1.1.6.1 Ensure separate partition exists for /var/log/audit | CIS Ubuntu Linux 18.04 LTS v2.2.0 L2 Workstation | Unix | AUDIT AND ACCOUNTABILITY |
1.2 Create mozilla.cfg file | CIS Mozilla Firefox 102 ESR Linux L1 v1.0.0 | Unix | CONFIGURATION MANAGEMENT |
1.5 Protect Firefox Binaries | CIS Mozilla Firefox 38 ESR Linux L1 v1.0.0 | Unix | CONFIGURATION MANAGEMENT |
1.7.9 Ensure GDM autorun-never is not overridden | CIS Oracle Linux 7 v4.0.0 L1 Workstation | Unix | MEDIA PROTECTION |
1.7.9 Ensure GDM autorun-never is not overridden | CIS CentOS Linux 7 v4.0.0 L1 Workstation | Unix | MEDIA PROTECTION |
1.7.9 Ensure GDM autorun-never is not overridden | CIS CentOS Linux 7 v4.0.0 L1 Server | Unix | MEDIA PROTECTION |
1.7.9 Ensure GDM autorun-never is not overridden | CIS Red Hat Enterprise Linux 7 v4.0.0 L1 Workstation | Unix | MEDIA PROTECTION |
1.8.9 Ensure GDM autorun-never is not overridden | CIS Ubuntu Linux 20.04 LTS Workstation L1 v2.0.1 | Unix | MEDIA PROTECTION |
1.8.9 Ensure GDM autorun-never is not overridden | CIS Oracle Linux 8 Server L1 v3.0.0 | Unix | MEDIA PROTECTION |
1.8.9 Ensure GDM autorun-never is not overridden | CIS Oracle Linux 8 Workstation L1 v3.0.0 | Unix | MEDIA PROTECTION |
1.8.9 Ensure GDM autorun-never is not overridden | CIS Red Hat Enterprise Linux 9 v2.0.0 L1 Server | Unix | MEDIA PROTECTION |
1.8.9 Ensure GDM autorun-never is not overridden | CIS Ubuntu Linux 18.04 LTS v2.2.0 L1 Workstation | Unix | MEDIA PROTECTION |
1.8.9 Ensure GDM autorun-never is not overridden | CIS Debian 10 Server L1 v2.0.0 | Unix | MEDIA PROTECTION |
1.8.9 Ensure GDM autorun-never is not overridden | CIS SUSE Linux Enterprise 15 v2.0.1 L1 Server | Unix | MEDIA PROTECTION |
1.8.9 Ensure GDM autorun-never is not overridden | CIS AlmaLinux OS 8 Workstation L1 v3.0.0 | Unix | MEDIA PROTECTION |
1.9 Ensure GDM is removed or login is configured - disable-user-list | CIS Debian Family Workstation L1 v1.0.0 | Unix | CONFIGURATION MANAGEMENT |
1.10 Ensure GDM is removed or login is configured - disable-user-list | CIS Fedora 19 Family Linux Server L1 v1.0.0 | Unix | CONFIGURATION MANAGEMENT |
2.1.2 Verify Backups are Good | CIS MariaDB 10.6 Database L1 v1.1.0 | MySQLDB | CONTINGENCY PLANNING |
2.1.2 Verify Backups are Good | CIS MySQL 5.7 Community Windows OS L1 v2.0.0 | Windows | CONTINGENCY PLANNING |
2.1.2 Verify Backups are Good | CIS MySQL 5.7 Enterprise Windows OS L1 v2.0.0 | Windows | CONTINGENCY PLANNING |
2.1.2 Verify Backups are Good | CIS Oracle MySQL Enterprise Edition 8.4 v1.0.0 L1 MySQL OS Linux | Unix | CONTINGENCY PLANNING |
2.1.2 Verify Backups are Good | CIS MySQL 5.6 Enterprise Database L1 v2.0.0 | MySQLDB | CONTINGENCY PLANNING |
2.1.2 Verify Backups are Good | CIS MySQL 8.0 Community Linux OS L1 v1.1.0 | Unix | CONTINGENCY PLANNING |
2.1.2 Verify Backups are Good | CIS Oracle MySQL Community Server 8.4 v1.0.0 L1 OS Linux on Linux | Unix | CONTINGENCY PLANNING |
2.2.1.6 Ensure 'Allow users to accept untrusted TLS certificates' is set to 'Disabled' | MobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L2 | MDM | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
2.3.10.8 (L1) Configure 'Network access: Remotely accessible registry paths and sub-paths' is configured | CIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 DC | Windows | ACCESS CONTROL |
2.3.10.8 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configured | CIS Microsoft Windows Server 2022 Stand-alone v1.0.0 L1 MS | Windows | ACCESS CONTROL |
2.3.10.9 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configured | CIS Microsoft Windows Server 2022 v4.0.0 L1 DC | Windows | ACCESS CONTROL |
2.3.10.9 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configured | CIS Microsoft Windows Server 2022 v4.0.0 L1 MS | Windows | ACCESS CONTROL |
2.3.17.4 (L1) Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled' | CIS Microsoft Windows Server 2008 R2 Domain Controller Level 1 v3.3.1 | Windows | ACCESS CONTROL |
2.3.17.4 (L1) Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled' | CIS Microsoft Windows Server 2016 v3.0.0 L1 MS | Windows | ACCESS CONTROL |
2.3.17.4 (L1) Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled' | CIS Microsoft Windows 10 Enterprise v4.0.0 L1 NG | Windows | ACCESS CONTROL |
2.3.17.4 (L1) Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled' | CIS Microsoft Windows Server 2019 v4.0.0 L1 MS | Windows | ACCESS CONTROL |
2.3.17.5 Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled' | CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG MS | Windows | ACCESS CONTROL |
2.3.17.5 Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled' | CIS Microsoft Windows Server 2016 STIG v3.0.0 L1 MS | Windows | ACCESS CONTROL |
2.4.1.1 Ensure cron daemon is enabled and active | CIS Oracle Linux 9 v2.0.0 L1 Workstation | Unix | CONFIGURATION MANAGEMENT |
2.8.3 (L1) Ensure 'Configure the required domain names for remote access clients' is set to 'Enabled' with a domain defined | CIS Google Chrome L1 v3.0.0 | Windows | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
3.8 Disable WebRTC - media.peerconnection.enabled | CIS Mozilla Firefox 38 ESR Linux L1 v1.0.0 | Unix | CONFIGURATION MANAGEMENT |
4.2 Ensure 'Software Update' returns 'Your software is up to date.' | MobileIron - CIS Apple iOS 12 v1.0.0 Institution Owned L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
4.2 Ensure 'Software Update' returns 'Your software is up to date.' | MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1 | MDM | CONFIGURATION MANAGEMENT |
4.2 Ensure 'Software Update' returns 'Your software is up to date.' | MobileIron - CIS Apple iOS 10 v2.0.0 End User Owned L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
4.2 Ensure 'Software Update' returns 'Your software is up to date.' | AirWatch - CIS Apple iOS 11 v1.0.0 Institution Owned L1 | MDM | SYSTEM AND INFORMATION INTEGRITY |
4.2 Ensure excessive administrative privileges are revoked | CIS PostgreSQL 12 DB v1.1.0 | PostgreSQLDB | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
4.2 Ensure excessive administrative privileges are revoked | CIS PostgreSQL 9.6 OS v1.0.0 | Unix | ACCESS CONTROL |
4.3 Ensure excessive administrative privileges are revoked | CIS PostgreSQL 13 DB v1.2.0 | PostgreSQLDB | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
4.3 Ensure excessive administrative privileges are revoked | CIS PostgreSQL 14 DB v 1.2.0 | PostgreSQLDB | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
CISC-RT-000010 - The Cisco switch must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies. | DISA STIG Cisco IOS Switch RTR v3r1 | Cisco | ACCESS CONTROL |
CISC-RT-000500 - The Cisco BGP switch must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS). | DISA Cisco NX OS Switch RTR STIG v3r3 | Cisco | ACCESS CONTROL |
EX16-ED-000420 - The Exchange Block List service provider must be identified. | DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6 | Windows | SYSTEM AND INFORMATION INTEGRITY |
GEN008800 - The system package management tool must cryptographically verify the authenticity of software packages during installation - '/etc/yum.repos.d/*' | DISA STIG for Oracle Linux 5 v2r1 | Unix | CONFIGURATION MANAGEMENT |