Item Search

NameAudit NamePluginCategory
1.2.4 Ensure that the --kubelet-https argument is set to trueCIS Kubernetes Benchmark v1.6.1 L1 MasterUnix
1.2.31 Ensure that the --client-ca-file argument is set as appropriateCIS Kubernetes Benchmark v1.6.1 L1 MasterUnix
1.3.5 Ensure that the --root-ca-file argument is set as appropriateCIS Kubernetes Benchmark v1.6.1 L1 MasterUnix
1.6.3 Ensure that the Certificate Securing Remote Access VPNs is Valid - GlobalProtect GatewaysCIS Palo Alto Firewall 9 Benchmark L2 v1.0.0Palo_Alto
2.1 Ensure that the --cert-file and --key-file arguments are set as appropriate - certCIS Kubernetes Benchmark v1.6.1 L1 MasterUnix
2.5.1 Ensure 'VPN' is 'Configured'AirWatch - CIS Apple iOS 12 v1.0.0 End User Owned L1MDM
2.5.1 Ensure 'VPN' is 'Configured'AirWatch - CIS Apple iOS 11 v1.0.0 End User Owned L1MDM
2.5.1 Ensure 'VPN' is 'Configured'AirWatch - CIS Apple iOS 10 v2.0.0 End User Owned L1MDM
3.2.3 Ensure that the --client-ca-file argument is set as appropriateCIS Google Kubernetes Engine (GKE) v1.1.0 L1 WorkerUnix
3.2.10 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate - certCIS Google Kubernetes Engine (GKE) v1.1.0 L1 WorkerUnix
3.2.11 Ensure that the --rotate-certificates argument is not set to falseCIS Google Kubernetes Engine (GKE) v1.1.0 L1 WorkerUnix
3.5.1 Ensure 'VPN' is 'Configured'AirWatch - CIS Apple iOS 11 v1.0.0 Institution Owned L1MDM
3.5.1 Ensure 'VPN' is 'Configured'AirWatch - CIS Apple iOS 10 v2.0.0 Institution Owned L1MDM
3.5.1 Ensure 'VPN' is 'Configured'AirWatch - CIS Apple iOS 12 v1.0.0 Institution Owned L1MDM
4.1 Ensure Encryption of Data in Transit TLS/SSL (Transport Encryption)CIS MongoDB 3.6 L1 Windows Audit v1.0.0Windows
4.1 Ensure Encryption of Data in Transit TLS/SSL (Transport Encryption)CIS MongoDB 3.6 L1 Unix Audit v1.0.0Unix
4.1.6 Ensure custom Diffie-Hellman parameters are usedCIS NGINX Benchmark v1.0.0 L1 ProxyUnix
4.2.10 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate - certCIS Kubernetes Benchmark v1.6.1 L1 WorkerUnix
4.2.10 Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate - keyCIS Kubernetes Benchmark v1.6.1 L1 WorkerUnix
4.2.12 Verify that the RotateKubeletServerCertificate argument is set to trueCIS Kubernetes Benchmark v1.6.1 L1 WorkerUnix
4.5 Protect TSIG Key Files During DeploymentCIS BIND DNS v3.0.1 Authoritative Name ServerUnix
5.2 Ensure login via "host" TCP/IP Socket is configured correctlyCIS PostgreSQL 12 OS v1.0.0Unix
6.7 Ensure FIPS 140-2 OpenSSL Cryptography Is Used - fips_enabledCIS PostgreSQL 13 OS v1.0.0Unix
6.7 Ensure FIPS 140-2 OpenSSL Cryptography Is Used - openssl versionCIS PostgreSQL 12 OS v1.0.0Unix
7.1 Ensure mod_ssl and/or mod_nss Is Installed - 'mod_nss is loaded'CIS Apache HTTP Server 2.4 L2 v1.5.0Unix
7.2 Ensure a Valid Trusted Certificate Is InstalledCIS Apache HTTP Server 2.4 L2 v1.5.0Unix
7.2 Ensure a Valid Trusted Certificate Is InstalledCIS Apache HTTP Server 2.4 L1 v2.0.0 MiddlewareUnix
7.2 Ensure a Valid Trusted Certificate Is InstalledCIS Apache HTTP Server 2.4 L1 v1.5.0Unix
7.2 Ensure Asymmetric Key Size is set to 'greater than or equal to 2048' in non-system databasesCIS SQL Server 2016 Database L1 AWS RDS v1.3.0MS_SQLDB
7.2 Ensure Asymmetric Key Size is set to 'greater than or equal to 2048' in non-system databasesCIS SQL Server 2016 Database L1 DB v1.3.0MS_SQLDB
7.3 Ensure WAL archiving is configured and functional - /var/lib/pgsql/WALCIS PostgreSQL 12 OS v1.0.0Unix
7.3 Ensure WAL archiving is configured and functional - /var/lib/pgsql/WALCIS PostgreSQL 13 OS v1.0.0Unix
7.3 Ensure WAL archiving is configured and functional - archive_commandCIS PostgreSQL 12 OS v1.0.0Unix
7.3 Ensure WAL archiving is configured and functional - archive_modeCIS PostgreSQL 13 OS v1.0.0Unix
7.5 Ensure Weak SSL/TLS Ciphers Are Disabled - 'VirtualHost SSLCipherSuite'CIS Apache HTTP Server 2.4 L1 v2.0.0Unix
7.6 Ensure Insecure SSL Renegotiation Is Not EnabledCIS Apache HTTP Server 2.4 L1 v2.0.0 MiddlewareUnix
7.6 Ensure that swarm manager is run in auto-lock modeCIS Docker v1.3.1 L2 Docker LinuxUnix
7.7 Ensure SSL Compression is not EnabledCIS Apache HTTP Server 2.4 L2 v1.5.0Unix
7.7 Ensure swarm manager auto-lock key is rotated periodicallyCIS Docker Community Edition v1.1.0 L1 DockerUnix
7.7 Ensure that the swarm manager auto-lock key is rotated periodicallyCIS Docker v1.2.0 L1 Docker LinuxUnix
7.7 Ensure that the swarm manager auto-lock key is rotated periodicallyCIS Docker v1.3.1 L1 Docker LinuxUnix
7.8 Ensure that node certificates are rotated as appropriateCIS Docker v1.3.1 L2 Docker LinuxUnix
7.9 Ensure All Web Content is Accessed via HTTPSCIS Apache HTTP Server 2.4 L2 v1.5.0Unix
7.9 Ensure All Web Content is Accessed via HTTPSCIS Apache HTTP Server 2.4 L1 v2.0.0Unix
7.9 Ensure All Web Content is Accessed via HTTPSCIS Apache HTTP Server 2.4 L1 v2.0.0 MiddlewareUnix
7.9 Ensure All Web Content is Accessed via HTTPSCIS Apache HTTP Server 2.4 L1 v1.5.0Unix
7.10 Ensure the TLSv1.0 and TLSv1.1 Protocols are DisabledCIS Apache HTTP Server 2.4 L2 v1.5.0 MiddlewareUnix
7.11 Ensure HTTP Strict Transport Security Is Enabled - 'httpd.conf Strict-Transport-Security 'max-age=480'CIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix
7.11 Ensure HTTP Strict Transport Security Is Enabled - 'httpd.conf Strict-Transport-Security configuration'CIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix
7.12 Ensure HTTP Strict Transport Security Is EnabledCIS Apache HTTP Server 2.4 L2 v1.5.0Unix