CSCv7|8.3

Title

Enable Operating System Anti-Exploitation Features/ Deploy Anti-Exploit Technologies

Description

Enable anti-exploitation features such as Data Execution Prevention (DEP) or Address Space Layout Randomization (ASLR) that are available in an operating system or deploy appropriate toolkits that can be configured to apply protection to a broader set of applications and executables.

Reference Item Details

Category: Malware Defenses

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.17.1 (L1) Ensure 'Block pop-ups from websites' is set to 'Enabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.18.1 (L1) Ensure 'browser.safebrowsing.malware.enabled' is set to 'Enabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.18.2 (L1) Ensure 'browser.safebrowsing.phishing.enabled' is set to 'Enabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L1
1.1.18.9 (L2) Ensure 'network.IDN_show_punycode' is set to 'Enabled'WindowsCIS Mozilla Firefox ESR GPO v1.0.0 L2
1.1.36 Ensure that the admission control plugin EventRateLimit is setUnixCIS Kubernetes 1.13 Benchmark v1.4.1 L1
1.2.7 Ensure that the APIPriorityAndFairness feature gate is enabledOpenShiftCIS Red Hat OpenShift Container Platform v1.8.0 L1 OpenShift
1.2.9 Ensure that the admission control plugin EventRateLimit is setUnixCIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master
1.2.9 Ensure that the admission control plugin EventRateLimit is setUnixCIS Kubernetes v1.11.1 L1 Master Node
1.2.9 Ensure that the admission control plugin EventRateLimit is setUnixCIS Kubernetes v1.23 Benchmark v1.0.1 L1 Master
1.2.9 Ensure that the admission control plugin EventRateLimit is setUnixCIS Kubernetes v1.20 Benchmark v1.0.1 L1 Master
1.4.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS CentOS Linux 7 v4.0.0 L1 Server
1.4.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS CentOS Linux 7 v4.0.0 L1 Workstation
1.4.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS Oracle Linux 7 v4.0.0 L1 Server
1.4.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS Oracle Linux 7 v4.0.0 L1 Workstation
1.4.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS Amazon Linux 2 v3.0.0 L1
1.4.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS Red Hat Enterprise Linux 7 v4.0.0 L1 Server
1.4.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS Red Hat Enterprise Linux 7 v4.0.0 L1 Workstation
1.4.2 Ensure XD/NX support is enabledUnixCIS Google Container-Optimized OS v1.2.0 L1 Server
1.4.3 Ensure address space layout randomization (ASLR) is enabledUnixCIS Google Container-Optimized OS v1.2.0 L1 Server
1.5.1 (L1) Ensure 'Configure Edge Website Typo Protection' is set to 'Enabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.5.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS Debian Linux 10 v2.0.0 L1 Server
1.5.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS Debian Linux 10 v2.0.0 L1 Workstation
1.5.1 Ensure address space layout randomization (ASLR) is enabledUnixCIS Amazon Linux 2023 v1.0.0 L1 Server
1.5.1 Ensure address space layout randomization is enabledUnixCIS SUSE Linux Enterprise 15 v2.0.1 L1 Workstation
1.5.1 Ensure address space layout randomization is enabledUnixCIS Debian Linux 11 v2.0.0 L1 Server
1.5.1 Ensure address space layout randomization is enabledUnixCIS Debian Linux 11 v2.0.0 L1 Workstation
1.5.1 Ensure address space layout randomization is enabledUnixCIS AlmaLinux OS 9 v2.0.0 L1 Workstation
1.5.1 Ensure address space layout randomization is enabledUnixCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 Workstation
1.5.1 Ensure address space layout randomization is enabledUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 Server
1.5.1 Ensure address space layout randomization is enabledUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG
1.5.1 Ensure address space layout randomization is enabledUnixCIS SUSE Linux Enterprise 15 v2.0.1 L1 Server
1.5.1 Ensure address space layout randomization is enabledUnixCIS Rocky Linux 9 v2.0.0 L1 Server
1.5.1 Ensure address space layout randomization is enabledUnixCIS AlmaLinux OS 9 v2.0.0 L1 Server
1.5.1 Ensure XD/NX support is enabledUnixCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0
1.5.1 Ensure XD/NX support is enabledUnixCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0
1.25.1 (L1) Ensure 'Configure Microsoft Defender SmartScreen' is set to 'Enabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.25.2 (L1) Ensure 'Configure Microsoft Defender SmartScreen to block potentially unwanted apps' is set to 'Enabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.25.3 (L1) Ensure 'Enable Microsoft Defender SmartScreen DNS requests' is set to 'Disabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.25.4 (L1) Ensure 'Force Microsoft Defender SmartScreen checks on downloads from trusted sources' is set to 'Enabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.25.5 (L1) Ensure 'Prevent bypassing Microsoft Defender SmartScreen prompts for sites' is set to 'Enabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.25.6 (L1) Ensure 'Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads' is set to 'Enabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.27 (L1) Ensure 'Ads setting for sites with intrusive ads' is set to 'Enabled: Block ads on sites with intrusive ads.'WindowsCIS Microsoft Edge v3.0.0 L1
1.28 (L1) Ensure 'Allow download restrictions' is set to 'Enabled: Block malicious downloads'WindowsCIS Microsoft Edge v3.0.0 L1
1.100 (L1) Ensure 'Enable site isolation for every site' is set to 'Enabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.106 (L1) Ensure 'Enable warnings for insecure forms' is set to 'Enabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.107 (L1) Ensure 'Enables DALL-E themes generation' is set to 'Disabled'WindowsCIS Microsoft Edge v3.0.0 L1
1.110 (L1) Ensure 'Enhance the security state in Microsoft Edge' is set to 'Enabled: Balanced mode' or higherWindowsCIS Microsoft Edge v3.0.0 L1
1.111 (L2) Ensure 'Enhanced Security Mode configuration for Intranet zone sites' is set to 'Disabled'WindowsCIS Microsoft Edge v3.0.0 L2
1.128 UBTU-24-700300UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.129 UBTU-24-700310UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II