Item Search

NameAudit NamePluginCategory
2.1 Ensure that authentication is enabled for Cassandra databasesCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

2.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iOS 10 v2.0.0 End User Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iOS 10 v2.0.0 Institution Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

4.1 Ensure 'MUST_CHANGE' Option is set to 'ON' for All SQL Authenticated LoginsCIS SQL Server 2008 R2 DB Engine L1 v1.7.0MS_SQLDB

IDENTIFICATION AND AUTHENTICATION

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/at.deny'CIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/cron.allow'CIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - at.allowCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - cron.allowCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

5.2.11 Ensure SSH PermitEmptyPasswords is disabledCIS Distribution Independent Linux Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.2.11 Ensure SSH PermitEmptyPasswords is disabledCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.2.12 Ensure SSH PermitUserEnvironment is disabledCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

5.2.12 Ensure SSH PermitUserEnvironment is disabledCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

5.2.17 Ensure SSH LoginGraceTime is set to one minute or lessCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.2.21 Ensure SSH AllowTcpForwarding is disabledCIS Distribution Independent Linux Server L2 v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

5.3.3 Ensure password reuse is limitedCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

5.4.2 Ensure system accounts are secured - lock not rootCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

5.4.2 Ensure system accounts are secured - lock not rootCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.4.2 Ensure system accounts are secured - non loginCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate UIDs existCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate UIDs existCIS Red Hat 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS Red Hat 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS Distribution Independent Linux Server L1 v2.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS Red Hat 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.19 Ensure no duplicate group names existCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.19 Ensure no duplicate group names existCIS Red Hat 6 Server L1 v3.0.0Unix

ACCESS CONTROL

Accounts: Guest account statusMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Allow log on locallyMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Allow log on locallyMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Deny log on as a serviceMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Deny log on locallyMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

Domain member: Maximum machine account password ageMSCT Windows Server 1903 MS v1.19.9Windows

IDENTIFICATION AND AUTHENTICATION

Domain member: Maximum machine account password ageMSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Domain member: Maximum machine account password ageMSCT Windows Server 2019 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Lock pages in memoryMSCT Windows Server v1909 DC v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows Server v1909 MS v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows Server 2019 DC v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

Replace a process level tokenMSCT Windows 10 v1507 v1.0.0Windows

ACCESS CONTROL

Replace a process level tokenMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Replace a process level tokenMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL