Item Search

NameAudit NamePluginCategory
1.1.4 Ensure 'Minimum password length' is set to '14 or more character(s)'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

1.1.6 Ensure 'Relax minimum password length limits' is set to 'Enabled'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L1 MSWindows

IDENTIFICATION AND AUTHENTICATION

2.3.17.1 Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.0.1 L1Windows

IDENTIFICATION AND AUTHENTICATION

2.3.17.1 Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.0.1 L1 BLWindows

IDENTIFICATION AND AUTHENTICATION

2.3.17.1 Ensure 'User Account Control: Admin Approval Mode for the Built-in Administrator account' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

IDENTIFICATION AND AUTHENTICATION

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'AirWatch - CIS Apple iPadOS 18 v2.0.0 L1 Institutionally OwnedMDM

IDENTIFICATION AND AUTHENTICATION

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iPadOS 18 v2.0.0 L1 Institution OwnedMDM

IDENTIFICATION AND AUTHENTICATION

3.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterAirWatch - CIS Apple iPadOS 18 v2.0.0 L1 Institutionally OwnedMDM

IDENTIFICATION AND AUTHENTICATION

4.1.6 Ensure 'Stolen Device Protection' Is EnabledMobileIron - CIS Apple iPadOS 18 v2.0.0 L2 End User OwnedMDM

IDENTIFICATION AND AUTHENTICATION

4.3 Ensure 'CHECK_POLICY' Option is set to 'ON' for All SQL Authenticated LoginsCIS Microsoft SQL Server 2025 v1.0.0 L1 AWS RDS MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure password creation requirements are configured - dcreditCIS SUSE Linux Enterprise Server 11 L1 v2.1.1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1.3 Ensure latest version of libpam-pwquality is installedCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.3 Ensure pam_pwquality module is enabledCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.3 Ensure pam_pwquality module is enabledCIS Debian Linux 12 v1.1.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.4 Ensure pam_pwhistory module is enabledCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.4 Ensure pam_pwhistory module is enabledCIS Debian Linux 13 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.4.1 Ensure pam_unix does not include nullokCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.2.2 Ensure minimum password length is configuredCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.2.2 Ensure password length is configuredCIS Debian Linux 13 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.3.1 Ensure password history remember is configuredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.3.1 Ensure password history remember is configuredCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.3.1 Ensure password history remember is configuredCIS Debian Linux 13 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.4.1 Ensure pam_unix does not include nullokCIS Ubuntu Linux 24.04 LTS v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.4.1 Ensure pam_unix does not include nullokCIS Debian Linux 13 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.4.2 Ensure pam_unix does not include rememberCIS Rocky Linux 9 v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.4.2 Ensure pam_unix does not include rememberCIS Debian Linux 12 v1.1.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.4.2 Ensure pam_unix does not include rememberCIS Debian Linux 13 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.4.2 Ensure pam_unix does not include rememberCIS Debian Linux 13 v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - 'lcredit'CIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - 'ocredit'CIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - retryCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.2 Ensure minimum password days is configuredCIS Debian Linux 12 v1.1.0 L2 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.2 Ensure minimum password days is configuredCIS Ubuntu Linux 24.04 LTS v1.0.0 L2 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.2 Ensure minimum password days is configuredCIS Ubuntu Linux 24.04 LTS v1.0.0 L2 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.3 Ensure password expiration warning days is configuredCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure all users last password change date is in the pastCIS SUSE Linux Enterprise Server 11 L1 v2.1.1Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure all users last password change date is in the pastCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure all users last password change date is in the pastCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Debian Linux 13 v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.6 Ensure all users last password change date is in the pastCIS SUSE Linux Enterprise 12 v3.2.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.5.1.2 Ensure password expiration is 365 days or less - usersCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.5.1.3 Ensure password expiration warning days is 7 or more - login.defsCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.5.1.3 Ensure password expiration warning days is 7 or more - usersCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.5.1.3 Ensure password expiration warning days is 7 or more - usersCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.5.1.4 Ensure inactive password lock is 30 days or less - useraddCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2 Ensure the uniqueness of CHAP authentication secrets for iSCSI trafficCIS VMware ESXi 6.7 v1.3.0 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

6.2.1 Ensure accounts in /etc/passwd use shadowed passwordsCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure /etc/shadow password fields are not emptyCIS SUSE Linux Enterprise 12 v3.2.1 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION