Item Search

NameAudit NamePluginCategory
1.1.4.10 Set 'Create global objects' to 'Administrators, SERVICE, LOCAL SERVICE, NETWORK SERVICE'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.11 Set 'Enable computer and user accounts to be trusted for delegation' to 'No One'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.13 Set 'Shut down the system' to 'Administrators, Users'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.14 Set 'Take ownership of files or other objects' to 'Administrators'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.15 Set 'Create symbolic links' to 'Administrators'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.24 Set 'Perform volume maintenance tasks' to 'Administrators'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.32 Set 'Change the system time' to 'LOCAL SERVICE, Administrators'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.4.3 Ensure authentication required for single user mode - rescue.serviceCIS CentOS 6 Server L1 v3.0.0Unix

CONFIGURATION MANAGEMENT

1.4.3 Ensure authentication required for single user mode - rescue.serviceCIS Oracle Linux 6 Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

2.2.1 (L1) Ensure 'Access Credential Manager as a trusted caller' is set to 'No One'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

AUDIT AND ACCOUNTABILITY

2.2.7 Ensure 'Back up files and directories' is set to 'Administrators'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.9 Ensure 'Change the time zone' is set to 'Administrators, LOCAL SERVICE, Users'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.11 Ensure 'Create a token object' is set to 'No One'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.14 Configure 'Create symbolic links'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.22 Ensure 'Force shutdown from a remote system' is set to 'Administrators'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.2.29 Configure 'Log on as a service'CIS Windows 7 Workstation Level 2 v3.2.0Windows

ACCESS CONTROL

2.2.33 (L1) Ensure 'Perform volume maintenance tasks' is set to 'Administrators'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

SYSTEM AND COMMUNICATIONS PROTECTION

2.3.1.1 Ensure 'Accounts: Administrator account status' is set to 'Disabled'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.3.1.1 Ensure 'Accounts: Administrator account status' is set to 'Disabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.3.1.4 Configure 'Accounts: Rename administrator account'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.3.17.5 (L1) Ensure 'User Account Control: Only elevate UIAccess applications that are installed in secure locations' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

IDENTIFICATION AND AUTHENTICATION

2.17 Ensure no login exists with the name 'sa'CIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

CONFIGURATION MANAGEMENT

2.17 Ensure no login exists with the name 'sa'CIS SQL Server 2014 Database L1 DB v1.5.0MS_SQLDB

CONFIGURATION MANAGEMENT

3.2.1.11 Ensure 'Allow Erase All Content and Settings' is set to 'Disabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.2.1.13 Ensure 'Allow installing configuration profiles' is set to 'Disabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.2.1.15 Ensure 'Allow modifying cellular data app settings' is set to 'Disabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L2MDM

CONFIGURATION MANAGEMENT

3.2.1.16 Ensure 'Allow modifying cellular data app settings' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L2MDM

CONFIGURATION MANAGEMENT

4.1.13 Ensure use of privileged commands is collectedCIS Distribution Independent Linux Server L2 v2.0.0Unix

CONFIGURATION MANAGEMENT

4.1.13 Ensure use of privileged commands is collectedCIS Distribution Independent Linux Workstation L2 v2.0.0Unix

CONFIGURATION MANAGEMENT

4.2.1.4 Ensure rsyslog default file permissions configuredCIS CentOS 6 Server L1 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.2.1.4 Ensure rsyslog default file permissions configuredCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

AUDIT AND ACCOUNTABILITY

4.2.3 Ensure permissions on all logfiles are configuredCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.1.1.1 Ensure 'EXECUTE' is revoked from 'PUBLIC' on 'Network' PackagesCIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

ACCESS CONTROL

5.1.1.3 Ensure 'EXECUTE' is revoked from 'PUBLIC' on 'Encryption' PackagesCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

5.1.2 Ensure permissions on /etc/crontab are configuredCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.1.3 Ensure permissions on /etc/cron.hourly are configuredCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.1.7 Ensure permissions on /etc/cron.d are configuredCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.2.2 Ensure permissions on SSH private host key files are configuredCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.2.3 Ensure permissions on SSH public host key files are configuredCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.2.20 Ensure SSH PAM is enabledCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.2.22 Ensure SSH MaxStartups is configuredCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.6 Ensure access to the su command is restricted - wheel group contains rootCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

5.7 Ensure access to the su command is restricted - pam_wheel.soCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

5.7 Ensure access to the su command is restricted - wheel group contains rootCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

6.1.13 Audit SUID executablesCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.1.13 Audit SUID executablesCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

6.1.14 Audit SGID executablesCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

6.1.14 Audit SGID executablesCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

6.2.6 Ensure root is the only UID 0 accountCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

6.2.10 Ensure root is the only UID 0 accountCIS Debian Family Server L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION