Item Search

NameAudit NamePluginCategory
1.2.14 Ensure that the admission control plugin NodeRestriction is setCIS Kubernetes v2.0.1 L2 Master NodeUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.15 Ensure that the admission control plugin NodeRestriction is setCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.16 Ensure that the admission control plugin NodeRestriction is setCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.3.4 Ensure that the --root-ca-file argument is set as appropriateCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

2.17 (L1) Ensure 'Proxy settings' is set to 'Enabled' and does not contain 'ProxyMode': 'auto_detect'CIS Google Chrome L1 v3.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.65 (L1) Ensure 'Proxy settings' is set to 'Enabled' and does not contain 'ProxyMode': 'auto_detect'CIS Google Chrome Group Policy v1.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.5.1 Block high risk categories on Application ControlCIS FortiGate 7.4.x v1.0.1 L1FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

4.11 Ensure 'Dynamic IP Address Restrictions' is enabled - Deny By Concurrent RequestsCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.11 Ensure 'Dynamic IP Address Restrictions' is enabled - maxConcurrentRequestsCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.1 Ensure allow and deny filters limit access to specific IP addressesCIS NGINX v3.0.0 L2 LoadbalancerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.1 Ensure allow and deny filters limit access to specific IP addressesCIS NGINX v3.0.0 L2 ProxyUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.1 Ensure allow and deny filters limit access to specific IP addressesCIS NGINX v3.0.0 L2 WebserverUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.1.3 Ensure 'identityAssertionEnabled' is set to 'true' within the CSIv2 Attribute LayerCIS IBM WebSphere Liberty v1.0.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.2 Minimize the admission of containers wishing to share the host process ID namespaceCIS Kubernetes v1.20 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.3 Ensure 'identityAssertionTypes' is specified to the correct identity tokens in CSIv2 Attribute Layer - review/ZechCIS IBM WebSphere Liberty v1.0.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.3 Minimize the admission of containers wishing to share the host IPC namespaceCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.3 Minimize the admission of containers wishing to share the host process ID namespaceCIS Kubernetes v1.24 Benchmark v1.0.0 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.3 Minimize the admission of containers wishing to share the host process ID namespaceCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

SYSTEM AND COMMUNICATIONS PROTECTION

7.1 Ensure the 'hostNameExcludeList' attribute is set to a whitelist of host namesCIS IBM WebSphere Liberty v1.0.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Ensure SSLv2 is DisabledCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

7.2 Ensure the 'hostNameIncludeList attribute' is set to a whitelist of host namesCIS IBM WebSphere Liberty v1.0.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

7.3 Ensure the 'addressExcludeList' attribute is set to a whitelist of hostnamesCIS IBM WebSphere Liberty v1.0.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

7.4 Ensure the 'addressIncludeList' attribute is set to a whitelist of IP addressesCIS IBM WebSphere Liberty v1.0.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

7.10 Ensure Azure Web Application Firewall (WAF) is enabled on Azure Application GatewayCIS Microsoft Azure Foundations v5.0.0 L2microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION

7.14 Ensure request body inspection is enabled in Azure Web Application Firewall policy on Azure Application GatewayCIS Microsoft Azure Foundations v5.0.0 L2microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION

7.15 Ensure bot protection is enabled in Azure Web Application Firewall policy on Azure Application GatewayCIS Microsoft Azure Foundations v5.0.0 L2microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION

9.2 Configure 'Disable changing Automatic Configuration settings'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

9.3 Configure 'Disable changing connection settings'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

9.4 Configure 'Disable changing proxy settings'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

9.5 Configure 'Make proxy settings per-machine (rather than per-user)'CIS IE 11 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

9.7 Set 'Prevent changing proxy settings' to 'Enabled'CIS IE 11 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

9.8 Configure 'Disable changing Automatic Configuration settings'CIS IE 11 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

9.11 Configure 'Disable changing connection settings'CIS IE 11 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

10.6 Enable strict servlet ComplianceCIS Apache Tomcat 9 L2 v1.2.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

10.6 Enable strict servlet ComplianceCIS Apache Tomcat 10 L2 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

10.6 Enable strict servlet ComplianceCIS Apache Tomcat 10 L2 v1.1.0 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

10.6 Enable strict servlet ComplianceCIS Apache Tomcat 11 v1.0.0 L2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

10.6 Enable strict servlet ComplianceCIS Apache Tomcat 10.1 v1.1.0 L2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

10.6 Enable strict servlet ComplianceCIS Apache Tomcat 9 L2 v1.2.0 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2025 Stand-alone v1.0.0 L1 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v3.0.0 L1 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2019 v4.0.0 L1 DCWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 DCWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2019 v4.0.0 L1 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.0.0 L1 DCWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.0.0 L1 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.0.0 L1 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.0.0 L1 DCWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.3.9.2 Ensure 'Require secure RPC communication' is set to 'Enabled'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION