CSCv6|3

Title

Secure Configurations for Hardware and Software

Description

Secure Configurations for Hardware and Software

Reference Item Details

Category: Secure Configurations for Hardware and Software

Family: System

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.3.8.2 Set 'Microsoft network server: Amount of idle time required before suspending session' to '15 or fewer minute(s)'WindowsCIS Windows 8 L1 v1.0.0
1.1.25 Ensure that the --service-account-key-file argument is set as appropriateUnixCIS Kubernetes 1.13 Benchmark v1.4.1 L1
1.1.25 Ensure that the --service-account-key-file argument is set as appropriateUnixCIS Kubernetes 1.11 Benchmark v1.3.0 L1
1.1.25 Ensure that the --service-account-key-file argument is set as appropriateUnixCIS Kubernetes 1.8 Benchmark v1.2.0 L1
1.1.26 Ensure that the --service-account-key-file argument is set as appropriateUnixCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1
1.2 Ensure the container host has been HardenedUnixCIS Docker Community Edition v1.1.0 L1 Linux Host OS
1.3.6 Apply Security Context to Your Pods and ContainersUnixCIS Kubernetes 1.7.0 Benchmark v1.1.0 L2
1.3.6 Apply Security Context to Your Pods and ContainersUnixCIS Kubernetes 1.8 Benchmark v1.2.0 L2
1.6.2 Create Pod Security Policies for your clusterUnixCIS Kubernetes 1.8 Benchmark v1.2.0 L1
1.6.2 Create Pod Security Policies for your clusterUnixCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1
1.6.5 Apply Security Context to Your Pods and ContainersUnixCIS Kubernetes 1.11 Benchmark v1.3.0 L2
1.6.5 Apply Security Context to Your Pods and ContainersUnixCIS Kubernetes 1.13 Benchmark v1.4.1 L2
1.6.6 Apply Security Context to Your Pods and ContainersUnixCIS Kubernetes 1.7.0 Benchmark v1.1.0 L2
1.6.6 Apply Security Context to Your Pods and ContainersUnixCIS Kubernetes 1.8 Benchmark v1.2.0 L2
1.13 Ensure 'Lock SIM card' is set to 'Enabled'MDMMobileIron - CIS Google Android v1.3.0 L2
1.13 Ensure 'Lock SIM card' is set to 'Enabled'MDMAirWatch - CIS Google Android v1.3.0 L2
2.1.6 Ensure that the --protect-kernel-defaults argument is set to trueUnixCIS Kubernetes 1.13 Benchmark v1.4.1 L1
2.1.7 Ensure that the --protect-kernel-defaults argument is set to trueUnixCIS Kubernetes 1.11 Benchmark v1.3.0 L1
2.1.7 Ensure that the --protect-kernel-defaults argument is set to trueUnixCIS Kubernetes 1.8 Benchmark v1.2.0 L1
2.1.7 Ensure that the --protect-kernel-defaults argument is set to trueUnixCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1
2.1.8 Ensure that the --hostname-override argument is not setUnixCIS Kubernetes 1.13 Benchmark v1.4.1 L1
2.1.9 Ensure that the --hostname-override argument is not setUnixCIS Kubernetes 1.11 Benchmark v1.3.0 L1
2.1.10 Ensure that the --hostname-override argument is not setUnixCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1
2.1.10 Ensure that the --hostname-override argument is not setUnixCIS Kubernetes 1.8 Benchmark v1.2.0 L1
2.3.9.1 (L1) Ensure 'Microsoft network server: Amount of idle time required before suspending session' is set to '15 or fewer minute(s)'WindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
2.3.9.1 Ensure 'Microsoft network server: Amount of idle time required before suspending session' is set to '15 or fewer minute(s)'WindowsCIS Windows 7 Workstation Level 1 v3.2.0
2.3.9.1 Ensure 'Microsoft network server: Amount of idle time required before suspending session' is set to '15 or fewer minute(s)'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
3.1.1 Disable IPv6UnixCIS Ubuntu Linux 18.04 LTS Workstation L2 v2.1.0
3.1.1 Disable IPv6UnixCIS Ubuntu Linux 18.04 LTS Server L2 v2.1.0
3.1.1 Ensure IP forwarding is disabled - ipv4 /etc/sysctl.conf /etc/sysctl.d/*UnixCIS Debian 8 Workstation L1 v2.0.2
3.1.1 Ensure IP forwarding is disabled - ipv4 /etc/sysctl.conf /etc/sysctl.d/*UnixCIS Debian 8 Server L1 v2.0.2
3.1.1 Ensure IP forwarding is disabled - ipv4 sysctlUnixCIS Debian 8 Server L1 v2.0.2
3.1.1 Ensure IP forwarding is disabled - ipv4 sysctlUnixCIS Debian 8 Workstation L1 v2.0.2
3.1.1 Ensure IP forwarding is disabled - ipv6 /etc/sysctl.conf /etc/sysctl.d/*UnixCIS Debian 8 Workstation L1 v2.0.2
3.1.1 Ensure IP forwarding is disabled - ipv6 /etc/sysctl.conf /etc/sysctl.d/*UnixCIS Debian 8 Server L1 v2.0.2
3.1.1 Ensure IP forwarding is disabled - ipv6 sysctlUnixCIS Debian 8 Workstation L1 v2.0.2
18.5.14.1 (L1) Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGONWindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
18.5.14.1 (L1) Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOLWindowsCIS Microsoft Windows 8.1 v2.4.1 L1 Bitlocker
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGONWindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGONWindowsCIS Windows 7 Workstation Level 1 v3.2.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGON/RequireIntegrityWindowsCIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGON/RequireIntegrityWindowsCIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGON/RequireMutualAuthenticationWindowsCIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - NETLOGON/RequireMutualAuthenticationWindowsCIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOLWindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOLWindowsCIS Windows 7 Workstation Level 1 v3.2.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOL/RequireIntegrityWindowsCIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOL/RequireIntegrityWindowsCIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOL/RequireMutualAuthenticationWindowsCIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.0
18.5.14.1 Ensure 'Hardened UNC Paths' is set to 'Enabled, with 'Require Mutual Authentication' and 'Require Integrity' set for all NETLOGON and SYSVOL shares' - SYSVOL/RequireMutualAuthenticationWindowsCIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.0