Item Search

NameAudit NamePluginCategory
1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Microsoft Windows Server 2025 v1.0.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

IDENTIFICATION AND AUTHENTICATION

1.1.3 (L1) Ensure 'Minimum password age' is set to '1 or more day(s)'CIS Microsoft Windows 11 Enterprise v4.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

1.1.6 (L1) Ensure 'Relax minimum password length limits' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

IDENTIFICATION AND AUTHENTICATION

2.3.1.2 (L1) Ensure 'Accounts: Limit local account use of blank passwords to console logon only' is set to 'Enabled'CIS Microsoft Windows Server 2025 v1.0.0 L1 DCWindows

IDENTIFICATION AND AUTHENTICATION

3.14 (L1) Host must configure the password history setting to restrict the reuse of passwordsCIS VMware ESXi 8.0 v1.1.0 L1VMware

IDENTIFICATION AND AUTHENTICATION

3.15 (L1) Host must be configured with an appropriate maximum password ageCIS VMware ESXi 8.0 v1.1.0 L1VMware

IDENTIFICATION AND AUTHENTICATION

4.2.19 Ensure sshd PermitEmptyPasswords is disabledCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.2.19 Ensure sshd PermitEmptyPasswords is disabledCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.2.22 Ensure sshd UsePAM is enabledCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.2.22 Ensure sshd UsePAM is enabledCIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

4.4.1.2 Ensure libpwquality is installedCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.2.1 Ensure pam_pwquality module is enabledCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.2.1 Ensure pam_pwquality module is enabledCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.2.4 Ensure password complexity is configuredCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.2.5 Ensure password same consecutive characters is configuredCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.2.5 Ensure password same consecutive characters is configuredCIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.2.7 Ensure password dictionary check is enabledCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.3.1 Ensure pam_pwhistory module is enabledCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.3.2 Ensure password history remember is configuredCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.3.3 Ensure password history is enforced for the root userCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.3.3 Ensure password history is enforced for the root userCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.4.2 Ensure pam_unix does not include rememberCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.4.2.4.2 Ensure pam_unix does not include rememberCIS Oracle Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

4.5.1.4 Ensure inactive password lock is 30 days or lessCIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

4.6.1.2 Ensure minimum days between password changes is configuredCIS Amazon Linux 2023 Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

5.1.9 Ensure sshd GSSAPIAuthentication is disabledCIS Debian Linux 11 v2.0.0 L2 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.2.8 Ensure Password History Is ConfiguredCIS Apple macOS 12.0 Monterey Cloud-tailored v1.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.2.8 Ensure Password History Is ConfiguredCIS Apple macOS 13.0 Ventura v3.0.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

5.3.1 Ensure password creation requirements are configuredCIS SUSE Linux Enterprise 12 v3.2.1 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.2.2 Ensure password number of changed characters is configuredCIS SUSE Linux Enterprise 15 v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.2.2 Ensure password number of changed characters is configuredCIS SUSE Linux Enterprise 15 v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.2.4 Ensure password complexity is configuredCIS SUSE Linux Enterprise 15 v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.2.6 Ensure password maximum sequential characters is configuredCIS SUSE Linux Enterprise 15 v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.3.1 Ensure password history remember is configuredCIS SUSE Linux Enterprise 15 v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.4.1 Ensure pam_unix does not include nullokCIS SUSE Linux Enterprise 15 v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3 Ensure password reuse is limitedCIS SUSE Linux Enterprise 12 v3.2.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configuredCIS Amazon Linux 2 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS SUSE Linux Enterprise 15 v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS SUSE Linux Enterprise 15 v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.6 Ensure all users last password change date is in the pastCIS SUSE Linux Enterprise 12 v3.2.1 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

6.1 Setup Client-cert AuthenticationCIS Apache Tomcat 10.1 v1.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure /etc/shadow password fields are not emptyCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

6.3.2 (L1) Host iSCSI client, if enabled, must employ unique CHAP authentication secretsCIS VMware ESXi 8.0 v1.1.0 L1VMware

IDENTIFICATION AND AUTHENTICATION

7.2.2 Ensure /etc/shadow password fields are not emptyCIS SUSE Linux Enterprise 15 v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

7.5 Ensure Password Complexity Policies are in PlaceCIS Oracle MySQL Community Server 8.4 v1.0.0 L1 DatabaseMySQLDB

IDENTIFICATION AND AUTHENTICATION

18.10.10.2.1 (BL) Ensure 'Allow enhanced PINs for startup' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v4.0.0 BitLockerWindows

IDENTIFICATION AND AUTHENTICATION

18.10.10.2.1 (BL) Ensure 'Allow enhanced PINs for startup' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v4.0.0 L1 BitLockerWindows

IDENTIFICATION AND AUTHENTICATION

26.9 (L1) Ensure 'Minimum Password Age' is set to '1 or more day(s)'CIS Microsoft Intune for Windows 11 v4.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION

105.3 (L1) Ensure 'Password Complexity' is set to 'Large letters + small letters + numbers + special characters'CIS Microsoft Intune for Windows 11 v4.0.0 L1Windows

IDENTIFICATION AND AUTHENTICATION