Item Search

NameAudit NamePluginCategory
1.2.1.1 Ensure 'Protection From Zone Elevation' is set to Enabled - groove.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.10 Ensure 'Object Caching Protection' is set to Enabled - winproj.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.11 Ensure 'Consistent Mime Handling' is set to Enabled - excel.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.11 Ensure 'Consistent Mime Handling' is set to Enabled - mspub.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.11 Ensure 'Consistent Mime Handling' is set to Enabled - visio.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.12 Ensure 'Add-on Management' is set to Enabled - groove.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

1.2.1.12 Ensure 'Add-on Management' is set to Enabled - mse7.exeCIS Microsoft Office 2016 v1.1.0Windows

CONFIGURATION MANAGEMENT

2.1.6 Ensure rsh server is not enabled - rexecCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.8 Ensure telnet server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.1.1 Ensure time synchronization is in useCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

2.2.1.3 Ensure chrony is configured - remote serverCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

2.2.4 Ensure CUPS is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.5 Ensure DHCP Server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.9 Ensure FTP Server is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.12 Ensure Samba is not enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.15 Ensure mail transfer agent is configured for local-only modeCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.3.3 Ensure talk client is not installedCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.3.5 Ensure LDAP client is not installedCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

3.1.2 Ensure packet redirect sending is disabled 'net.ipv4.conf.all.send_redirects = 0 - sysctl'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.5 Ensure broadcast ICMP requests are ignored - /etc/sysctl.conf /etc/sysctl.d/*CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.5 Ensure broadcast ICMP requests are ignored - sysctlCIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.8 Ensure TCP SYN Cookies is enabled - /etc/sysctl.conf /etc/sysctl.d/*CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.2 Ensure IPv6 redirects are not accepted - 'net.ipv6.conf.default.accept_redirects = 0 /etc/sysctl.conf /etc/sysctl.d/*'CIS Amazon Linux v2.1.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.1 Ensure DCCP is disabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

3.5.4 Ensure TIPC is disabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

4.2.1.2 Ensure logging is configuredCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.2.1.4 Ensure rsyslog is configured to send logs to a remote log host - rsyslog.confCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.2.2.1 Ensure syslog-ng service is enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

4.2.2.4 Ensure syslog-ng is configured to send logs to a remote log host - log srcCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

4.2.2.5 Ensure remote syslog-ng messages are only accepted on designated log hostsCIS Amazon Linux v2.1.0 L1Unix

AUDIT AND ACCOUNTABILITY

5.1.3 Ensure permissions on /etc/cron.hourly are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.2.2 Ensure SSH Protocol is set to 2CIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.2.4 Ensure SSH X11 forwarding is disabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.2.9 Ensure SSH PermitEmptyPasswords is disabledCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure password creation requirements are configured - dcreditCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure password creation requirements are configured - password-auth ocreditCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure password creation requirements are configured - retry=3CIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.2 Ensure lockout for failed password attempts is configured - system-auth 'auth [default=die] pam_faillock.so authfail audit deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - system-auth 'auth [success=1 default=bad] pam_unix.so'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.4 Ensure password hashing algorithm is SHA-512 - password-authCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.3.4 Ensure password hashing algorithm is SHA-512 - system-authCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile.d/*.shCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.1.2 Ensure permissions on /etc/passwd are configuredCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.1.3 Ensure permissions on /etc/shadow are configuredCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.1.4 Ensure permissions on /etc/group are configuredCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.1.5 Ensure permissions on /etc/gshadow are configuredCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.1.7 Ensure permissions on /etc/shadow- are configuredCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.1.12 Ensure no ungrouped files or directories existCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.2.6 Ensure root PATH IntegrityCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

6.2.9 Ensure users own their home directoriesCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT