1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0' | CIS Cisco IOS 15 L1 v4.1.1 | Cisco | ACCESS CONTROL |
1.2.9 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty' | CIS Cisco IOS 15 L1 v4.1.1 | Cisco | ACCESS CONTROL |
1.11 Ensure Deny access after failed login attempts is selected | CIS Check Point Firewall L1 v1.1.0 | CheckPoint | ACCESS CONTROL |
1.12 Ensure Maximum number of failed attempts allowed is set to 5 or fewer | CIS Check Point Firewall L1 v1.1.0 | CheckPoint | ACCESS CONTROL |
1.13 Ensure Allow access again after time is set to 300 or more seconds | CIS Check Point Firewall L1 v1.1.0 | CheckPoint | ACCESS CONTROL |
1.23 Ensure 'Sleep' is set to 1 minute or less | MobileIron - CIS Google Android 7 v1.0.0 L1 | MDM | ACCESS CONTROL |
1.23 Ensure 'Sleep' is set to 1 minute or less | AirWatch - CIS Google Android 7 v1.0.0 L1 | MDM | ACCESS CONTROL |
2.1.5 - MobileIron - Set the 'timeout' for 'Time without user input before password must be re-entered (in minutes)' | MobileIron - CIS Google Android 4 v1.0.0 L1 | MDM | ACCESS CONTROL |
2.2.6 - AirWatch - Set Maximum Auto-lock | AirWatch - CIS Apple iOS 8 v1.0.0 L1 | MDM | ACCESS CONTROL |
2.3.1 Set an inactivity interval of 20 minutes or less for the screen saver | CIS Apple OSX 10.9 L1 v1.3.0 | Unix | ACCESS CONTROL |
2.3.3 Verify Display Sleep is set to a value larger than the Screen Saver | CIS Apple OSX 10.9 L1 v1.3.0 | Unix | ACCESS CONTROL |
2.4.3 Ensure 'Maximum Auto-Lock' is set to '2 minutes' or less | MobileIron - CIS Apple iOS 10 v2.0.0 End User Owned L1 | MDM | ACCESS CONTROL |
2.4.4 Ensure 'Maximum grace period for device lock' is set to 'Immediately' | AirWatch - CIS Apple iOS 10 v2.0.0 End User Owned L1 | MDM | ACCESS CONTROL |
2.4.4 Ensure 'Maximum grace period for device lock' is set to 'Immediately' | AirWatch - CIS Apple iOS 11 v1.0.0 End User Owned L1 | MDM | ACCESS CONTROL |
2.5.1 Disable "Wake for network access" | CIS Apple OSX 10.9 L2 v1.3.0 | Unix | ACCESS CONTROL |
2.5.2 Disable sleeping the computer when connected to power | CIS Apple OSX 10.9 L2 v1.3.0 | Unix | ACCESS CONTROL |
2.8 Disable 'Wake for network access' and 'Power Nap' - nap | CIS Apple macOS 10.13 L1 v1.1.0 | Unix | ACCESS CONTROL |
2.17 Set 'Time without user input before password must be re-entered' to '15' | CIS Microsoft Exchange Server 2016 CAS v1.0.0 | Windows | ACCESS CONTROL |
2.17 Set 'Time without user input before password must be re-entered' to '15' | CIS Microsoft Exchange Server 2013 CAS v1.1.0 | Windows | ACCESS CONTROL |
3.1.5 - AirWatch - Set the 'timeout' for 'Time without user input before password must be re-entered (in minutes)' | AirWatch - CIS Apple iOS 8 v1.0.0 L1 | MDM | ACCESS CONTROL |
3.1.5 - MobileIron - Set the 'timeout' for 'Time without user input before password must be re-entered (in minutes)' | MobileIron - CIS Apple iOS 9 v1.0.0 L1 | MDM | ACCESS CONTROL |
3.4.3 Ensure 'Maximum Auto-Lock' is set to '2 minutes' or less | AirWatch - CIS Apple iOS 11 v1.0.0 Institution Owned L1 | MDM | ACCESS CONTROL |
5.1 Ensure the DCUI timeout is set to 600 seconds or less | CIS VMware ESXi 6.5 v1.0.0 Level 1 | VMware | ACCESS CONTROL |
5.2.15 Ensure SSH Idle Timeout Interval is configured - ClientAliveInterval | CIS Debian Family Workstation L1 v1.0.0 | Unix | ACCESS CONTROL |
5.3.17 Ensure SSH Idle Timeout Interval is configured - 'ClientAliveCountMax' | CIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0 | Unix | ACCESS CONTROL |
5.3.17 Ensure SSH Idle Timeout Interval is configured - 'ClientAliveInterval' | CIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0 | Unix | ACCESS CONTROL |
5.4.5 Ensure default user shell timeout is 900 seconds or less - /etc/profile | CIS Debian 9 Server L2 v1.0.1 | Unix | ACCESS CONTROL |
5.5.5 Ensure default user shell timeout is 900 seconds or less - /etc/bash.bashrc | CIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0 | Unix | ACCESS CONTROL |
5.5.5 Ensure default user shell timeout is 900 seconds or less - /etc/bash.bashrc | CIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0 | Unix | ACCESS CONTROL |
5.8 Ensure idle ESXi shell and SSH sessions time out after 300 seconds or less | CIS VMware ESXi 6.5 v1.0.0 Level 1 | VMware | ACCESS CONTROL |
5.9 Require a password to wake the computer from sleep or screen saver | CIS Apple OSX 10.9 L1 v1.3.0 | Unix | ACCESS CONTROL |
5.10 Require a password to wake the computer from sleep or screen saver | CIS Apple macOS 10.12 L1 v1.2.0 | Unix | ACCESS CONTROL |
6.7 Set Default Screen Lock for CDE Users - CDE package was not found | CIS Solaris 10 L1 v5.2 | Unix | ACCESS CONTROL |
6.7 Set Default Screen Lock for CDE Users - Check if file permissions for files under /etc/dt/config/*/sys.resources are OK. | CIS Solaris 10 L1 v5.2 | Unix | ACCESS CONTROL |
6.8 Set Default Screen Lock for GNOME Users - GNOME package was not found | CIS Solaris 10 L1 v5.2 | Unix | ACCESS CONTROL |
18.10.56.3.10.2 Ensure 'Set time limit for disconnected sessions' is set to 'Enabled: 1 minute' | CIS Microsoft Windows Server 2016 STIG v3.0.0 L2 MS | Windows | ACCESS CONTROL |
44 - Use Lockout Realms | TNS Best Practice Jetty 9 Linux | Unix | ACCESS CONTROL |
Citrix ADM - User Administration - Password Policy - Enable User Lockout | Tenable Best Practice Citrix ADM v1.0.0 | Citrix_Application_Delivery | ACCESS CONTROL |
Citrix ADM - User Administration - Password Policy - Invalid Login Attempts | Tenable Best Practice Citrix ADM v1.0.0 | Citrix_Application_Delivery | ACCESS CONTROL |
Citrix ADM - User Administration - Password Policy - User Lockout Interval (Seconds) | Tenable Best Practice Citrix ADM v1.0.0 | Citrix_Application_Delivery | ACCESS CONTROL |
Interactive logon: Machine inactivity limit | MSCT Windows 10 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit | MSCT Windows 11 v24H2 v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit | MSCT Windows Server 2022 v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit - InactivityTimeoutSecs | MSCT Windows Server 2025 DC v1.0.0 | Windows | ACCESS CONTROL |
Interactive logon: Machine inactivity limit - InactivityTimeoutSecs | MSCT Windows Server 2025 MS v1.0.0 | Windows | ACCESS CONTROL |