Item Search

NameAudit NamePluginCategory
1.1.3.5.1 Set 'Domain member: Require strong (Windows 2000 or later) session key' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.1.3.5.2 Set 'Domain member: Digitally sign secure channel data (when possible)' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.3.5.3 Set 'Domain member: Digitally encrypt secure channel data (when possible)' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.3.8.3 Set 'Microsoft network server: Digitally sign communications (if client agrees)' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.18 Ensure sticky bit is set on all world-writable directoriesCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

1.17 Ensure 'Allow remote lock and erase' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L1MDM
1.17 Ensure 'Allow remote lock and erase' is set to 'Enabled'MobileIron - CIS Google Android v1.3.0 L1MDM
2.2.1.3 Ensure 'Allow managed apps to store data in iCloud' is set to 'Disabled'AirWatch - CIS Apple iOS 11 v1.0.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT

2.3 Ensure 'Back up to Google Drive' is 'Disabled'MobileIron - CIS Google Android v1.3.0 L2MDM
2.3 Ensure 'Back up to Google Drive' is 'Disabled'AirWatch - CIS Google Android v1.3.0 L2MDM
2.3.8.3 Ensure 'Microsoft network client: Send unencrypted password to third-party SMB servers' is set to 'Disabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.3.11.9 Ensure 'Network security: Minimum session security for NTLM SSP based (including secure RPC) clients' is set to 'Require NTLMv2 session security, Require 128-bit encryption'CIS Windows 7 Workstation Level 1 v3.2.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.7 Ensure 'YouTube Search History' is set to 'Disabled'AirWatch - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.8 Ensure 'YouTube Watch History' is set to 'Disabled'AirWatch - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.9 Ensure 'Google Location History' is set to 'Disabled'MobileIron - CIS Google Android v1.3.0 L1MDM

CONFIGURATION MANAGEMENT

2.10 Ensure 'Opt out of Ads Personalization' is set to 'Enabled'MobileIron - CIS Google Android v1.3.0 L1MDM
2.10 Ensure 'Opt out of Ads Personalization' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L1MDM
3.2 Ensure 'Location' is set to 'Enabled'MobileIron - CIS Google Android v1.3.0 L1MDM
3.2.1.21 Ensure 'Allow setting up new nearby devices' is set to 'Disabled'AirWatch - CIS Apple iOS 12 v1.0.0 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.2.1.21 Ensure 'Allow setting up new nearby devices' is set to 'Disabled'MobileIron - CIS Apple iOS 12 v1.0.0 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.4 Ensure 'Safe Browsing' is set to 'Enabled'MobileIron - CIS Google Android v1.3.0 L1MDM
3.4 Ensure 'Safe Browsing' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L1MDM
3.6 Ensure 'Do Not Track' is set to 'Enabled'MobileIron - CIS Google Android v1.3.0 L2MDM
3.6 Ensure 'Do Not Track' is set to 'Enabled'AirWatch - CIS Google Android v1.3.0 L2MDM
4.1.13 Ensure successful file system mounts are collected - 'auditctl mounts'CIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.13 Ensure successful file system mounts are collected - 'auditctl mounts'CIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0Unix

AUDIT AND ACCOUNTABILITY

18.8.22.1.3 Ensure 'Turn off handwriting recognition error reporting' is set to 'Enabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

SYSTEM AND INFORMATION INTEGRITY

18.8.22.1.14 Ensure 'Turn off Windows Error Reporting' is set to 'Enabled'CIS Windows 7 Workstation Level 2 v3.2.0Windows

SYSTEM AND INFORMATION INTEGRITY

Audit IPSec DriverMSCT Windows 10 v1507 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit IPSec DriverMSCT Windows Server 2016 DC v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Ensure mounting of cramfs filesystems is disabled - lsmodTenable Cisco Firepower Management Center OS Best Practices AuditUnix

CONFIGURATION MANAGEMENT

Ensure mounting of freevxfs filesystems is disabled - lsmodTenable Cisco Firepower Management Center OS Best Practices AuditUnix

CONFIGURATION MANAGEMENT

Ensure mounting of freevxfs filesystems is disabled - modprobeTenable Cisco Firepower Management Center OS Best Practices AuditUnix

CONFIGURATION MANAGEMENT

Ensure mounting of hfs filesystems is disabled - lsmodTenable Cisco Firepower Management Center OS Best Practices AuditUnix

CONFIGURATION MANAGEMENT

Ensure mounting of hfsplus filesystems is disabled - lsmodTenable Cisco Firepower Management Center OS Best Practices AuditUnix

CONFIGURATION MANAGEMENT

Ensure successful file system mounts are collected - auditctl b32Tenable Cisco Firepower Management Center OS Best Practices AuditUnix

AUDIT AND ACCOUNTABILITY

Ensure successful file system mounts are collected - b64Tenable Cisco Firepower Management Center OS Best Practices AuditUnix

AUDIT AND ACCOUNTABILITY

Microsoft network client: Send unencrypted password to third-party SMB serversMSCT Windows Server 2019 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows 10 1909 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows Server 1903 DC v1.19.9Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows Server v1909 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows Server 1903 MS v1.19.9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows Server v2004 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows Server v2004 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows 10 v2004 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows 10 v20H2 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows 10 v21H2 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows Server 2012 R2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows Server 2016 MS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows Server 2019 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION