Item Search

NameAudit NamePluginCategory
1.2.1 Ensure 'Account lockout duration' is set to '15 or more minute(s)'CIS Windows 7 Workstation Level 1 v3.1.0Windows

ACCESS CONTROL

1.2.2 Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'CIS Microsoft Windows 10 Enterprise (Release 1809) v1.6.1 L1Windows
1.2.2 Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'CIS Microsoft Windows 10 Enterprise (Release 1903) v1.7.1 L1Windows
1.2.2 Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'CIS Microsoft Windows 10 Enterprise (Release 2004) v1.9.1 L1Windows
1.2.2 Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0'CIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.1.0Windows

ACCESS CONTROL

1.4.1.1 Ensure 'aaa local authentication max failed attempts' is set to less than or equal to '3'CIS Cisco ASA 9.x Firewall L1 v1.0.0Cisco
1.4.2 Ensure 'Failed Attempts' and 'Lockout Time' for Authentication Profile are properly configured - Lockout TimeCIS Palo Alto Firewall 9 Benchmark v1.0.0 L1Palo_Alto
1.6.10 Set retry limit for account lockout 'AUTH_MAXTRIES=10' (non-trusted)CIS HP-UX 11i v1.5Unix

ACCESS CONTROL

2.1.1.1.5 Set maximimum value for 'ip ssh authentication-retries'CIS Cisco IOS 15 L1 v4.1.0Cisco
2.2.11 Ensure 'SEC_MAX_FAILED_LOGIN_ATTEMPTS' Is '3' or LessCIS Oracle Server 18c DB Traditional Auditing v1.0.0OracleDB
3.1 Ensure 'FAILED_LOGIN_ATTEMPTS' Is Less than or Equal to '5'CIS Oracle Server 18c DB Traditional Auditing v1.0.0OracleDB
3.1 Ensure 'FAILED_LOGIN_ATTEMPTS' Is Less than or Equal to '5'CIS Oracle Server 18c DB Unified Auditing v1.0.0OracleDB
3.2 Ensure 'PASSWORD_LOCK_TIME' Is Greater than or Equal to '1'CIS Oracle Server 18c DB Unified Auditing v1.0.0OracleDB
5.2.7 Ensure SSH MaxAuthTries is set to 4 or less - sshd outputCIS Oracle Linux 8 Workstation L1 v1.0.1Unix
5.2.7 Ensure SSH MaxAuthTries is set to 4 or less - sshd_configCIS Oracle Linux 8 Workstation L1 v1.0.1Unix
5.2.7 Ensure SSH MaxAuthTries is set to 4 or less - sshd_configCIS Oracle Linux 8 Server L1 v1.0.1Unix
5.2.7 Ensure SSH MaxAuthTries is set to 4 or less - sshd_configCIS Red Hat EL8 Server L1 v1.0.1Unix
5.2.7 Ensure SSH MaxAuthTries is set to 4 or less - sshd_configCIS Red Hat EL8 Workstation L1 v1.0.1Unix
5.3.1 Ensure password creation requirements are configured - retry=3CIS Debian 10 Server L1 v1.0.0Unix
5.3.2 Ensure lockout for failed password attempts is configured - pam_tally2.soCIS Debian 10 Server L1 v1.0.0Unix
5.3.2 Ensure lockout for failed password attempts is configured - password-auth 'auth [default=die] pam_faillock.so authfail audit deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Ensure lockout for failed password attempts is configured - password-auth 'auth sufficient pam_faillock.so authsucc audit deny=5 unlock_time=900'CIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

5.3.2 Lockout for failed password attempts - 'auth required pam_faillock.so preauth audit silent deny=5 unlock_time=900'CIS Distribution Independent Linux Workstation L1 v1.1.0Unix

ACCESS CONTROL

5.3.2 Lockout for failed password attempts - 'auth required pam_tally2.so onerr=fail audit silent deny=5 unlock_time=900'CIS Distribution Independent Linux Workstation L1 v1.1.0Unix

ACCESS CONTROL

5.4.1 Ensure password creation requirements are configured - system-auth retry=3CIS Oracle Linux 8 Server L1 v1.0.1Unix
5.4.1 Ensure password creation requirements are configured - system-auth retry=3CIS Oracle Linux 8 Workstation L1 v1.0.1Unix
5.4.2 Ensure lockout for failed password attempts is configured - account pam_deny.soCIS Ubuntu Linux 20.04 LTS Workstation L1 v1.1.0Unix
5.4.2 Ensure lockout for failed password attempts is configured - account pam_tally2.soCIS Ubuntu Linux 20.04 LTS Server L1 v1.1.0Unix
5.4.2 Ensure lockout for failed password attempts is configured - account pam_tally2.soCIS Ubuntu Linux 20.04 LTS Workstation L1 v1.1.0Unix
5.4.2 Ensure lockout for failed password attempts is configured - password-auth 'auth required pam_faillock.so authfailCIS Oracle Linux 8 Server L1 v1.0.1Unix
5.4.2 Ensure lockout for failed password attempts is configured - password-auth 'auth required pam_faillock.so authfailCIS Oracle Linux 8 Workstation L1 v1.0.1Unix
5.4.2 Ensure lockout for failed password attempts is configured - password-auth 'auth required pam_faillock.so preauthCIS Oracle Linux 8 Server L1 v1.0.1Unix
5.4.2 Ensure lockout for failed password attempts is configured - password-auth 'auth required pam_faillock.so preauthCIS Oracle Linux 8 Workstation L1 v1.0.1Unix
5.4.2 Ensure lockout for failed password attempts is configured - system-auth auth required pam_faillock.so authfailCIS Oracle Linux 8 Server L1 v1.0.1Unix
5.4.2 Ensure lockout for failed password attempts is configured - system-auth auth required pam_faillock.so authfailCIS Oracle Linux 8 Workstation L1 v1.0.1Unix
5.4.2 Ensure lockout for failed password attempts is configured - system-auth auth required pam_faillock.so preauthCIS Oracle Linux 8 Workstation L1 v1.0.1Unix
6.17 Set Retry Limit for Account Lockout - LOCK_AFTER_RETRIESCIS Oracle Solaris 11.4 L1 v1.0.0Unix
6.17 Set Retry Limit for Account Lockout - RETRIESCIS Oracle Solaris 11.4 L1 v1.0.0Unix
9.2.1 Set Password Creation Requirement Parameters Using pam_cracklib - retryCIS Debian Linux 7 L1 v1.0.0Unix

ACCESS CONTROL

9.2.2 Set Lockout for Failed Password AttemptsCIS Debian Linux 7 L1 v1.0.0Unix

ACCESS CONTROL

17.5.1 Ensure 'Audit Account Lockout' is set to 'Success and Failure'CIS Microsoft Windows Server 2008 Member Server Level 1 v3.1.0Windows

AUDIT AND ACCOUNTABILITY

17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 1809) v1.6.1 L1 + BLWindows
17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 1909) v1.8.1 L1 + BLWindows
17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 1909) v1.8.1 L1 + BL + NGWindows
17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 2004) v1.9.1 L1 + BL + NGWindows
17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 1809) v1.6.1 L1 + BL + NGWindows
17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 1809) v1.6.1 L1Windows
17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 1903) v1.7.1 L1Windows
17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 1903) v1.7.1 L1 + BLWindows
17.5.1 Ensure 'Audit Account Lockout' is set to include 'Failure'CIS Microsoft Windows 10 Enterprise (Release 2004) v1.9.1 L1 + BLWindows