Item Search

NameAudit NamePluginCategory
1.1 Ensure the appropriate MongoDB software version/patches are installedCIS MongoDB 7 L1 DB v1.0.0MongoDB

CONFIGURATION MANAGEMENT

1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - lsmodCIS Debian 8 Server L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - lsmodCIS Debian 8 Workstation L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - modprobeCIS Debian 8 Server L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.1.5 Ensure mounting of hfsplus filesystems is disabled - modprobeCIS Debian 8 Workstation L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.7 Ensure noexec option set on /dev/shm partition - fstabCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.1.8 Ensure nodev option set on /dev/shm partition - fstabCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.1.9 Ensure noexec option set on /var/tmp partitionCIS Debian 8 Workstation L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.9 Ensure noexec option set on /var/tmp partitionCIS Debian 8 Server L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.9 Ensure nosuid option set on /dev/shm partition - fstabCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.1.16 Ensure noexec option set on /dev/shm partitionCIS Debian 8 Server L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.16 Ensure noexec option set on /dev/shm partitionCIS Debian 8 Workstation L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.19 Ensure noexec option set on removable media partitionsCIS Debian 8 Server L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

1.1.19 Ensure noexec option set on removable media partitionsCIS Debian 8 Workstation L1 v2.0.2Unix

CONFIGURATION MANAGEMENT

2.022 - Disallow AutoPlay/Autorun from Autorun.infDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.059 - The system is configured to autoplay removable media.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

18.10.15.8 (L1) Ensure 'Toggle user control over Insider builds' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v3.0.0 L1 + NGWindows

CONFIGURATION MANAGEMENT

18.10.15.8 (L1) Ensure 'Toggle user control over Insider builds' is set to 'Disabled'CIS Microsoft Windows Server 2016 v3.0.0 L1 DCWindows

CONFIGURATION MANAGEMENT

18.10.15.8 (L1) Ensure 'Toggle user control over Insider builds' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v3.0.0 L1 + BLWindows

CONFIGURATION MANAGEMENT

20.71 Ensure 'Windows PowerShell 2.0' is 'not installed'CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG DCWindows

CONFIGURATION MANAGEMENT

20.71 Ensure 'Windows PowerShell 2.0' is 'not installed'CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG MSWindows

CONFIGURATION MANAGEMENT

Big Sur - Enable Parental ControlsNIST macOS Big Sur v1.4.0 - 800-53r5 ModerateUnix

CONFIGURATION MANAGEMENT

DTOO210 - Excel - Pre-release versions of file formats new to Office Products must be blocked.DISA STIG Office 2010 Excel v1r11Windows

CONFIGURATION MANAGEMENT

DTOO210 - PowerPoint - Pre-release versions of file formats new to Office Products must be blocked.DISA STIG Office 2010 PowerPoint v1r11Windows

CONFIGURATION MANAGEMENT

DTOO210 - Word - Pre-release versions of file formats new to Office Products must be blocked.DISA STIG Office 2010 Word v1r12Windows

CONFIGURATION MANAGEMENT

GOOG-12-006600 - Google Android 12 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-13-706600 - Google Android 13 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 13 BYOD v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-14-006600 - Google Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 14 COBO v2r1MDM

CONFIGURATION MANAGEMENT

Monterey - Enable Parental ControlsNIST macOS Monterey v1.0.0 - All ProfilesUnix

CONFIGURATION MANAGEMENT

MSFT-11-001000 - Microsoft Android 11 must be configured to enforce an application installation policy by specifying an application allow list that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Microsoft Android 11 COBO v1r2MDM

CONFIGURATION MANAGEMENT

MSFT-11-001000 - Microsoft Android 11 must be configured to enforce an application installation policy by specifying an application allow list that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Microsoft Android 11 COBO v1r2MDM

CONFIGURATION MANAGEMENT

MSFT-11-001000 - Microsoft Android 11 must be configured to enforce an application installation policy by specifying an application allow list that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Microsoft Android 11 COPE v1r2MDM

CONFIGURATION MANAGEMENT

OL08-00-040124 - OL 8 must mount '/tmp' with the 'nosuid' option.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

OL08-00-040128 - OL 8 must mount '/var/log' with the 'noexec' option.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

OL08-00-040129 - OL 8 must mount '/var/log/audit' with the 'nodev' option.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

OL08-00-040131 - OL 8 must mount '/var/log/audit' with the 'noexec' option.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

OL08-00-040132 - OL 8 must mount '/var/tmp' with the 'nodev' option.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040122 - RHEL 8 must mount /dev/shm with the noexec option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040123 - RHEL 8 must mount /tmp with the nodev option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040129 - RHEL 8 must mount /var/log/audit with the nodev option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040130 - RHEL 8 must mount /var/log/audit with the nosuid option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040132 - RHEL 8 must mount /var/tmp with the nodev option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040134 - RHEL 8 must mount /var/tmp with the noexec option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040136 - The RHEL 8 fapolicy module must be enabled.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040137 - The RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-09-231130 - RHEL 9 must mount /tmp with the noexec option.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-09-231135 - RHEL 9 must mount /tmp with the nosuid option.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-09-231155 - RHEL 9 must mount /var/log with the nosuid option.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-09-231165 - RHEL 9 must mount /var/log/audit with the noexec option.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

CONFIGURATION MANAGEMENT

WN22-CC-000220 - Windows Server 2022 default AutoRun behavior must be configured to prevent AutoRun commands.DISA Windows Server 2022 STIG v2r2Windows

CONFIGURATION MANAGEMENT