Item Search

NameAudit NamePluginCategory
1.1.1 Ensure NGINX is installedCIS NGINX v3.0.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

1.2.1 Ensure package manager repositories are properly configuredCIS NGINX v3.0.0 L1 WebserverUnix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.2.2 Ensure the latest software package is installedCIS NGINX v3.0.0 L1 WebserverUnix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.1.1 Ensure only required dynamic modules are loadedCIS NGINX v3.0.0 L1 WebserverUnix

CONFIGURATION MANAGEMENT

2.2.1 Ensure that NGINX is run using a non-privileged, dedicated service accountCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL

2.2.2 Ensure the NGINX service account is lockedCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, MEDIA PROTECTION

2.2.3 Ensure the NGINX service account has an invalid shellCIS NGINX v3.0.0 L1 WebserverUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.1 Ensure NGINX directories and files are owned by rootCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, MEDIA PROTECTION

2.3.2 Ensure access to NGINX directories and files is restrictedCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, MEDIA PROTECTION

2.3.3 Ensure the NGINX process ID (PID) file is securedCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, MEDIA PROTECTION

2.4.1 Ensure NGINX only listens for network connections on authorized portsCIS NGINX v3.0.0 L1 WebserverUnix

PLANNING, SYSTEM AND SERVICES ACQUISITION

2.4.2 Ensure requests for unknown host names are rejectedCIS NGINX v3.0.0 L1 WebserverUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.4.3 Ensure keepalive_timeout is 10 seconds or less, but not 0CIS NGINX v3.0.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

2.5.1 Ensure server_tokens directive is set to `off`CIS NGINX v3.0.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

2.5.2 Ensure default error and index.html pages do not reference NGINXCIS NGINX v3.0.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

2.5.3 Ensure hidden file serving is disabledCIS NGINX v3.0.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

3.2 Ensure access logging is enabledCIS NGINX v3.0.0 L1 WebserverUnix

AUDIT AND ACCOUNTABILITY

3.3 Ensure error logging is enabled and set to the info logging levelCIS NGINX v3.0.0 L1 WebserverUnix

AUDIT AND ACCOUNTABILITY

4.1.1 Ensure HTTP is redirected to HTTPSCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.2 Ensure a trusted certificate and trust chain is installedCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.3 Ensure private key permissions are restrictedCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.4 Ensure only modern TLS protocols are usedCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.5 Disable weak ciphersCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.6 Ensure awareness of TLS 1.3 new Diffie-Hellman parametersCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.7 Ensure Online Certificate Status Protocol (OCSP) stapling is enabledCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.8 Ensure HTTP Strict Transport Security (HSTS) is enabledCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.11 Ensure Secure Session Resumption is EnabledCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.2.2 Ensure the maximum request body size is set correctlyCIS NGINX v3.0.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

5.2.3 Ensure the maximum buffer size for URIs is definedCIS NGINX v3.0.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

5.3.1 Ensure X-Content-Type-Options header is configured and enabledCIS NGINX v3.0.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

CIS_Apple_macOS_10.14_v2.0.0_L1.audit from CIS Apple macOS 10.14 Benchmark v2.0.0CIS Apple macOS 10.14 v2.0.0 L1Unix
CIS_Apple_macOS_10.14_v2.0.0_L2.audit from CIS Apple macOS 10.14 Benchmark v2.0.0CIS Apple macOS 10.14 v2.0.0 L2Unix
CIS_CentOS_8_Server_L2_v2.0.0.audit from CIS CentOS Linux 8 Benchmark v2.0.0CIS CentOS Linux 8 Server L2 v2.0.0Unix
CIS_CentOS_8_Workstation_L2_v2.0.0.audit from CIS CentOS Linux 8 Benchmark v2.0.0CIS CentOS Linux 8 Workstation L2 v2.0.0Unix
CIS_CentOS_Linux_8_v2.0.0_L1_Server.audit from CIS CentOS Linux 8 Benchmark v2.0.0CIS CentOS Linux 8 Server L1 v2.0.0Unix
CIS_CentOS_Linux_8_v2.0.0_L1_Workstation.audit from CIS CentOS Linux 8 Benchmark v2.0.0CIS CentOS Linux 8 Workstation L1 v2.0.0Unix
CIS_Fedora_28_Family_Linux_Server_L1_v2.0.0.audit from CIS Fedora 28 Family Linux Benchmark v2.0.0CIS Fedora 28 Family Linux Workstation L1 v2.0.0Unix
CIS_Fedora_28_Family_Linux_Server_L1_v2.0.0.audit from CIS Fedora 28 Family Linux Benchmark v2.0.0CIS Fedora 28 Family Linux Server L1 v2.0.0Unix
CIS_Fedora_28_Family_Linux_Server_L1_v2.0.0.audit from CIS Fedora 28 Family Linux Benchmark v2.0.0CIS Fedora 28 Family Linux Server L2 v2.0.0Unix
CIS_Fedora_28_Family_Linux_Server_L1_v2.0.0.audit from CIS Fedora 28 Family Linux Benchmark v2.0.0CIS Fedora 28 Family Linux Workstation L2 v2.0.0Unix
CIS_MacOS_Safari_Benchmark_v2.0.0_L1.audit from CIS MacOS Safari Benchmark v2.0.0CIS MacOS Safari v2.0.0 L1Unix
CIS_MacOS_Safari_Benchmark_v2.0.0_L2.audit from CIS MacOS Safari Benchmark v2.0.0CIS MacOS Safari v2.0.0 L2Unix
CIS_Oracle_Linux_6_v2.0.0_Server_L1.audit from CIS Oracle Linux 6 Benchmark v2.0.0CIS Oracle Linux 6 Server L1 v2.0.0Unix
CIS_Oracle_Linux_6_v2.0.0_Server_L2.audit from CIS Oracle Linux 6 Benchmark v2.0.0CIS Oracle Linux 6 Server L2 v2.0.0Unix
CIS_Oracle_Linux_6_v2.0.0_Workstation_L1.audit from CIS Oracle Linux 6 Benchmark v2.0.0CIS Oracle Linux 6 Workstation L1 v2.0.0Unix
CIS_Oracle_Linux_6_v2.0.0_Workstation_L2.audit from CIS Oracle Linux 6 Benchmark v2.0.0CIS Oracle Linux 6 Workstation L2 v2.0.0Unix
CIS_Ubuntu_16.04_LTS_Server_v2.0.0_L1.audit from CIS Ubuntu 16.04 LTS Server Benchmark L1 v2.0.0CIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix
CIS_Ubuntu_16.04_LTS_Server_v2.0.0_L2.audit from CIS Ubuntu 16.04 LTS Server Benchmark L2 v2.0.0CIS Ubuntu Linux 16.04 LTS Server L2 v2.0.0Unix
CIS_Ubuntu_16.04_LTS_Workstation_v2.0.0_L1.audit from CIS Ubuntu 16.04 LTS Workstation Benchmark L1 v2.0.0CIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix
CIS_Ubuntu_16.04_LTS_Workstation_v2.0.0_L2.audit from CIS Ubuntu 16.04 LTS Workstation Benchmark L2 v2.0.0CIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix