Item Search

NameAudit NamePluginCategory
1.1.1.3 Configure AAA Authentication - RADIUS if applicableCIS Cisco NX-OS v1.2.0 L1Cisco

ACCESS CONTROL

1.1.10 - AirWatch - Turn Off AirDrop DiscoverabilityAirWatch - CIS Apple iOS 9 v1.0.0 L2MDM

ACCESS CONTROL

1.1.10 - MobileIron - Turn Off AirDrop DiscoverabilityMobileIron - CIS Apple iOS 9 v1.0.0 L2MDM

ACCESS CONTROL

1.1.11 - AirWatch - Turn Off AirDrop DiscoverabilityAirWatch - CIS Apple iOS 8 v1.0.0 L2MDM

ACCESS CONTROL

1.1.11 - MobileIron - Turn Off AirDrop DiscoverabilityMobileIron - CIS Apple iOS 8 v1.0.0 L2MDM

ACCESS CONTROL

1.18 CISC-RT-000240CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT ICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.23 CISC-RT-000320CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.7 Ensure 'Receive connector timeout' is set to '5'CIS Microsoft Exchange Server 2019 L1 Mailbox v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.11 Disable Apache services - Make sure that /etc/apache/httpd.conf does not exist. Note this check is only applicable for Apache 1.xCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

2.2.11 Disable Apache services - Make sure that network/http:apache2 is disabled.CIS Solaris 10 L1 v5.2Unix
4.1.17 Ensure kernel module loading and unloading is collected - '/sbin/modprobe'CIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - 'auditctl 32-bit'CIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - 'auditctl modprobe'CIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - 'auditctl rmmod'CIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - /sbin/modprobeCIS Debian 8 Workstation L2 v2.0.2Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - auditctl /sbin/insmodCIS Debian 8 Server L2 v2.0.2Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - auditctl /sbin/insmodCIS Debian 8 Workstation L2 v2.0.2Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - auditctl insmodCIS SUSE Linux Enterprise Workstation 11 L2 v2.1.1Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - auditctl modprobeCIS Aliyun Linux 2 L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - init_moduleCIS Debian 8 Workstation L2 v2.0.2Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - init_module/delete_module (64-bit)CIS Aliyun Linux 2 L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - modprobeCIS Aliyun Linux 2 L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - modprobeCIS SUSE Linux Enterprise Workstation 11 L2 v2.1.1Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - rmmodCIS Aliyun Linux 2 L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

5.3.2.1.1 Ensure password failed attempts lockout is configuredCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

ACCESS CONTROL

5.3.3 Ensure password reuse is limited - password-authCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.3 Ensure password reuse is limited - system-authCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

7.7 Prevent X server from listening on port 6000/tcp (Solaris 9)CIS Solaris 9 v1.3Unix

CONFIGURATION MANAGEMENT

7.7 Prevent X server from listening on port 6000/tcp, Check if file permissions for /etc/dt/config/Xservers are OK (Solaris 9)CIS Solaris 9 v1.3Unix
7.10 Repairing permissions is no longer needed with 10.11CIS Apple OSX 10.11 El Capitan L1 v1.1.0Unix
9.2.3 Limit Password ReuseCIS Debian Linux 7 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

89.17 (L1) Ensure 'Generate Security Audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Intune for Windows 10 v4.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

BIND-9X-001600 - The BIND 9.x name server software must run with restricted privileges.DISA BIND 9.x STIG v3r2Unix

CONFIGURATION MANAGEMENT

CISC-RT-000320 - The Cisco perimeter switch must be configured to filter traffic destined to the enclave in accordance with the guidelines contained in DoD Instruction 8551.1.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

Configure IPsec Tunnel Parameters - replay-windowTenable Cisco Viptela SD-WAN - vEdgeCisco_Viptela

ACCESS CONTROL

DTAVSEL-009 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to scan files when being read from disk.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-011 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner maximum scan time must not be less than 45 seconds - scanMaxTmoMcAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

Ensure kernel module loading and unloading is collected - auditctl insmodTenable Cisco Firepower Management Center OS Best Practices AuditUnix

AUDIT AND ACCOUNTABILITY

Ensure password reuse is limited - pam_unix.soTenable Cisco Firepower Management Center OS Best Practices AuditUnix

IDENTIFICATION AND AUTHENTICATION

GEN005180 - All .Xauthority files must have mode 0600 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005190 - The .Xauthority files must not have extended ACLs.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

Huawei: User Interfaces Idle Timeout Less Than 5 MinutesTNS Huawei VRP Best Practice AuditHuawei

ACCESS CONTROL

O112-C2-015700 - The DBMS must use NIST-validated FIPS 140-2-compliant cryptography for authentication mechanisms.DISA STIG Oracle 11.2g v2r5 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

O112-C2-015700 - The DBMS must use NIST-validated FIPS 140-2-compliant cryptography for authentication mechanisms.DISA STIG Oracle 11.2g v2r5 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

RHEL-06-000290 - X Windows must not be enabled unless required.DISA Red Hat Enterprise Linux 6 STIG v2r2Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020510 - All .Xauthority files must have mode 0600 or less permissive.DISA Solaris 11 X86 STIG v3r5Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

SOL-11.1-020520 - The .Xauthority files must not have extended ACLs.DISA Solaris 11 SPARC STIG v3r5Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

SOL-11.1-020520 - The .Xauthority files must not have extended ACLs.DISA Solaris 11 X86 STIG v3r5Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

VCFL-67-000013 - vSphere Client must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

CONFIGURATION MANAGEMENT

VCLU-70-000012 - Lookup Service must have Multipurpose Internet Mail Extensions (MIMEs) that invoke operating system shell programs disabled - MIMEs that invoke operating system shell programs disabled.DISA STIG VMware vSphere 7.0 Lookup Service v1r2Unix

CONFIGURATION MANAGEMENT