Item Search

NameAudit NamePluginCategory
1.2 Ensure that Multi-Factor Authentication is 'Enabled' for All Non-Service AccountsCIS Google Cloud Platform v3.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

1.16 Ensure Essential Contacts is Configured for OrganizationCIS Google Cloud Platform v3.0.0 L1GCP

INCIDENT RESPONSE

2.1.4.1 Ensure cloud storage is set to enabledCIS Zoom L2 v1.0.0Zoom

CONFIGURATION MANAGEMENT

2.10 Ensure That the Log Metric Filter and Alerts Exist for Cloud Storage IAM Permission ChangesCIS Google Cloud Platform v3.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

2.10.1 Ensure 'Allow automatic sign-in to Microsoft cloud identity providers' Is EnabledCIS Google Chrome L1 v3.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

4.1.1.1 Ensure correct container image is set for stackdriver logging agentCIS Google Container-Optimized OS v1.2.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

4.2 Ensure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIsCIS Google Cloud Platform v3.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

4.2.6 Ensure inline scanning with FortiGuard AI-Based Sandbox Service is enabledCIS Fortigate 7.0.x v1.3.0 L1FortiGate

SYSTEM AND INFORMATION INTEGRITY

5.7 Choosing Wildfire public cloud regionCIS Palo Alto Firewall 11 v1.1.0 L2Palo_Alto

CONFIGURATION MANAGEMENT

5.7 Choosing Wildfire public cloud regionCIS Palo Alto Firewall 10 v1.2.0 L2Palo_Alto

CONFIGURATION MANAGEMENT

5.7.1 Ensure Logging and Cloud Monitoring is EnabledCIS Google Kubernetes Engine (GKE) v1.6.1 L1GCP

AUDIT AND ACCOUNTABILITY

5.8 Ensure that 'Inline Cloud Analysis' on Wildfire profiles is enabledCIS Palo Alto Firewall 10 v1.2.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.8 Ensure that 'Inline Cloud Analysis' on Wildfire profiles is enabledCIS Palo Alto Firewall 11 v1.1.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.9.1 Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD)CIS Google Kubernetes Engine (GKE) v1.6.1 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.9.2 Enable Customer-Managed Encryption Keys (CMEK) for Boot DisksCIS Google Kubernetes Engine (GKE) v1.6.1 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.1.1 Ensure That a MySQL Database Instance Does Not Allow Anyone To Connect With Administrative PrivilegesCIS Google Cloud Platform v3.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

6.5 Ensure That Cloud SQL Database Instances Do Not Implicitly Whitelist All Public IP AddressesCIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

6.6 Ensure That Cloud SQL Database Instances Do Not Have Public IPsCIS Google Cloud Platform v3.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

6.7 Ensure That Cloud SQL Database Instances Are Configured With Automated BackupsCIS Google Cloud Platform v3.0.0 L1GCP

CONTINGENCY PLANNING

6.22 Ensure that 'Inline Cloud Analysis' on Vulnerability Protection profiles are enabled if 'Advanced Threat Prevention' is availableCIS Palo Alto Firewall 10 v1.2.0 L1Palo_Alto

RISK ASSESSMENT

6.22 Ensure that 'Inline Cloud Analysis' on Vulnerability Protection profiles are enabled if 'Advanced Threat Prevention' is availableCIS Palo Alto Firewall 11 v1.1.0 L1Palo_Alto

RISK ASSESSMENT

6.24 Ensure that 'Inline Cloud Analysis' on Anti-Spyware profiles are enabled if 'Advanced Threat Prevention' is availableCIS Palo Alto Firewall 10 v1.2.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.24 Ensure that 'Inline Cloud Analysis' on Anti-Spyware profiles are enabled if 'Advanced Threat Prevention' is availableCIS Palo Alto Firewall 11 v1.1.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

8.1 Ensure that Dataproc Cluster is encrypted using Customer-Managed Encryption KeyCIS Google Cloud Platform v3.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.10.12.2 (L2) Ensure 'Turn off cloud optimized content' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v3.0.0 L2 NGWindows

CONFIGURATION MANAGEMENT

18.10.12.2 (L2) Ensure 'Turn off cloud optimized content' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

18.10.12.2 (L2) Ensure 'Turn off cloud optimized content' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v3.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

60.1 (L2) Ensure 'Allow Cloud Search' is set to 'Not allowed'CIS Microsoft Intune for Windows 10 v3.0.1 L2Windows

CONFIGURATION MANAGEMENT

60.1 (L2) Ensure 'Allow Cloud Search' is set to 'Not allowed'CIS Microsoft Intune for Windows 11 v3.0.1 L2Windows

CONFIGURATION MANAGEMENT

AADC-CL-001315 - Adobe Acrobat Pro DC Classic SharePoint and Office365 access must be disabled.DISA STIG Adobe Acrobat Pro DC Classic Track v2r1Windows

CONFIGURATION MANAGEMENT

AADC-CN-001315 - Adobe Acrobat Pro DC Continuous SharePoint and Office365 access must be disabled.DISA STIG Adobe Acrobat Pro DC Continuous Track v2r1Windows

CONFIGURATION MANAGEMENT

ADBP-XI-001315 - Adobe Acrobat Pro XI SharePoint and Office365 Access must be disabled.DISA STIG ADOBE ACROBAT PROFESSIONAL (PRO) XI v1r2Windows

CONFIGURATION MANAGEMENT

AIOS-02-080003 - Apple iOS must not allow backup to remote systems (iCloud document and data synchronization).MobileIron - DISA Apple iOS 10 v1r3MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-02-080003 - Apple iOS must not allow backup to remote systems (iCloud document and data synchronization).AirWatch - DISA Apple iOS 10 v1r3MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AIOS-02-080103 - Apple iOS must not allow backup to remote systems (managed applications data stored in iCloud).AirWatch - DISA Apple iOS 10 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-02-080103 - Apple iOS must not allow backup to remote systems (managed applications data stored in iCloud).MobileIron - DISA Apple iOS 10 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-02-090101 - Apple iOS must implement the management setting: Disable Allow iCloud Photo Library.AirWatch - DISA Apple iOS 10 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-02-090101 - Apple iOS must implement the management setting: Disable Allow iCloud Photo Library.MobileIron - DISA Apple iOS 10 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-12-004600 - Apple iOS must not allow backup to remote systems (managed applications data stored in iCloud).AirWatch - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-12-004600 - Apple iOS must not allow backup to remote systems (managed applications data stored in iCloud).MobileIron - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-004600 - Apple iOS/iPadOS must not allow backup to remote systems (managed applications data stored in iCloud).AirWatch - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-004600 - Apple iOS/iPadOS must not allow backup to remote systems (managed applications data stored in iCloud).MobileIron - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

ARDC-CL-000060 - Adobe Reader DC must disable all service access to Document Cloud Services.DISA STIG Adobe Acrobat Reader DC Classic Track v2r1Windows

CONFIGURATION MANAGEMENT

ARDC-CN-000060 - Adobe Reader DC must disable all service access to Document Cloud Services.DISA STIG Adobe Acrobat Reader DC Continuous Track v2r1Windows

CONFIGURATION MANAGEMENT

DTBC-0023 - Cloud print sharing must be disabled.DISA STIG Google Chrome v2r9Windows

ACCESS CONTROL

iOS Device Management - Managed apps sync to cloudTenable Best Practices for Microsoft Intune iOS v1.0microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT

KNOX-07-001600 - The Samsung whitelist must be configured to not include applications that Back up MD data to non-DoD cloud servers.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-001600 - The Samsung whitelist must be configured to not include applications that Back up MD data to non-DoD cloud servers.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

WDNS-CM-000025 - The Windows 2012 DNS Servers zone files must not include CNAME records pointing to a zone with lesser security for more than six months.DISA Microsoft Windows 2012 Server DNS STIG v2r7Windows

CONFIGURATION MANAGEMENT

Windows Device Configuration - Cloud-delivered protectionTenable Best Practices for Microsoft Intune Windows v1.0microsoft_azure

CONFIGURATION MANAGEMENT