Item Search

NameAudit NamePluginCategory
1.4.1 Enable SELinux in /etc/grub.conf - enforcing != 0CIS Red Hat Enterprise Linux 5 L2 v2.2.1Unix

ACCESS CONTROL

1.5.1 Ensure bootloader password is setCIS Red Hat EL7 Server L1 v3.0.1Unix

ACCESS CONTROL

1.5.1 Ensure bootloader password is setCIS Red Hat EL7 Workstation L1 v3.0.1Unix

ACCESS CONTROL

1.5.2 Ensure bootloader password is setCIS Oracle Linux 8 Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.6.1.2 Ensure AppArmor is enabled in the bootloader configuration - securityCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure all AppArmor Profiles are enforcing - complainCIS Ubuntu Linux 16.04 LTS Server L2 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure all AppArmor Profiles are enforcing - complainCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure all AppArmor Profiles are enforcing - loadedCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure all AppArmor Profiles are enforcing - unconfinedCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure the SELinux mode is enforcing or permissive - getenforceCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

1.6.1.4 Ensure the SELinux mode is enforcing or permissive - getenforceCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

1.6.1.6 Ensure no unconfined daemons existHuawei EulerOS 2 Server L2 v1.0Unix

ACCESS CONTROL

1.7.1.5 Ensure no unconfined services existCIS Red Hat EL8 Workstation L2 v1.0.0Unix

ACCESS CONTROL

2.2 Give the BIND User Account an Invalid ShellCIS BIND DNS v3.0.1 Caching Only Name ServerUnix

ACCESS CONTROL

2.2.11 Ensure 'SEC_PROTOCOL_ERROR_FURTHER_ACTION' Is Set to '(DROP,3)'CIS Oracle Server 18c DB Unified Auditing v1.1.0OracleDB

ACCESS CONTROL

2.2.56 (L1) Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Microsoft Windows Server 2016 STIG v2.0.0 L1 MSWindows

ACCESS CONTROL

2.2.56 (L1) Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Microsoft Windows Server 2016 STIG v2.0.0 STIG DCWindows

ACCESS CONTROL

2.2.59 (L1) Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Microsoft Windows Server 2019 STIG v2.0.0 L1 MSWindows

ACCESS CONTROL

2.2.59 (L1) Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Microsoft Windows Server 2019 STIG v2.0.0 STIG MSWindows

ACCESS CONTROL

2.2.59 Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Microsoft Windows Server 2022 STIG v1.0.0 L1 DCWindows

ACCESS CONTROL

2.3.10.12 (L1) Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Windows Server 2012 MS L1 v3.0.0Windows

ACCESS CONTROL

2.3.10.14 Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows Server 2022 STIG v1.0.0 L1 DCWindows

ACCESS CONTROL

3.1 Ensure 'datadir' Has Appropriate PermissionsCIS MySQL 8.0 Community Database L1 v1.0.0MySQLDB

ACCESS CONTROL

3.1 Ensure JMX Console is either secured or removed - 'java:/jaas/jmx-console = true'Redhat JBoss EAP 5.xUnix

ACCESS CONTROL

3.3 Ensure 'log_error' Has Appropriate PermissionsCIS MySQL 8.0 Enterprise Database L1 v1.3.0MySQLDB

ACCESS CONTROL

3.3 Ensure Admin Console is either secured or removed - 'java:/jaas/jmx-console = true'Redhat JBoss EAP 5.xUnix

ACCESS CONTROL

3.4 The JMXInvokerServlet servlet must be secured against web attacksRedhat JBoss EAP 5.xUnix

ACCESS CONTROL

3.6 Ensure 'general_log_file' Has Appropriate PermissionsCIS MySQL 8.0 Enterprise Database L1 v1.3.0MySQLDB

ACCESS CONTROL

4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf no Deny directives exist'CIS Apache HTTP Server 2.2 L1 v3.5.0Unix

ACCESS CONTROL

4.1 Ensure Access to OS Root Directory Is Denied By Default - 'httpd.conf no Require directives exist'CIS Apache HTTP Server 2.2 L1 v3.5.0Unix

ACCESS CONTROL

5.1.9 Ensure at is restricted to authorized users - '/etc/at.allow'CIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

ACCESS CONTROL

5.2.2 Ensure permissions on SSH private host key files are configuredCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

ACCESS CONTROL

5.2.3 Ensure permissions on SSH public host key files are configuredCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

5.3.1 Ensure permissions on /etc/ssh/sshd_config are configuredCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profileHuawei EulerOS 2 Server L1 v1.0Unix

ACCESS CONTROL

5.4.10 Ensure default user umask is 077CIS Amazon Linux 2 STIG v1.0.0 L3Unix

ACCESS CONTROL

5.5.3 Ensure default group for the root account is GID 0CIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.5.5 Ensure default user umask is 027 or more restrictive - bashrcCIS Red Hat EL8 Server L1 v1.0.0Unix

ACCESS CONTROL

6.1.3 Disable guest account loginCIS Apple macOS 10.14 v1.3.0 L1Unix

ACCESS CONTROL

6.1.5 Ensure permissions on /etc/gshadow are configuredCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.11 Ensure users' .netrc Files are not group or world accessibleCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.20 Ensure shadow group is empty - /etc/groupCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

7.1 Extensible Firmware Interface (EFI) passwordCIS Apple macOS 10.15 v1.3.0 L2Unix

ACCESS CONTROL

8.1.1 Set Warning Banner for Standard Login Services - /etc/issueCIS Red Hat Enterprise Linux 5 L1 v2.2.1Unix

ACCESS CONTROL

8.1.1 Set Warning Banner for Standard Login Services - /etc/issue.netCIS Red Hat Enterprise Linux 5 L1 v2.2.1Unix

ACCESS CONTROL

8.11 Set default umask for users, Check if 'umask' is set to 077 - Check /etc/profile.CIS Solaris 9 v1.3Unix

ACCESS CONTROL

9.1.1 Verify System File PermissionsCIS Red Hat Enterprise Linux 5 L2 v2.2.1Unix

ACCESS CONTROL

18.10.3.1 (L2) Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows Server 2022 v3.0.0 L2 Member ServerWindows

ACCESS CONTROL

18.10.3.1 (L2) Ensure 'Allow a Windows app to share application data between users' is set to 'Disabled'CIS Microsoft Windows Server 2016 v3.0.0 L2 MSWindows

ACCESS CONTROL

19.7.26.1 (L1) Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2019 v3.0.1 L1 DCWindows

ACCESS CONTROL