1.2.3.2.6 Set 'Enumerate local users on domain-joined computers' to 'Disabled' | CIS Windows 8 L1 v1.0.0 | Windows | ACCESS CONTROL |
2.1 Run BIND as a non-root User - UID | CIS BIND DNS v3.0.1 Authoritative Name Server | Unix | ACCESS CONTROL |
2.3.10.7 (L1) Ensure 'Network access: Remotely accessible registry paths' is configured | CIS Microsoft Windows Server 2022 Stand-alone v1.0.0 L1 MS | Windows | ACCESS CONTROL |
2.3.10.8 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configured | CIS Microsoft Windows 11 Stand-alone v4.0.0 L1 BL | Windows | ACCESS CONTROL |
2.3.10.8 (L1) Ensure 'Network access: Remotely accessible registry paths and sub-paths' is configured | CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL | Windows | ACCESS CONTROL |
3.1 Ensure that role-based access control is enabled and configured appropriately | CIS MongoDB 3.2 Database Audit L1 v1.0.0 | MongoDB | ACCESS CONTROL |
3.4 Ensure that each role for each MongoDB database is needed and grants only the necessary privileges | CIS MongoDB 3.4 Database Audit L2 v1.0.0 | MongoDB | ACCESS CONTROL |
5.2.4 Ensure SSH access is limited | CIS SUSE Linux Enterprise 12 v3.2.1 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
5.2.4 Ensure SSH access is limited | CIS SUSE Linux Enterprise 12 v3.2.1 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
5.2.14 Ensure SSH access is limited | CIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
5.3.6 Ensure SSH access is limited | CIS Amazon Linux 2 STIG v2.0.0 L1 Server | Unix | ACCESS CONTROL, MEDIA PROTECTION |
5.3.6 Ensure SSH access is limited | CIS Amazon Linux 2 STIG v2.0.0 L1 Workstation | Unix | ACCESS CONTROL, MEDIA PROTECTION |
6.9 Restrict at/cron To Authorized Users - should pass if /etc/cron.d/cron.deny does not exist. | CIS Solaris 10 L1 v5.2 | Unix | ACCESS CONTROL |
6.13 Restrict at/cron to Authorized Users - /etc/cron.d/cron.allow perms | CIS Solaris 11.2 L1 v1.1.0 | Unix | ACCESS CONTROL |
7.1 Establish an administrator group | CIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS Linux | Unix | ACCESS CONTROL |
7.4 Secure SYSMON Authority | CIS IBM DB2 v10 v1.1.0 Linux OS Level 1 | Unix | ACCESS CONTROL |
7.4 Secure SYSMON Authority | CIS IBM DB2 v10 v1.1.0 Windows OS Level 1 | Windows | ACCESS CONTROL |
9.5 Verify No UID 0 Accounts Exist Other than root | CIS Solaris 11 L1 v1.1.0 | Unix | ACCESS CONTROL |
10.3 Restrict manager application | CIS Apache Tomcat 8 L2 v1.1.0 Middleware | Unix | ACCESS CONTROL |
13.5 Verify No UID 0 Accounts Exist Other Than root | CIS Debian Linux 7 L1 v1.0.0 | Unix | ACCESS CONTROL |
Always install with elevated privileges | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
Big Sur - Require Administrator Password to Modify System-Wide Preferences | NIST macOS Big Sur v1.4.0 - 800-53r4 Moderate | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
Catalina - Require Administrator Password to Modify System-Wide Preferences | NIST macOS Catalina v1.5.0 - 800-53r5 Moderate | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
Catalina - Require Administrator Password to Modify System-Wide Preferences | NIST macOS Catalina v1.5.0 - CNSSI 1253 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
Configure Windows Defender SmartScreen - EnableSmartScreen | MSCT Windows Server v20H2 MS v1.0.0 | Windows | ACCESS CONTROL |
Create a pagefile | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
Create a token object | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
Create global objects | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
Create global objects | MSCT Windows Server 2025 DC v1.0.0 | Windows | ACCESS CONTROL |
Deny access to this computer from the network | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
Deny log on through Remote Desktop Services | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
Disallow WinRM from storing RunAs credentials | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
Enable computer and user accounts to be trusted for delegation | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
Ensure noexec option set on /dev/shm partition | Tenable Cisco Firepower Management Center OS Best Practices Audit | Unix | ACCESS CONTROL |
Ensure root login is restricted to system console | Tenable Cisco Firepower Management Center OS Best Practices Audit | Unix | ACCESS CONTROL |
Enumerate local users on domain-joined computers | MSCT Windows Server v20H2 MS v1.0.0 | Windows | ACCESS CONTROL |
Impersonate a client after authentication | MSCT Windows Server 2025 DC v1.0.0 | Windows | ACCESS CONTROL |
Load and unload device drivers | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
Lock pages in memory | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Manage auditing and security log | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
Manage auditing and security log | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Modify firmware environment values | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
Modify firmware environment values | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
Network security: Allow LocalSystem NULL session fallback | MSCT Windows Server v20H2 DC v1.0.0 | Windows | ACCESS CONTROL |
OpenStack Identity - Disable admin token in /etc/keystone/keystone.conf | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
Perform volume maintenance tasks | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Take ownership of files or other objects | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
Take ownership of files or other objects | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
User Account Control: Admin Approval Mode for the Built-in Administrator account | MSCT Windows Server v20H2 MS v1.0.0 | Windows | ACCESS CONTROL |
User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode | MSCT Windows Server 2019 MS v1.0.0 | Windows | ACCESS CONTROL |