1.2 Enable SSH (PermitRootLogin) | CIS FreeBSD v1.0.5 | Unix | ACCESS CONTROL |
1.2.3.4.3 Configure 'Customize Warning Messages' | CIS Windows 8 L1 v1.0.0 | Windows | ACCESS CONTROL |
1.6.2 Ensure 'SSH version 2' is enabled | CIS Cisco ASA 9.x Firewall L1 v1.1.0 | Cisco | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
1.9 Management plane protection | CIS Cisco IOS XR 7.x v1.0.0 L2 | Cisco | ACCESS CONTROL |
2.1.1 Ensure 'SECURE_CONTROL_<listener_name>' Is Set In 'listener.ora' | CIS Oracle Server 11g R2 Unix v2.2.0 | Unix | ACCESS CONTROL |
2.1.9 Enable Global Strong Encryption | CIS Fortigate 7.0.x v1.3.0 L2 | FortiGate | ACCESS CONTROL |
2.2.2 - Configuring SSH - disabling direct root access - 'PermitRootLogin = no' | CIS AIX 5.3/6.1 L1 v1.1.0 | Unix | ACCESS CONTROL |
2.2.32 Ensure 'Deny log on through Remote Desktop Services' is set to 'Guests, Local account, Enterprise Admins Group, and Domain Admins Group' (STIG MS only) | CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG MS | Windows | ACCESS CONTROL |
2.2.34 Ensure 'Deny log on through Remote Desktop Services' is set to 'Guests, Local account, Enterprise Admins Group, and Domain Admins Group' (STIG MS only) | CIS Microsoft Windows Server 2022 STIG v1.0.0 STIG MS | Windows | ACCESS CONTROL |
2.2.35 Ensure 'Deny log on through Remote Desktop Services' is set to 'Guests, Local account, Enterprise Admins Group, and Domain Admins Group' (STIG MS only) | CIS Microsoft Windows Server 2019 STIG v2.0.0 STIG MS | Windows | ACCESS CONTROL |
2.4.5 Disable Remote Login | CIS Apple macOS 10.13 L1 v1.1.0 | Unix | ACCESS CONTROL |
2.4.5 Disable Remote Login | CIS Apple OSX 10.10 Yosemite L1 v1.2.0 | Unix | ACCESS CONTROL |
2.4.5 Disable Remote Login | CIS Apple OSX 10.11 El Capitan L1 v1.1.0 | Unix | ACCESS CONTROL |
2.4.5 Disable Remote Login | CIS Apple macOS 10.12 L1 v1.2.0 | Unix | ACCESS CONTROL |
2.4.5 Disable Remote Login | CIS Apple OSX 10.9 L1 v1.3.0 | Unix | ACCESS CONTROL |
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled' | AirWatch - CIS Apple iOS 17 Institution Owned L1 | MDM | ACCESS CONTROL |
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled' | MobileIron - CIS Apple iOS 17 Institution Owned L1 | MDM | ACCESS CONTROL |
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled' | AirWatch - CIS Apple iPadOS 17 Institutionally Owned L1 | MDM | ACCESS CONTROL |
3.2.1.16 Ensure 'Allow adding VPN configurations' is set to 'Disabled' | MobileIron - CIS Apple iPadOS 17 Institutionally Owned L1 | MDM | ACCESS CONTROL |
4.39 listener.ora - 'secure_control_listener_name = (TCP,IPC)' | CIS v1.1.0 Oracle 11g OS L2 | Unix | ACCESS CONTROL |
4.41 listener.ora - 'secure_register_listener_name = (TCP,IPC)' | CIS v1.1.0 Oracle 11g OS Windows Level 2 | Windows | ACCESS CONTROL |
5.05 OAS - 'Integrity Protection - sqlnet.crypto_checksum_client = REQUIRED' | CIS v1.1.0 Oracle 11g OS Windows Level 2 | Windows | ACCESS CONTROL |
5.16 OAS - 'SSL Client Authentication - ssl_client_authentication = TRUE' | CIS v1.1.0 Oracle 11g OS Windows Level 2 | Windows | ACCESS CONTROL |
6.6 Disable root login for SSH - PermitRootLogin = no | CIS Solaris 11.1 L1 v1.0.0 | Unix | ACCESS CONTROL |
6.6 Disable root login for SSH - PermitRootLogin = no | CIS Solaris 11 L1 v1.1.0 | Unix | ACCESS CONTROL |
9.3.8 Disable SSH Root Login | CIS Debian Linux 7 L1 v1.0.0 | Unix | ACCESS CONTROL |
12.51 Remote Administration of Listener - 'Use encryption if remote administration is required' | CIS v1.1.0 Oracle 11g OS Windows Level 2 | Windows | ACCESS CONTROL |
18.9.97.2.2 Ensure 'Allow remote server management through WinRM' is set to 'Disabled' | CIS Windows 7 Workstation Level 2 v3.2.0 | Windows | ACCESS CONTROL |
Allow Basic authentication - Client - AllowBasic | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
Allow Basic authentication - Client - AllowBasic | MSCT Windows 11 v23H2 v1.0.0 | Windows | ACCESS CONTROL |
Allow Basic authentication - Client - AllowBasic | MSCT Windows 10 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Allow Basic authentication - Service - AllowBasic | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
Allow Basic authentication - Service - AllowBasic | MSCT Windows Server 2022 v1.0.0 | Windows | ACCESS CONTROL |
Allow Basic authentication - Service - AllowBasic | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows Server 2022 v1.0.0 | Windows | ACCESS CONTROL |
Allow unencrypted traffic - Client - AllowUnencryptedTraffic | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | ACCESS CONTROL |
Allow unencrypted traffic - Service - AllowUnencryptedTraffic | MSCT Windows Server 2022 v1.0.0 | Windows | ACCESS CONTROL |
Configure Solicited Remote Assistance - fAllowToGetHelp | MSCT Windows 10 v21H1 v1.0.0 | Windows | ACCESS CONTROL |
Configure Solicited Remote Assistance - fAllowToGetHelp | MSCT Windows 10 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Configure Solicited Remote Assistance - fAllowToGetHelp | MSCT Windows 11 v22H2 v1.0.0 | Windows | ACCESS CONTROL |
Disallow Digest authentication | MSCT Windows 11 v1.0.0 | Windows | ACCESS CONTROL |
Disallow Digest authentication | MSCT Windows Server 2022 v1.0.0 | Windows | ACCESS CONTROL |
FireEye - SNMP v3 uses SHA instead of MD5 | TNS FireEye | FireEye | ACCESS CONTROL |
Fortigate - Admin access - trusted hosts | TNS Fortigate FortiOS Best Practices v2.0.0 | FortiGate | ACCESS CONTROL |
Fortigate - VPN SSL cipher suite > than 128 bits | TNS Fortigate FortiOS Best Practices v2.0.0 | FortiGate | ACCESS CONTROL |
Set client connection encryption level | MSCT MSCT Windows Server 2022 DC v1.0.0 | Windows | ACCESS CONTROL |
WatchGuard : SNMP Configuration - v3 user has password - priv protocol | TNS Best Practice WatchGuard Audit 1.0.0 | WatchGuard | ACCESS CONTROL |