CSCv7|18

Title

Application Software Security

Reference Item Details

Category: Application Software Security

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2 Ensure 'Host headers' are on all sitesWindowsCIS IIS 10 v1.2.1 Level 1
1.3 Do not use development tools in productionUnixCIS Docker 1.6 v1.0.0 L1 Linux
1.3 Ensure 'Directory browsing' is set to DisabledWindowsCIS IIS 10 v1.2.1 Level 1
1.4 Ensure 'application pool identity' is configured for all application poolsWindowsCIS IIS 10 v1.2.1 Level 1
1.4 Ensure Service Runlevel Is Registered And Set CorrectlyUnixCIS PostgreSQL 9.6 OS v1.0.0
1.4 Ensure Service Runlevel Is Registered And Set CorrectlyUnixCIS PostgreSQL 9.5 OS v1.1.0
1.4 Ensure systemd Service Files Are EnabledUnixCIS PostgreSQL 10 OS v1.0.0
2.1 Ensure 'global authorization rule' is set to restrict accessWindowsCIS IIS 10 v1.2.1 Level 1
2.4 Ensure 'forms authentication' is set to use cookies - ApplicationWindowsCIS IIS 10 v1.2.1 Level 2
2.4 Ensure 'forms authentication' is set to use cookies - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
2.5 Ensure 'cookie protection mode' is configured for forms authentication - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
2.5 Ensure 'cookie protection mode' is configured for forms authentication - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
2.6 Ensure aufs storage driver is not usedUnixCIS Docker v1.6.0 L1 Docker Linux
2.8 Ensure the default ulimit is configured appropriately - daemon.json nofile hardUnixCIS Docker v1.6.0 L1 Docker Linux
2.8 Ensure the default ulimit is configured appropriately - daemon.json nofile softUnixCIS Docker v1.6.0 L1 Docker Linux
2.8 Ensure the default ulimit is configured appropriately - daemon.json nproc hardUnixCIS Docker v1.6.0 L1 Docker Linux
2.8 Ensure the default ulimit is configured appropriately - daemon.json nproc softUnixCIS Docker v1.6.0 L1 Docker Linux
2.8 Ensure the default ulimit is configured appropriately - psUnixCIS Docker v1.6.0 L1 Docker Linux
2.9 Enable user namespace support - /etc/subgidUnixCIS Docker v1.6.0 L2 Docker Linux
2.9 Enable user namespace support - /etc/subuidUnixCIS Docker v1.6.0 L2 Docker Linux
2.9 Enable user namespace support - SecurityOptionsUnixCIS Docker v1.6.0 L2 Docker Linux
2.10 Ensure the default cgroup usage has been confirmed - daemon.jsonUnixCIS Docker v1.6.0 L2 Docker Linux
2.10 Ensure the default cgroup usage has been confirmed - dockerdUnixCIS Docker v1.6.0 L2 Docker Linux
2.11 Ensure base device size is not changed until needed - daemon.jsonUnixCIS Docker v1.6.0 L2 Docker Linux
2.11 Ensure base device size is not changed until needed - dockerdUnixCIS Docker v1.6.0 L2 Docker Linux
2.15 Ensure live restore is enabledUnixCIS Docker v1.6.0 L1 Docker Linux
2.17 Ensure that a daemon-wide custom seccomp profile is applied if appropriateUnixCIS Docker v1.6.0 L2 Docker Linux
2.18 Ensure that experimental features are not implemented in productionUnixCIS Docker v1.6.0 L1 Docker Linux
3.1 Ensure 'deployment method retail' is setWindowsCIS IIS 10 v1.2.1 Level 1
3.2 Ensure 'debug' is turned off - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
3.2 Ensure 'debug' is turned off - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
3.3 Ensure custom error messages are not off - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
3.3 Ensure custom error messages are not off - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
3.5 Ensure ASP.NET stack tracing is not enabled - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
3.5 Ensure ASP.NET stack tracing is not enabled - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
3.6 Ensure 'httpcookie' mode is configured for session state - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
3.6 Ensure 'httpcookie' mode is configured for session state - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
3.7 Ensure 'cookies' are set with HttpOnly attribute - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
3.7 Ensure 'cookies' are set with HttpOnly attribute - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
4.1 Ensure 'maxAllowedContentLength' is configured - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
4.1 Ensure 'maxAllowedContentLength' is configured - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
4.2 Ensure 'maxURL request filter' is configured - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
4.2 Ensure 'maxURL request filter' is configured - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
4.3 Ensure 'MaxQueryString request filter' is configured - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
4.3 Ensure 'MaxQueryString request filter' is configured - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
4.4 Ensure non-ASCII characters in URLs are not allowed - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
4.4 Ensure non-ASCII characters in URLs are not allowed - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
4.10 Ensure 'notListedCgisAllowed' is set to falseWindowsCIS IIS 10 v1.2.1 Level 1