Item Search

NameAudit NamePluginCategory
1.1 Ensure device firmware is up to dateAirWatch - CIS Google Android v1.3.0 L1MDM
1.2 Ensure that Multi-Factor Authentication is 'Enabled' for All Non-Service AccountsCIS Google Cloud Platform v3.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

1.3 Ensure 'Make pattern visible' is set to 'Disabled' (if using a pattern as device lock mechanism)AirWatch - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

1.5 Ensure 'Power button instantly locks' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L1MDM

IDENTIFICATION AND AUTHENTICATION

1.6 Ensure 'Lock Screen Message' is configuredAirWatch - CIS Google Android v1.3.0 L1MDM
1.7 Do not connect to untrusted Wi-Fi networksMobileIron - CIS Google Android v1.3.0 L2MDM
1.8 Ensure 'Show passwords' is set to 'Disabled'AirWatch - CIS Google Android v1.3.0 L2MDM

CONFIGURATION MANAGEMENT

1.9 Ensure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly AccessibleCIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

1.12 Ensure 'Smart Lock' is set to 'Disabled'MobileIron - CIS Google Android v1.3.0 L2MDM

CONFIGURATION MANAGEMENT

1.13 Ensure 'Lock SIM card' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L2MDM
1.16 Ensure 'Remotely locate this device' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L1MDM
1.18 Ensure 'Scan device for security threats' is set to 'Enabled'MobileIron - CIS Google Android v1.3.0 L1MDM
1.22 Ensure 'Wi-Fi assistant' is set to 'Disabled'MobileIron - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

1.24 Ensure 'Add users from lock screen' is set to 'Disabled'AirWatch - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

1.27 Ensure 'Instant apps' is set to 'Disabled'MobileIron - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.1 Ensure That Cloud Audit Logging Is Configured ProperlyCIS Google Cloud Platform v3.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

2.1.4 Ensure correct system time is configured through NTPCIS Fortigate 7.0.x v1.3.0 L1FortiGate

AUDIT AND ACCOUNTABILITY

2.3 Ensure 'Back up to Google Drive' is 'Disabled'AirWatch - CIS Google Android v1.3.0 L2MDM
2.4 Ensure 'Web and App Activity' is set to 'Disabled'AirWatch - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.4 Ensure 'Web and App Activity' is set to 'Disabled'MobileIron - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.4.3 Ensure admin accounts with different privileges have their correct profiles assignedCIS Fortigate 7.0.x v1.3.0 L1FortiGate

ACCESS CONTROL

2.4.8 Virtual patching on the local-in management interfaceCIS Fortigate 7.0.x v1.3.0 L1FortiGate

SECURITY ASSESSMENT AND AUTHORIZATION, RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.5 Ensure 'Device Information' is set to 'Disabled'AirWatch - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.5 Ensure 'Device Information' is set to 'Disabled'MobileIron - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.5 Ensure That the Log Metric Filter and Alerts Exist for Audit Configuration ChangesCIS Google Cloud Platform v3.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

2.5.3 Ensure HA Reserved Management Interface is configuredCIS Fortigate 7.0.x v1.3.0 L1FortiGate

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.1 Ensure 'Microphone' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L1MDM

ACCESS CONTROL

3.4 Ensure 'Safe Browsing' is set to 'Enabled'MobileIron - CIS Google Android v1.3.0 L1MDM
3.4 Ensure logging is enabled on all firewall policiesCIS Fortigate 7.0.x v1.3.0 L1FortiGate

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

3.5 Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSECCIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.6 Ensure 'Do Not Track' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L2MDM
4.1.2.1 Ensure audit log storage size is configuredCIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.2.2 Ensure audit logs are not automatically deletedCIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.2.3 Ensure system is disabled when audit logs are full - 'action_mail_acct = root'CIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.2.3 Ensure system is disabled when audit logs are full - 'space_left_action = email'CIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - rules.d EPERM 32-bitCIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure unsuccessful unauthorized file access attempts are collected - rules.d EPERM 64-bitCIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.15 Ensure system administrator command executions (sudo) are collected - rules.d 64-bitCIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.16 Ensure kernel module loading and unloading is collected - rules.d /sbin/insmodCIS CentOS 6 Workstation L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

4.1.16 Ensure kernel module loading and unloading is collected - rules.d /sbin/modprobeCIS CentOS 6 Workstation L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

4.1.16 Ensure kernel module loading and unloading is collected - rules.d /sbin/rmmodCIS CentOS 6 Workstation L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

4.3 Ensure 'Block Project-Wide SSH Keys' Is Enabled for VM InstancesCIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.1.1 Enable Compromised Host QuarantineCIS Fortigate 7.0.x v1.3.0 L1FortiGate

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

6.1.3 Ensure That the 'Local_infile' Database Flag for a Cloud SQL MySQL Instance Is Set to 'Off'CIS Google Cloud Platform v3.0.0 L1GCP

CONFIGURATION MANAGEMENT

6.2.3 Ensure That the 'Log_disconnections' Database Flag for Cloud SQL PostgreSQL Instance Is Set to 'On'CIS Google Cloud Platform v3.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

6.2.7 Ensure That the 'Log_min_duration_statement' Database Flag for Cloud SQL PostgreSQL Instance Is Set to '-1' (Disabled)CIS Google Cloud Platform v3.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

6.3.4 Ensure 'user options' database flag for Cloud SQL SQL Server instance is not configuredCIS Google Cloud Platform v3.0.0 L1GCP

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.3.7 Ensure that the 'contained database authentication' database flag for Cloud SQL on the SQL Server instance is not set to 'on'CIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

6.4 Ensure That the Cloud SQL Database Instance Requires All Incoming Connections To Use SSLCIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.3.1 Centralized Logging and ReportingCIS Fortigate 7.0.x v1.3.0 L2FortiGate

AUDIT AND ACCOUNTABILITY