Item Search

NameAudit NamePluginCategory
1.1.1 Ensure NGINX is installedCIS NGINX Benchmark v2.1.0 L1 WebserverUnix

SYSTEM AND SERVICES ACQUISITION

1.1.1 Ensure NGINX is installedCIS NGINX Benchmark v2.1.0 L1 LoadbalancerUnix

SYSTEM AND SERVICES ACQUISITION

1.1.1 Ensure NGINX is installedCIS NGINX Benchmark v2.1.0 L1 ProxyUnix

SYSTEM AND SERVICES ACQUISITION

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL

2.1 Ensure 'global authorization rule' is set to restrict accessCIS IIS 7 L1 v1.8.0Windows

ACCESS CONTROL

2.3.22.2 Ensure 'Block signing into Office' is set to 'Enabled: Org ID only'CIS Microsoft Office Enterprise v1.2.0 L1Windows

ACCESS CONTROL

2.4 Ensure 'Protect RE' Firewall Filter includes explicit terms for all ProtocolsCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Ensure 'deployment method retail' is setCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

3.1 Ensure 'deployment method retail' is setCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

3.1 Ensure 'deployment method retail' is setCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND SERVICES ACQUISITION

3.3 Ensure Custom Error Messages are not Off - ApplicationsCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

3.3 Ensure Custom Error Messages are not Off - DefaultCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

3.6 Ensure 'httpcookie' mode is configured for session stateCIS IIS 8.0 v1.5.1 Level 2Windows

CONFIGURATION MANAGEMENT

3.6 Ensure 'httpcookie' mode is configured for session state - ApplicationsCIS IIS 7 L2 v1.8.0Windows

CONFIGURATION MANAGEMENT

4.2 Ensure 'maxURL request filter' is configured - ApplicationsCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

4.3.2.7 Ensure mrouted is not in useCIS IBM AIX 7 v1.1.0 L2Unix

CONFIGURATION MANAGEMENT

4.5 Configure Solaris Auditing - active non-attributable audit flagsCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.5 Configure Solaris Auditing - p_minfreeCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.5 Configure Solaris Auditing - userattr audit_flags rootCIS Solaris 11.2 L1 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.7 Ensure Unlisted File Extensions are not allowedCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

4.11 Ensure 'Dynamic IP Address Restrictions' is enabled - Deny By Concurrent RequestsCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.11 Ensure 'Dynamic IP Address Restrictions' is enabled - maxConcurrentRequestsCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

5.2 Ensure Advanced IIS logging is enabledCIS IIS 8.0 v1.5.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

7.4 Ensure TLS 1.0 is enabledCIS IIS 7 L1 v1.8.0Windows
CIS FreeBSD Benchmark v1.0.5CIS FreeBSD v1.0.5Unix
IIST-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 website, patches, loaded modules, and directory paths.DISA IIS 10.0 Site v2r12Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SI-000236 - The IIS 10.0 websites connectionTimeout setting must be explicitly configured to disconnect an idle session.DISA IIS 10.0 Site v2r12Windows

ACCESS CONTROL

IIST-SI-000238 - The IIS 10.0 website must use a logging mechanism configured to allocate log record storage capacity large enough to accommodate the logging requirements of the IIS 10.0 website.DISA IIS 10.0 Site v2r12Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000246 - Cookies exchanged between the IIS 10.0 website and the client must have cookie properties set to prohibit client-side scripts from reading the cookie data.DISA IIS 10.0 Site v2r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000251 - The IIS 10.0 website must have a unique application pool.DISA IIS 10.0 Site v2r12Windows

CONFIGURATION MANAGEMENT

IIST-SV-000115 - The log information from the IIS 10.0 web server must be protected from unauthorized modification or deletion.DISA IIS 10.0 Server v3r4Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000116 - The log data and records from the IIS 10.0 web server must be backed up onto a different system or media.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000116 - The log data and records from the IIS 10.0 web server must be backed up onto a different system or media.DISA IIS 10.0 Server v3r4Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000149 - The Internet Printing Protocol (IPP) must be disabled on the IIS 10.0 web serverDISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000149 - The Internet Printing Protocol (IPP) must be disabled on the IIS 10.0 web server.DISA IIS 10.0 Server v3r4Windows

CONFIGURATION MANAGEMENT

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.DISA IIS 10.0 Server v3r4Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SI-000205 - The enhanced logging for each IIS 8.5 website must be enabled and capture, record, and log all content related to a user sessionDISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000209 - The IIS 8.5 website must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 8.5 website events - success or failure of IIS 8.5 website eventsDISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 website, patches, loaded modules, and directory paths.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SI-000235 - The Idle Time-out monitor for each IIS 8.5 website must be enabled.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000251 - The IIS 8.5 website must have a unique application pool.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SV-000115 - The log information from the IIS 8.5 web server must be protected from unauthorized modification or deletion.DISA IIS 8.5 Server v2r7Windows

AUDIT AND ACCOUNTABILITY

IISW-SV-000116 - The log data and records from the IIS 8.5 web server must be backed up onto a different system or media.DISA IIS 8.5 Server v2r7Windows

AUDIT AND ACCOUNTABILITY

IISW-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 web server, patches, loaded modules, and directory paths.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SV-000149 - The Internet Printing Protocol (IPP) must be disabled on the IIS 8.5 web server - IPP must be disabled on the IIS 8.5 web serverDISA IIS 8.5 Server v2r7Windows

CONFIGURATION MANAGEMENT

SP13-00-000060 - SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds - maxBandwidthDISA STIG SharePoint 2013 v2r4Windows

CONFIGURATION MANAGEMENT

WN10-00-000100 - Internet Information System (IIS) or its subcomponents must not be installed on a workstation.DISA Microsoft Windows 10 STIG v3r4Windows

CONFIGURATION MANAGEMENT