Item Search

NameAudit NamePluginCategory
1.1.1 Ensure 'Login Banner' is setCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

CONFIGURATION MANAGEMENT

1.1.2 Ensure 'Login Banner' is setCIS Palo Alto Firewall 11 v1.0.0 L1Palo_Alto

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.6 Ensure maximum RAM is installedCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

1.6.1 Ensure 'Verify Update Server Identity' is enabledCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

CONFIGURATION MANAGEMENT

1.8 Ensure Retired JUNOS Devices are Disposed of SecurelyCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

3.1 Ensure a fully-synchronized High Availability peer is configuredCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

CONFIGURATION MANAGEMENT

3.1.3.1 Set Interfaces with no Peers to Passive-InterfaceCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.1.3.1 Set Interfaces with no Peers to Passive-InterfaceCIS Cisco NX-OS L2 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.1.3.2 Authenticate OSPF peers with MD5 authentication keysCIS Cisco NX-OS L2 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.1.3.3 Log OSPF Adjacency ChangesCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.1.3.3 Log OSPF Adjacency ChangesCIS Cisco NX-OS L2 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.2 Ensure 'High Availability' requires Link Monitoring and/or Path MonitoringCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

CONFIGURATION MANAGEMENT

3.2 Ensure 'High Availability' requires Link Monitoring and/or Path Monitoring - Link Monitoring Failure ConditionCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

CONFIGURATION MANAGEMENT

3.2 Ensure 'High Availability' requires Link Monitoring and/or Path Monitoring - Path Monitoring Failure ConditionCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

CONFIGURATION MANAGEMENT

3.2.1 Ensure VRRP authentication-key is setCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - External interface has ACL appliedCIS Cisco IOS 15 L2 v4.1.1Cisco

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

3.2.4 Disable IP Directed Broadcasts on all Layer 3 InterfacesCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.3 Ensure 'Passive Link State' and 'Preemptive' are configured appropriately - Election SetingsCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

CONFIGURATION MANAGEMENT

3.3 Ensure 'Passive Link State' and 'Preemptive' are configured appropriately - Passive Link StateCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

CONFIGURATION MANAGEMENT

3.3.1 Configure DHCP Trust - ip dhcp snoopingCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.3.1 Configure DHCP Trust - ip dhcp snooping trustCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.3.1 Configure DHCP Trust - ip dhcp snooping vlanCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.3.2 Configure Storm ControlCIS Cisco NX-OS L2 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.3.2 Configure Storm ControlCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.4.1 Configure LLDPCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.4.2 Configure CDPCIS Cisco NX-OS L1 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.4.2 Configure CDPCIS Cisco NX-OS L2 v1.0.0Cisco

CONFIGURATION MANAGEMENT

3.8 Ensure Loopback interface address is setCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

3.9 Ensure only one loopback address is setCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

4.1.3 Ensure EBGP peers are set to use GTSMCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

4.5.2 Ensure RIP is set to check for zero values in reserved fieldsCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

4.6.1 Ensure BFD Authentication is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

4.6.2 Ensure BFD Authentication is Not Set to Loose-CheckCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

5.6.2 Ensure use of VPC-native clustersCIS Google Kubernetes Engine (GKE) v1.5.0 L1GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.5.1 Ensure ICMPv4 rate-limit is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.5.2 Ensure ICMPv6 rate-limit is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.5.3 Ensure ICMP Source-Quench is Set to DisabledCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.5.4 Ensure TCP SYN/FIN is Set to DropCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.5.5 Ensure TCP RST is Set to DisabledCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.6.9 Ensure local passwords require multiple character setsCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.6.10 Ensure at least 4 set changes in local passwordsCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.6.11 Ensure local passwords are at least 10 charactersCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.10.5.8 Ensure REST Allowed Sources is SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.10.5.10 Ensure REST Service Address is SetCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL, CONFIGURATION MANAGEMENT

6.11.2 Ensure Auxiliary Port is Set as Insecure If UsedCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

6.13 Ensure Autoinstallation is Set to DisabledCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

6.14 Ensure Configuration File Encryption is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.19 Ensure Hostname is Not Set to Device Make or ModelCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.20 Ensure Default Address Selection is SetCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.23 Ensure Password is Set for PIC-Console-AuthenticationCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT