Item Search

NameAudit NamePluginCategory
2.2.29 (L1) Configure 'Log on as a service'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.29 (L2) Ensure 'Log on as a service' is configuredCIS Microsoft Windows 10 Enterprise v4.0.0 L2 BL NGWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.29 (L2) Ensure 'Log on as a service' is configuredCIS Microsoft Windows 11 Enterprise v4.0.0 L2 BitLockerWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.29 (L2) Ensure 'Log on as a service' is configuredCIS Microsoft Windows 11 Stand-alone v4.0.0 L2Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

18.10.35.1 (L1) Ensure 'Disable Internet Explorer 11 as a standalone browser' is set to 'Enabled: Always'CIS Microsoft Windows 10 Enterprise v4.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

18.10.35.1 (L1) Ensure 'Disable Internet Explorer 11 as a standalone browser' is set to 'Enabled: Always'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

18.10.35.1 (L1) Ensure 'Disable Internet Explorer 11 as a standalone browser' is set to 'Enabled: Always'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 NGWindows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-056230 - AlmaLinux OS 9 audit tools must be group-owned by root.DISA CloudLinux AlmaLinux OS 9 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GOOG-10-000400 - Google Android 10 must be configured to lock the display after 15 minutes (or less) of inactivity.MobileIron - DISA Google Android 10.x v2r1MDM

ACCESS CONTROL

Hardened UNC Paths - \\*\SYSVOLMSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Include local path when user is uploading files to a server - Restricted Sites ZoneMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Initialize and script ActiveX controls not marked as safe - Restricted Sites ZoneMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Initialize and script ActiveX controls not marked as safe - Trusted Sites ZoneMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Interactive logon: Machine account lockout thresholdMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Internet Explorer Processes - FEATURE_RESTRICT_FILEDOWNLOAD - (Reserved)MSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_SECURITYBAND - (Reserved)MSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Internet Explorer Processes - FEATURE_SECURITYBAND - iexplore.exeMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Internet ZoneMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Java permissions - Local Machine ZoneMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Join Microsoft MAPSMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Load and unload device driversMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network server: Digitally sign communications (if client agrees)MSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Minimum password ageMSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network access: Let Everyone permissions apply to anonymous usersMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Network access: Restrict clients allowed to make remote calls to SAMMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Network security: Force logoff when logon hours expireMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Network security: LAN Manager authentication levelMSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Perform volume maintenance tasksMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Run .NET Framework-reliant components not signed with Authenticode - Internet ZoneMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Scan removable drivesMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Security Zones: Do not allow users to change policiesMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Use only machine settingsMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Send file samples when further analysis is requiredMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Sign-in last interactive user automatically after a system-initiated restartMSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Specify the maximum log file size (KB) - SecurityMSCT Windows Server 2016 MS v1.0.0Windows

AUDIT AND ACCOUNTABILITY

System objects: Strengthen default permissions of internal system objects (e.g., Symbolic Links)MSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn off AutoplayMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn off blocking of outdated ActiveX controls for Internet ExplorerMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn on Cross-Site Scripting Filter - Restricted Sites ZoneMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn on Enhanced Protected ModeMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn on PowerShell Script Block Logging - EnableScriptBlockInvocationLoggingMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Turn on Protected Mode - Restricted Sites ZoneMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Turn on the auto-complete feature for user names and passwords on forms - FormSuggest PW AskMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Turn On Virtualization Based Security - EnableVirtualizationBasedSecurityMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Userdata persistence - Restricted Sites ZoneMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WDigest AuthenticationMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Windows Firewall: Protect all network connectionsMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

ZEBR-10-000400 - Zebra Android 10 must be configured to lock the display after 15 minutes (or less) of inactivity.MobileIron - DISA Zebra Android 10 COBO v1r2MDM

ACCESS CONTROL