Item Search

NameAudit NamePluginCategory
1.1.4.2 Set 'Deny log on through Remote Desktop Services' to 'Guests'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.42 Set 'Modify an object label' to 'No one'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

2.1 Ensure Only Necessary Authentication and Authorization Modules Are Enabled - 'Loaded ldap* modules'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

CONFIGURATION MANAGEMENT

2.2.5 Ensure 'Allow log on locally' is set to 'Administrators, Users'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.6 Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.8 Ensure 'REMOTE_OS_AUTHENT' Is Set to 'FALSE'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

IDENTIFICATION AND AUTHENTICATION

2.2.9 Ensure 'REMOTE_OS_ROLES' Is Set to 'FALSE'CIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

IDENTIFICATION AND AUTHENTICATION

2.2.18 Ensure 'Deny log on as a service' to include 'Guests'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.2.23 Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.27 (L1) Ensure 'Lock pages in memory' is set to 'No One'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

AUDIT AND ACCOUNTABILITY

2.2.27 Ensure 'Lock pages in memory' is set to 'No One'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.31 (L1) Ensure 'Modify an object label' is set to 'No One'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

AUDIT AND ACCOUNTABILITY

2.3.1.1 Ensure 'Accounts: Administrator account status' is set to 'Disabled'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.3.1.5 Configure 'Accounts: Rename guest account'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.3.10.3 (L1) Ensure 'Network access: Do not allow anonymous enumeration of SAM accounts and shares' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT

2.3.11.6 Ensure 'Network security: Force logoff when logon hours expire' is set to 'Enabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2008 R2 DB Engine L1 v1.7.0MS_SQLDB

ACCESS CONTROL

3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

ACCESS CONTROL

3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2014 Database L1 DB v1.5.0MS_SQLDB

ACCESS CONTROL

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iOS 12 v1.0.0 Institution Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

4.1 Ensure 'MUST_CHANGE' Option is set to 'ON' for All SQL Authenticated LoginsCIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

IDENTIFICATION AND AUTHENTICATION

4.1 Ensure 'MUST_CHANGE' Option is set to 'ON' for All SQL Authenticated LoginsCIS SQL Server 2014 Database L1 DB v1.5.0MS_SQLDB

IDENTIFICATION AND AUTHENTICATION

4.3 Ensure 'DBA_USERS.AUTHENTICATION_TYPE' Is Not Set to 'EXTERNAL' for Any UserCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

IDENTIFICATION AND AUTHENTICATION

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/cron.allow'CIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0Unix

ACCESS CONTROL

5.1.8 Ensure at/cron is restricted to authorized users - '/etc/cron.deny'CIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

5.3.3 Ensure password reuse is limitedCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

5.3.3 Ensure password reuse is limitedCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.1 Ensure password expiration is 90 days or less - login.defsCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.2 Ensure minimum days between password changes is 7 or more - usersCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile.d/*.shCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

6.2.16 Ensure no duplicate UIDs existCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.17 Ensure no duplicate GIDs existCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.18 Ensure no duplicate user names existCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.19 Ensure no duplicate group names existCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.2.19 Ensure no duplicate group names existCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

ACCESS CONTROL

Allow log on locallyMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Allow log on locallyMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Deny log on as a serviceMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Deny log on locallyMSCT Windows Server 2016 MS v1.0.0Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

Deny log on through Remote Desktop ServicesMSCT Windows Server 2019 MS v1.0.0Windows

ACCESS CONTROL

Domain member: Maximum machine account password ageMSCT Windows Server 2016 MS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

Lock pages in memoryMSCT Windows Server v1909 MS v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Lock pages in memoryMSCT Windows Server 2019 DC v1.0.0Windows

ACCESS CONTROL

Replace a process level tokenMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Replace a process level tokenMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL