

Ensure that all account usernames and authentication credentials are transmitted across networks using encrypted channels.


Ensure that all account usernames and authentication credentials are transmitted across networks using encrypted channels.

Reference Item Details

Category: Account Monitoring and Control

Family: Application

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.1 Ensure 'Logon Password' is setCiscoCIS Cisco Firewall v8.x L1 v4.2.0
1.1.1 Ensure 'Logon Password' is setCiscoCIS Cisco Firewall ASA 9 L1 v4.1.0 Set 'Store passwords using reversible encryption' to 'Disabled'WindowsCIS Windows 8 L1 v1.0.0
1.1.2 Ensure 'Enable Password' is setCiscoCIS Cisco Firewall v8.x L1 v4.2.0
1.1.2 Ensure 'Enable Password' is setCiscoCIS Cisco Firewall ASA 9 L1 v4.1.0 Configure 'Network access: Do not allow storage of passwords and credentials for network authentication'WindowsCIS Windows 8 L1 v1.0.0
1.1.6 Ensure 'Store passwords using reversible encryption' is set to 'Disabled'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
1.1.6 Ensure 'Store passwords using reversible encryption' is set to 'Disabled'WindowsCIS Windows 7 Workstation Level 1 v3.2.0
1.2.3 Ensure HTTP and Telnet options are disabled for the Management InterfacePalo_AltoCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0
1.2.3 Ensure HTTP and Telnet options are disabled for the Management InterfacePalo_AltoCIS Palo Alto Firewall 7 Benchmark L1 v1.0.0
1.2.3 Ensure HTTP and Telnet options are disabled for the management interfacePalo_AltoCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0
1.2.4 Ensure valid certificate is set for browser-based administrator interface - Authentication ProfilePalo_AltoCIS Palo Alto Firewall 7 Benchmark L2 v1.0.0
1.2.4 Ensure valid certificate is set for browser-based administrator interface - Authentication ProfilePalo_AltoCIS Palo Alto Firewall 6 Benchmark L2 v1.0.0
1.2.4 Ensure valid certificate is set for browser-based administrator interface - Certificate ProfilesPalo_AltoCIS Palo Alto Firewall 7 Benchmark L2 v1.0.0
1.2.4 Ensure valid certificate is set for browser-based administrator interface - Certificate ProfilesPalo_AltoCIS Palo Alto Firewall 6 Benchmark L2 v1.0.0
1.2.4 Ensure valid certificate is set for browser-based administrator interface - CertificatesPalo_AltoCIS Palo Alto Firewall 7 Benchmark L2 v1.0.0
1.2.4 Ensure valid certificate is set for browser-based administrator interface - CertificatesPalo_AltoCIS Palo Alto Firewall 6 Benchmark L2 v1.0.0 Set 'Disallow Digest authentication' to 'Enabled'WindowsCIS Windows 8 L1 v1.0.0 Set 'Allow Basic authentication' to 'Disabled'WindowsCIS Windows 8 L1 v1.0.0 Set 'Allow unencrypted traffic' to 'Disabled'WindowsCIS Windows 8 L1 v1.0.0
1.2.5 Ensure valid certificate is set for browser-based administrator interface - Authentication ProfilePalo_AltoCIS Palo Alto Firewall 8 Benchmark L2 v1.0.0
1.2.5 Ensure valid certificate is set for browser-based administrator interface - Certificate ProfilesPalo_AltoCIS Palo Alto Firewall 8 Benchmark L2 v1.0.0
1.2.5 Ensure valid certificate is set for browser-based administrator interface - CertificatesPalo_AltoCIS Palo Alto Firewall 8 Benchmark L2 v1.0.0 Ensure 'Network access: Do not allow storage of passwords and credentials for network authentication' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 v3.2.0 Ensure 'Network access: Do not allow storage of passwords and credentials for network authentication' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
2.6 Ensure transport layer security for 'basic authentication' is configuredWindowsCIS IIS 7 L1 v1.8.0
2.7 Ensure 'passwordFormat' is not set to clear - ApplicationsWindowsCIS IIS 7 L1 v1.8.0
2.7 Ensure 'passwordFormat' is not set to clear - DefaultWindowsCIS IIS 7 L1 v1.8.0
2.8 Ensure 'credentials' are not stored in configuration files - ApplicationsWindowsCIS IIS 7 L2 v1.8.0
2.8 Ensure 'credentials' are not stored in configuration files - DefaultWindowsCIS IIS 7 L2 v1.8.0
6.3.4 Upgrade Password Hashing Algorithm to SHA-512UnixCIS Red Hat Enterprise Linux 5 L1 v2.2.1
8.10 Use Blowfish encryption for all users by defaultUnixCIS FreeBSD v1.0.5
9.4 Set 'Turn on Basic feed authentication over HTTP' to 'Not Configured'WindowsCIS IE 11 v1.0.0
9.4 Set 'Turn on Basic feed authentication over HTTP' to 'Not Configured'WindowsCIS IE 10 v1.1.0
9.5 Enable SSL communication with LDAP serverUnixCIS IBM DB2 v10 v1.1.0 Linux OS Level 1 (L1) Ensure 'Allow Basic authentication' is set to 'Disabled'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker Ensure 'Allow Basic authentication' is set to 'Disabled' - ClientWindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 Ensure 'Allow Basic authentication' is set to 'Disabled' - ClientWindowsCIS Windows 7 Workstation Level 1 v3.2.0 (L1) Ensure 'Allow unencrypted traffic' is set to 'Disabled'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker Ensure 'Allow unencrypted traffic' is set to 'Disabled' - ClientWindowsCIS Windows 7 Workstation Level 1 v3.2.0 Ensure 'Allow unencrypted traffic' is set to 'Disabled' - ClientWindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 (L1) Ensure 'Disallow Digest authentication' is set to 'Enabled'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker Ensure 'Disallow Digest authentication' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 v3.2.0 Ensure 'Disallow Digest authentication' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 (L1) Ensure 'Allow Basic authentication' is set to 'Disabled'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker Ensure 'Allow Basic authentication' is set to 'Disabled' - ServiceWindowsCIS Windows 7 Workstation Level 1 v3.2.0 Ensure 'Allow Basic authentication' is set to 'Disabled' - ServiceWindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 (L1) Ensure 'Allow unencrypted traffic' is set to 'Disabled'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker Ensure 'Allow unencrypted traffic' is set to 'Disabled' - ServiceWindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0 Ensure 'Allow unencrypted traffic' is set to 'Disabled' - ServiceWindowsCIS Windows 7 Workstation Level 1 v3.2.0