.1.0Unix
CIS_Oracle_Linux_6_v2.0.0_Server_L2.audit from CIS Oracle Linux 6 Benchmark v2.0.0CIS Oracle Linux 6 Server L2 v2.0.0Unix
CIS_Ubuntu_18.04_LXD_Host_v1.0.0_L1_Workstation.audit from CIS Ubuntu Linux 18.04 LXD Host BenchmarkCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix
CIS_Ubuntu_18.04_LXD_Host_v1.0.0_L2_LXD.audit from CIS Ubuntu Linux 18.04 LXD Host BenchmarkCIS Ubuntu Linux 18.04 LXD Host L2 LXD v1.0.0Unix
CIS_Ubuntu_18.04_LXD_Host_v1.0.0_L2_Server.audit from CIS Ubuntu Linux 18.04 LXD Host BenchmarkCIS Ubuntu Linux 18.04 LXD Host L2 Server v1.0.0Unix
CIS_Ubuntu_Linux_18.04_LTS_v2.2.0_L2_Server.audit from CIS Ubuntu Linux 18.04 LTS Benchmark v2.2.0CIS Ubuntu Linux 18.04 LTS v2.2.0 L2 ServerUnix
CIS_Ubuntu_Linux_22.04_LTS_v2.0.0_L2_Workstation.audit from CIS Ubuntu Linux 22.04 LTS Benchmark v2.0.0CIS Ubuntu Linux 22.04 LTS v2.0.0 L2 WorkstationUnix
CIS_Ubuntu_Linux_24.04_LTS_v1.0.0_L1_Workstation.audit from CIS Ubuntu Linux 24.04 LTS Benchmark v1.0.0CIS Ubuntu Linux 24.04 LTS v1.0.0 L1 WorkstationUnix
CIS_Ubuntu_Linux_24.04_LTS_v1.0.0_L2_Workstation.audit from CIS Ubuntu Linux 24.04 LTS Benchmark v1.0.0CIS Ubuntu Linux 24.04 LTS v1.0.0 L2 WorkstationUnix
Configure Microsoft Defender SmartScreen to block potentially unwanted appsMSCT Edge v87 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Configure Microsoft Defender SmartScreen to block potentially unwanted appsMSCT Microsoft Edge Version 83 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Configure Microsoft Defender SmartScreen to block potentially unwanted appsMSCT Edge v86 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

EDGE-00-000051 - Microsoft Defender SmartScreen must be configured to block potentially unwanted apps.DISA STIG Edge v2r2Windows

CONFIGURATION MANAGEMENT

SQL2-00-038910 - If SQL Server authentication, using passwords, is employed, SQL Server must enforce the DoD standards for password lifetime.DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

IDENTIFICATION AND AUTHENTICATION

WDNS-CM-000001 - The validity period for the RRSIGs covering the DS RR for a zones delegated children must be no less than two days and no more than one week.DISA Microsoft Windows 2012 Server DNS STIG v2r7Windows

CONFIGURATION MANAGEMENT