Item Search

NameAudit NamePluginCategory
1.2.1 Use an EFI passwordCIS Apple OSX 10.6 Snow Leopard L2 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.4.2 Ensure bootloader password is set - 'passwd_pbkdf2'CIS Ubuntu Linux 14.04 LTS Server L1 v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.4.2 Ensure bootloader password is set - password_pbkdf2CIS SUSE Linux Enterprise Server 12 L1 v2.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.4.2 Ensure filesystem integrity is regularly checked - aidecheck.timer statusCIS Oracle Linux 8 Server L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.4.3 Ensure boot loader does not allow removable mediaCIS Amazon Linux 2 STIG v1.0.0 L3Unix

SYSTEM AND INFORMATION INTEGRITY

1.5.3 Ensure authentication required for single user mode - rescue.serviceCIS Red Hat EL8 Workstation L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.2.1 Use an Open Firmware or EFI passwordCIS Apple OSX 10.5 Leopard L2 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.4 Do not use insecure registriesCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

SYSTEM AND INFORMATION INTEGRITY

2.13 Ensure EFI version is valid and being regularly checked - daemonCIS Apple macOS 10.13 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.29.2 Ensure 'Legacy Format Signatures' is set to DisabledCIS Microsoft Office 2013 v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.030 - A file integrity tool must verify the baseline operating system configuration at least weekly - cronTenable Fedora Linux Best Practices v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.040 - Designated personnel must be notified if baseline configurations are changed in an unauthorized manner.Tenable Fedora Linux Best Practices v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.3 Set Boot Loader Password - passwordCIS Ubuntu 12.04 LTS Benchmark L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.3.3 Ensure IPv6 is disabledCIS SUSE Linux Enterprise Server 11 L1 v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

5.3.3 Ensure cryptographic mechanisms are used to protect the integrity of audit toolsCIS Oracle Linux 8 Server L1 v3.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

5.23 System Integrity Protection statusCIS Apple macOS 10.13 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.1.1 Audit system file permissionsCIS Amazon Linux 2 STIG v1.0.0 L2Unix

SYSTEM AND INFORMATION INTEGRITY

6.13 Secure the GRUB Menu - Check if 'password' is set in /boot/grub/menu.lst. Note: This check only checks if password is setCIS Solaris 10 L1 v5.2Unix

SYSTEM AND INFORMATION INTEGRITY

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-#badlogins = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-mode = commandCIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.17 Secure the GRUB Menu (Intel) - grub.cfg passwordCIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.17 Secure the GRUB Menu (Intel) - grub2_defs.bios GRUB_TIMEOUT = 30CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.17 Secure the GRUB Menu (Intel) - grub2_defs.bios GRUB_TIMEOUT = 30CIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.17 Secure the GRUB Menu (Intel) - menu.conf timeout = 30CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.17 Secure the GRUB Menu (Intel) - menu.conf timeout = 30CIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

9.2 Verify System File PermissionsCIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

18.4.6 (L1) Ensure 'LSA Protection' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v2.0.0 L1 MSWindows

SYSTEM AND INFORMATION INTEGRITY

18.9.25.1 (NG) Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock'CIS Microsoft Windows Server 2019 STIG v2.0.0 NG DCWindows

SYSTEM AND INFORMATION INTEGRITY

Big Sur - Ensure Secure Boot Level Set to FullNIST macOS Big Sur v1.4.0 - 800-53r4 HighUnix

SYSTEM AND INFORMATION INTEGRITY

Big Sur - Ensure Secure Boot Level Set to FullNIST macOS Big Sur v1.4.0 - 800-53r5 HighUnix

SYSTEM AND INFORMATION INTEGRITY

Big Sur - Ensure Secure Boot Level Set to FullNIST macOS Big Sur v1.4.0 - 800-53r5 ModerateUnix

SYSTEM AND INFORMATION INTEGRITY

Brocade - Enable the power-on self-test (POST)Tenable Best Practices Brocade FabricOSBrocade

SYSTEM AND INFORMATION INTEGRITY

Brocade : 'Enforce signature validation for firmware'TNS Brocade FabricOS Best PracticesBrocade

SYSTEM AND INFORMATION INTEGRITY

Catalina - Ensure Secure Boot Level Set to FullNIST macOS Catalina v1.5.0 - 800-53r5 HighUnix

SYSTEM AND INFORMATION INTEGRITY

Catalina - Ensure Secure Boot Level Set to FullNIST macOS Catalina v1.5.0 - 800-53r5 ModerateUnix

SYSTEM AND INFORMATION INTEGRITY

Check for signatures on downloaded programsMSCT Windows Server 1903 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Check for signatures on downloaded programsMSCT Windows 10 v1709 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Ensure GPG keys are configured - apt-key listTenable Cisco Firepower Management Center OS Best Practices AuditUnix

SYSTEM AND INFORMATION INTEGRITY

Monterey - Ensure Secure Boot Level Set to FullNIST macOS Monterey v1.0.0 - 800-53r5 ModerateUnix

SYSTEM AND INFORMATION INTEGRITY

Monterey - Ensure Secure Boot Level Set to FullNIST macOS Monterey v1.0.0 - All ProfilesUnix

SYSTEM AND INFORMATION INTEGRITY

Monterey - Ensure Secure Boot Level Set to FullNIST macOS Monterey v1.0.0 - 800-53r4 HighUnix

SYSTEM AND INFORMATION INTEGRITY

PCI 2.2.4 - Verify that common security parameter settings are included - NFS - 'all entries in /etc/exports contain sec='PCI DSS 2.0/3.0 - AIXUnix

SYSTEM AND INFORMATION INTEGRITY

Require that application add-ins are signed by Trusted Publisher - requireaddinsig - excelMicrosoft 365 Apps for Enterprise 2306 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Require that application add-ins are signed by Trusted Publisher - requireaddinsig - ms projectMSCT Microsoft 365 Apps for Enterprise 2206 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - ConfigureSystemGuardLaunchMSCT Windows 10 v1903 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - EnableVirtualizationBasedSecurityMSCT Windows 10 v1703 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - HVCIMATRequiredMSCT Windows Server 1903 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - HVCIMATRequiredMSCT Windows 10 v1903 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - LsaCfgFlagsMSCT Windows 10 v1709 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Turn On Virtualization Based Security - RequirePlatformSecurityFeaturesMSCT Windows 10 v1903 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY