Item Search

NameAudit NamePluginCategory
1.1.22 Disable AutomountingCIS SUSE Linux Enterprise Workstation 11 L2 v2.1.1Unix

MEDIA PROTECTION

1.1.23 Disable AutomountingCIS SUSE Linux Enterprise 12 v3.2.1 L2 WorkstationUnix

MEDIA PROTECTION

1.1.27 Disable AutomountingCIS Amazon Linux 2 STIG v2.0.0 L1 ServerUnix

MEDIA PROTECTION

18.9.7.1.1 (L1) Ensure 'Allow installation of devices that match any of these device IDs' is set to 'Enabled: <Org Specific Device IDs>'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL, MEDIA PROTECTION

18.9.7.1.2 (L1) Ensure 'Apply layered order of evaluation for Allow and Prevent device installation policies across all device match criteria' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL, MEDIA PROTECTION

18.10.9.3.5 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION

18.10.9.3.7 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Save BitLocker recovery information to AD DS for removable data drives' is set to 'Enabled: False'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION

18.10.10.3.2 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v4.0.0 L1 BLWindows

MEDIA PROTECTION

18.10.10.3.2 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.10.3.3 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'CIS Microsoft Windows 11 Stand-alone v4.0.0 L1 BLWindows

MEDIA PROTECTION

18.10.10.3.3 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BLWindows

MEDIA PROTECTION

18.10.10.3.3 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'CIS Microsoft Windows 11 Enterprise v4.0.0 BitLockerWindows

MEDIA PROTECTION

18.10.10.3.3 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Allow data recovery agent' is set to 'Enabled: True'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

MEDIA PROTECTION

18.10.10.3.4 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Password' is set to 'Enabled: Do not allow 48-digit recovery password'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

MEDIA PROTECTION

18.10.10.3.4 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Password' is set to 'Enabled: Do not allow 48-digit recovery password'CIS Microsoft Windows 11 Stand-alone v4.0.0 BLWindows

MEDIA PROTECTION

18.10.10.3.4 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Password' is set to 'Enabled: Do not allow 48-digit recovery password'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.10.3.4 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Password' is set to 'Enabled: Do not allow 48-digit recovery password'CIS Microsoft Windows 11 Enterprise v4.0.0 BitLockerWindows

MEDIA PROTECTION

18.10.10.3.5 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'CIS Microsoft Windows 11 Enterprise v4.0.0 BitLockerWindows

MEDIA PROTECTION

18.10.10.3.5 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'CIS Microsoft Windows 11 Stand-alone v4.0.0 BLWindows

MEDIA PROTECTION

18.10.10.3.6 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Omit recovery options from the BitLocker setup wizard' is set to 'Enabled: True'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.10.3.7 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Save BitLocker recovery information to AD DS for removable data drives' is set to 'Enabled: False'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.10.3.8 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages'CIS Microsoft Windows 11 Enterprise v4.0.0 BitLockerWindows

MEDIA PROTECTION

18.10.10.3.8 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

MEDIA PROTECTION

18.10.10.3.8 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Configure storage of BitLocker recovery information to AD DS:' is set to 'Enabled: Backup recovery passwords and key packages'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.10.3.9 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for removable data drives' is set to 'Enabled: False'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.10.42.13.1 (L1) Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.42.13.1 Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Windows Server 2016 STIG v3.0.0 L1 MSWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.42.13.1 Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Windows Server 2022 STIG v2.0.0 L1 Member ServerWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.42.13.1 Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Windows Server 2019 STIG v3.0.0 L1 DCWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.42.13.2 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows Server 2016 v3.0.0 L1 DCWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.42.13.2 Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows Server 2016 STIG v3.0.0 L1 MSWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.42.13.2 Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows Server 2019 STIG v3.0.0 L1 MSWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.42.13.2 Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows Server 2022 STIG v2.0.0 L1 Domain ControllerWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.1 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Windows Server 2012 DC L1 v3.0.0Windows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.1 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Windows Server 2012 MS L1 v3.0.0Windows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.2 (L1) Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Windows Server 2022 v4.0.0 L1 DCWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.2 (L1) Ensure 'Scan packed executables' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.3 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows Server 2019 v4.0.0 L1 MSWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.3 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows Server 2025 v1.0.0 L1 MSWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.3 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v4.0.0 L1Windows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.10.43.13.3 (L1) Ensure 'Scan removable drives' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 NGWindows

MEDIA PROTECTION, SYSTEM AND INFORMATION INTEGRITY

Catalina - Disable Removable Storage DevicesNIST macOS Catalina v1.5.0 - CNSSI 1253Unix

MEDIA PROTECTION

Catalina - Disable Removable Storage DevicesNIST macOS Catalina v1.5.0 - 800-53r5 HighUnix

MEDIA PROTECTION

Monterey - Disable Removable Storage DevicesNIST macOS Monterey v1.0.0 - 800-53r4 HighUnix

MEDIA PROTECTION

Monterey - Disable Removable Storage DevicesNIST macOS Monterey v1.0.0 - 800-53r4 ModerateUnix

MEDIA PROTECTION

Monterey - Disable Removable Storage DevicesNIST macOS Monterey v1.0.0 - 800-53r5 HighUnix

MEDIA PROTECTION

Monterey - Disable Removable Storage DevicesNIST macOS Monterey v1.0.0 - 800-53r5 LowUnix

MEDIA PROTECTION

Monterey - Disable Removable Storage DevicesNIST macOS Monterey v1.0.0 - 800-53r5 ModerateUnix

MEDIA PROTECTION

Monterey - Disable Removable Storage DevicesNIST macOS Monterey v1.0.0 - All ProfilesUnix

MEDIA PROTECTION

Monterey - Disable Removable Storage DevicesNIST macOS Monterey v1.0.0 - CNSSI 1253Unix

MEDIA PROTECTION