Item Search

NameAudit NamePluginCategory
1.1.2.7.1 Ensure separate partition exists for /var/log/auditCIS Ubuntu Linux 24.04 LTS v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

1.1.2.7.1 Ensure separate partition exists for /var/log/auditCIS Debian Linux 12 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

1.1.2.7.1 Ensure separate partition exists for /var/log/auditCIS Rocky Linux 9 v2.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

1.1.2.7.1 Ensure separate partition exists for /var/log/auditCIS AlmaLinux OS 8 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.2.7.1 Ensure separate partition exists for /var/log/auditCIS Oracle Linux 8 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.2.7.1 Ensure separate partition exists for /var/log/auditCIS Oracle Linux 8 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.2.7.1 Ensure separate partition exists for /var/log/auditCIS Rocky Linux 8 Server L2 v2.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.6.1 Ensure separate partition exists for /var/log/auditCIS Amazon Linux 2023 Server L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.6.1 Ensure separate partition exists for /var/log/auditCIS CentOS Linux 8 Workstation L2 v2.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.6.1 Ensure separate partition exists for /var/log/auditCIS Fedora 28 Family Linux Workstation L2 v2.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.16 Ensure separate partition exists for /var/log/auditCIS Amazon Linux 2 STIG v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

1.1.18.7 (L1) Ensure 'extensions.blocklist.enabled' is set to 'Enabled'CIS Mozilla Firefox ESR GPO v1.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.2 Create mozilla.cfg fileCIS Mozilla Firefox 102 ESR Windows L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.3 Ensure gpgcheck is globally activatedCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND INFORMATION INTEGRITY

1.7.8 Ensure GDM autorun-never is enabledCIS Debian Linux 11 v2.0.0 L1 ServerUnix

MEDIA PROTECTION

1.7.8 Ensure GDM autorun-never is enabledCIS Ubuntu Linux 22.04 LTS v2.0.0 L1 WorkstationUnix

MEDIA PROTECTION

1.7.8 Ensure GDM autorun-never is enabledCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

MEDIA PROTECTION

1.7.9 Ensure GDM autorun-never is not overriddenCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

MEDIA PROTECTION

1.8.8 Ensure GDM autorun-never is enabledCIS Debian 10 Workstation L1 v2.0.0Unix

MEDIA PROTECTION

1.8.8 Ensure GDM autorun-never is enabledCIS Red Hat Enterprise Linux 9 v2.0.0 L1 ServerUnix

MEDIA PROTECTION

1.8.9 Ensure GDM autorun-never is not overriddenCIS Debian 10 Workstation L1 v2.0.0Unix

MEDIA PROTECTION

1.8.9 Ensure GDM autorun-never is not overriddenCIS AlmaLinux OS 9 v2.0.0 L1 ServerUnix

MEDIA PROTECTION

1.8.9 Ensure GDM autorun-never is not overriddenCIS AlmaLinux OS 9 v2.0.0 L1 WorkstationUnix

MEDIA PROTECTION

1.8.9 Ensure GDM autorun-never is not overriddenCIS Red Hat EL8 Server L1 v3.0.0Unix

MEDIA PROTECTION

1.8.9 Ensure GDM autorun-never is not overriddenCIS Oracle Linux 9 v2.0.0 L1 WorkstationUnix

MEDIA PROTECTION

1.8.9 Ensure GDM autorun-never is not overriddenCIS Red Hat Enterprise Linux 9 v2.0.0 L1 WorkstationUnix

MEDIA PROTECTION

2.2 (L1) Host must have all software updates installedCIS VMware ESXi 8.0 v1.2.0 L1VMware

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.2 Set 'Only use the ActiveX Installer Service for installation of ActiveX Controls' to 'Enabled'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

2.3.10.8 (L1) Configure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Azure Compute Microsoft Windows Server 2019 v1.0.0 L1 MSWindows

ACCESS CONTROL

2.3.10.9 (L1) Configure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Windows Server 2012 DC L1 v3.0.0Windows

ACCESS CONTROL

2.3.10.9 (L1) Configure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Microsoft Windows Server 2008 R2 Domain Controller Level 1 v3.3.1Windows

ACCESS CONTROL

2.3.10.9 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Microsoft Windows Server 2025 v1.0.0 L1 DCWindows

ACCESS CONTROL

2.3.10.9 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Microsoft Windows Server 2025 v1.0.0 L1 MSWindows

ACCESS CONTROL

2.3.10.9 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Microsoft Windows Server 2019 v4.0.0 L1 DCWindows

ACCESS CONTROL

2.3.10.11 Configure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Microsoft Windows Server 2019 STIG v3.0.0 L1 MSWindows

ACCESS CONTROL

5.2 Ensure PostgreSQL is Bound to an IP AddressCIS PostgreSQL 14 DB v 1.2.0PostgreSQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

6.2.2 Ensure that an exclusionary geographic Conditional Access policy is consideredCIS Microsoft Azure Foundations v4.0.0 L2microsoft_azure

ACCESS CONTROL

6.7 Ensure That Cloud SQL Database Instances Are Configured With Automated BackupsCIS Google Cloud Platform v3.0.0 L1GCP

CONTINGENCY PLANNING

Configuration files should be secured against unauthorized access.TNS IBM HTTP Server Best Practice MiddlewareUnix
ESXI-65-000003 - The ESXi host must verify the exception users list for lockdown mode.DISA STIG VMware vSphere ESXi 6.5 v2r4VMware

CONFIGURATION MANAGEMENT

GOOG-11-009400 - Google Android 11 work profile must be configured to enforce the system application disable list.AirWatch - DISA Google Android 11 COBO v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-11-009400 - Google Android 11 work profile must be configured to enforce the system application disable list.AirWatch - DISA Google Android 11 COPE v2r1MDM

CONFIGURATION MANAGEMENT

Host versionTNS Citrix HypervisorUnix

CONFIGURATION MANAGEMENT

IIST-SV-000158 - Unspecified file extensions on a production IIS 10.0 web server must be removed.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

Logs containing auditing information should be secured at the directory level.TNS IBM HTTP Server Best Practice MiddlewareUnix

AUDIT AND ACCOUNTABILITY

OL6-00-000001 - The system must use a separate file system for /tmp.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

Review accounts used to mount remote storageTNS Citrix HypervisorUnix

CONFIGURATION MANAGEMENT

The hosts.deny file blocks access by defaultTNS Citrix HypervisorUnix

SYSTEM AND COMMUNICATIONS PROTECTION

XAPI SSL certificate is in default locationTNS Citrix HypervisorUnix

CONFIGURATION MANAGEMENT

ZEBR-11-009400 - Zebra Android 11 work profile must be configured to enforce the system application disable list.MobileIron - DISA Zebra Android 11 COBO v1r3MDM

CONFIGURATION MANAGEMENT