Item Search

NameAudit NamePluginCategory
1.1 Ensure device firmware is up to dateAirWatch - CIS Google Android v1.6.0 L1MDM

SYSTEM AND INFORMATION INTEGRITY

1.1 Ensure device firmware is up to dateMobileIron - CIS Google Android v1.6.0 L1MDM

SYSTEM AND INFORMATION INTEGRITY

1.4 Ensure 'Automatically Lock' is set to 'Immediately'MobileIron - CIS Google Android v1.6.0 L1MDM

IDENTIFICATION AND AUTHENTICATION

1.7.2 Do not admit containers wishing to share the host process ID namespaceCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

CONFIGURATION MANAGEMENT

1.14 Ensure 'Use network-provided time' and 'Use network-provided time zone' are set to 'Enabled'MobileIron - CIS Google Android v1.6.0 L1MDM

AUDIT AND ACCOUNTABILITY

1.15 Ensure 'Remotely locate this device' is set to 'Enabled'MobileIron - CIS Google Android v1.6.0 L1MDM

ACCESS CONTROL

1.16 Ensure 'Allow remote lock and erase' is set to 'Enabled'AirWatch - CIS Google Android v1.6.0 L1MDM

ACCESS CONTROL

1.16 Ensure 'Allow remote lock and erase' is set to 'Enabled'MobileIron - CIS Google Android v1.6.0 L1MDM

ACCESS CONTROL

1.19 Ensure 'Ask for unlock pattern/PIN/password before unpinning' is set to 'Enabled'MobileIron - CIS Google Android v1.6.0 L1MDM

IDENTIFICATION AND AUTHENTICATION

1.21 Ensure 'Wi-Fi assistant' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.2 Ensure network traffic is restricted between containers on the default bridgeCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure 'Device Information' is set to 'Disabled'AirWatch - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.4 Ensure 'Device Information' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.4 Configure TCP Wrappers - Allow localhost.CIS Solaris 10 L1 v5.2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.6 Ensure 'YouTube Search History' is set to 'Disabled'AirWatch - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.8 Enable user namespace supportCIS Docker 1.12.0 v1.0.0 L2 DockerUnix
2.11 Ensure 'Bluetiooth' scanning' Is 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

4.3 Enable Auditing of File Metadata Modification EventsCIS Oracle Solaris 11.4 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.3 Enable Debug Level Daemon Logging - Check if permissions for /var/log/connlog are OK.CIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

4.6 Ensure that HEALTHCHECK instructions have been added to container imagesCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND SERVICES ACQUISITION

4.9 Enable Kernel Level Auditing - Check audit policies is set to arge,argv,cntCIS Solaris 10 L1 v5.2Unix

AUDIT AND ACCOUNTABILITY

5.10 Ensure memory usage for container is limitedCIS Docker Community Edition v1.1.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.11 Ensure that the memory usage for containers is limitedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.14 Set the 'on-failure' container restart policy to 5 - RestartPolicyName=alwaysCIS Docker 1.11.0 v1.0.0 L1 DockerUnix
5.14 Set the 'on-failure' container restart policy to 5 - RestartPolicyName=on-failureCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.15 Do not share the host's process namespaceCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.15 Set the 'on-failure' container restart policy to 5 - RestartPolicyName=on-failureCIS Docker 1.6 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.16 Do not share the host's IPC namespaceCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.16 Do not share the host's process namespaceCIS Docker 1.6 v1.0.0 L1 DockerUnix
5.20 Do not share the host's UTS namespaceCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.25 Restrict container from acquiring additional privilegesCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.25 Restrict container from acquiring additional privilegesCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.28 Ensure PIDs cgroup limit is usedCIS Docker Community Edition v1.1.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.2 Ensure that container sprawl is avoidedCIS Docker v1.8.0 L1 OS LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.9 Harden host operating systemCIS Sybase 15.0 L1 DB v1.1.0SybaseDB
7.2 Set Password Expiration Parameters on Active Accounts - Check MINWEEKS is set to 1CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Password Expiration Parameters on Active Accounts - Check WARNWEEKS is set to 4CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - Check PASSLENGTH is set to 8CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.3 Set Strong Password Creation Policies - MINNONALPHA is set to 1CIS Solaris 10 L1 v5.2Unix

IDENTIFICATION AND AUTHENTICATION

7.6 Set Default umask for Users - Check if 'umask' is set to 077 - Check /etc/.login.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.7 Set Default umask for FTP Users - Check if 'defumask' is set to 077.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

7.9 Lock Inactive User Accounts - Check if definact is set to 35.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

8.2 Create Warning Banner for CDE Users - Check if 'Dtlogin*greeting.persLabelString' is set appropriately.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

8.2 Create Warning Banner for CDE Users - Check if file permissions for files under /etc/dt/config/*/Xresources are OK.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

CNTR-K8-000960 - The Kubernetes cluster must use non-privileged host ports for user pods.DISA Kubernetes STIG v2r6Unix

CONFIGURATION MANAGEMENT

DKER-EE-001240 - The Docker Enterprise hosts process namespace must not be shared.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

ACCESS CONTROL

DKER-EE-001960 - Privileged Linux containers must not be used for Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002030 - All Docker Enterprise containers root filesystem must be mounted as read only.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-004030 - The on-failure container restart policy must be is set to 5 in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001630 - The WebSphere Application Server plugin must be configured to use HTTPS only.DISA IBM WebSphere Traditional 9 Windows STIG v2r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION