Item Search

NameAudit NamePluginCategory
1.1 Ensure packages are obtained from authorized repositoriesCIS PostgreSQL 11 OS v1.0.0Unix

CONFIGURATION MANAGEMENT

1.2 Ensure Installation of Binary PackagesCIS PostgreSQL 10 OS v1.0.0Unix

CONFIGURATION MANAGEMENT

1.4 Ensure systemd Service Files Are EnabledCIS PostgreSQL 10 OS v1.0.0Unix

SYSTEM AND SERVICES ACQUISITION

1.4.5 (L2) Ensure 'Control use of the File System API for reading' is set to 'Enabled: Don't allow any site to request read access to files and directories via the File System API'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.4.7 (L2) Ensure 'Control use of the Web Bluetooth API' is set to 'Enabled: Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

1.4.10 (L1) Ensure 'Default geolocation setting' is set to 'Enabled: Don't allow any site to track users' physical location'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.4.11 (L2) Ensure 'Default setting for third-party storage partitioning' is set to 'Enabled: Block third-party storage partitioning from being enabled.'CIS Microsoft Edge v4.0.0 L2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.6.1 (L1) Ensure 'Enable insecure download warnings' is set to 'Enabled'CIS Microsoft Edge v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.13.3 (L2) Ensure 'Supported authentication schemes' is set to 'Enabled: ntlm, negotiate'CIS Microsoft Edge v4.0.0 L2Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.31.5 (L1) Ensure 'Prevent bypassing Microsoft Defender SmartScreen prompts for sites' is set to 'Enabled'CIS Microsoft Edge v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.35 (L2) Ensure 'Allow features to download assets from the Asset Delivery Service' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.36 (L2) Ensure 'Allow file selection dialogs' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.37 (L1) Ensure 'Allow Google Cast to connect to Cast devices on all IP addresses' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.47 (L2) Ensure 'Allow or block video capture' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.52 (L1) Ensure 'Allow the audio sandbox to run' is set to 'Enabled'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.57 (L2) Ensure 'Allow users to proceed from the HTTPS warning page' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.65 (L2) Ensure 'Browser sign-in settings' is set to 'Enabled: Disable browser sign-in'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.67 (L1) Ensure 'Clear cached images and files when Microsoft Edge closes' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.84 (L1) Ensure 'Disable saving browser history' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.88 (L1) Ensure 'Edge 3P SERP Telemetry Enabled' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.90 (L1) Ensure 'Enable Application Bound Encryption' is set to 'Enabled'CIS Microsoft Edge v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.93 (L1) Ensure 'Enable browser legacy extension point blocking' is set to 'Enabled'CIS Microsoft Edge v4.0.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

1.94 (L1) Ensure 'Enable component updates in Microsoft Edge' is set to 'Enabled'CIS Microsoft Edge v4.0.0 L1Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.95 (L1) Ensure 'Enable deleting browser and download history' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.98 (L2) Ensure 'Enable guest mode' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

1.111 (L2) Ensure 'Enable QR Code Generator' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

2.1 Ensure the file permissions mask is correctCIS PostgreSQL 11 OS v1.0.0Unix

ACCESS CONTROL

3.1.5 Ensure the filename pattern for log files is set correctlyCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.6 Ensure the log file permissions are set correctlyCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

3.1.7 Ensure 'log_truncate_on_rotation' is enabledCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.12 Ensure the correct messages are written to the server logCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.15 Ensure 'debug_print_rewritten' is disabledCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT

3.1.18 Ensure 'log_connections' is enabledCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.19 Ensure 'log_disconnections' is enabledCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.20 Ensure 'log_error_verbosity' is set correctlyCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.22 Ensure 'log_line_prefix' is set correctlyCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.1.23 Ensure 'log_statement' is set correctlyCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

AUDIT AND ACCOUNTABILITY

3.3.1 (L1) Ensure 'Auto-update check period override' is set to any value except '0'CIS Microsoft Edge v4.0.0 L1Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.5 Use pg_permission extension to audit object permissionsCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

4.6 Ensure Row Level Security (RLS) is configured correctlyCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

4.6 Ensure Row Level Security (RLS) is configured correctlyCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

4.8 Make use of default rolesCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

5.1 Ensure login via 'local' UNIX Domain Socket is configured correctlyCIS PostgreSQL 11 OS v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.2 Ensure login via "host" TCP/IP Socket is configured correctlyCIS PostgreSQL 11 OS v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.1 Ensure 'Attack Vectors' Runtime Parameters are ConfiguredCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT

6.2 Ensure 'backend' runtime parameters are configured correctlyCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT

6.4 Ensure 'SIGHUP' Runtime Parameters are ConfiguredCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

SYSTEM AND SERVICES ACQUISITION

6.8 Ensure SSL is enabled and configured correctlyCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

8.1 Ensure PostgreSQL configuration files are outside the data clusterCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT

8.2 Ensure PostgreSQL subdirectory locations are outside the data clusterCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT