Item Search

NameAudit NamePluginCategory
1.1.9 - AirWatch - Disable 'Location Services' - GPS Location ServicesAirWatch - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

1.1.17 - MobileIron - Disable 'Unknown sources' - Samsung SAFEMobileIron - CIS Google Android 4 v1.0.0 L1MDM

ACCESS CONTROL

2.1 Ensure 'Lock screen' is set to 'Don't show notifications at all'AirWatch - CIS Google Android v1.3.0 L1MDM
2.1.1 Disable Local CDE ToolTalk Database Server - Make sure that /network/rpc/cde-ttdbserver:tcp is disabledCIS Solaris 10 L1 v5.2Unix
2.1.4 Disable Local Web Console - Make sure that /system/webconsole:console is disabledCIS Solaris 10 L1 v5.2Unix
2.1.5 Disable Local WBEM - Make sure that application/management/wbem is disabledCIS Solaris 10 L1 v5.2Unix
2.2 Configure sendmail Service for Local-Only ModeCIS Solaris 11.1 L1 v1.0.0Unix
2.2 Configure sendmail Service for Local-Only ModeCIS Solaris 11.2 L1 v1.1.0Unix
2.2 Only enable telnetd if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.2.2 Disable NIS Server Daemons - Make sure that /network/nis/server is disabledCIS Solaris 10 L1 v5.2Unix
2.2.3 Disable NIS Client Daemons - Make sure that /network/nis/client is disabledCIS Solaris 10 L1 v5.2Unix
2.2.4 Disable NIS+ daemons - Make sure that /network/rpc/nisplus is disabledCIS Solaris 10 L1 v5.2Unix
2.2.7 Disable Generic Security Services (GSS) daemons - Make sure that /network/rpc/gss is disabledCIS Solaris 10 L1 v5.2Unix
2.2.12 Disable Solaris Volume Manager Services - Make sure that system/mdmonitor is disabled - Solaris 10 <= 11/06CIS Solaris 10 L1 v5.2Unix
2.2.13 Disable Solaris Volume Manager GUI - Make sure that network/rpc/meta is disabled.CIS Solaris 10 L1 v5.2Unix
2.3 Disable RPC Encryption KeyCIS Solaris 11.1 L1 v1.0.0Unix
2.3 Disable RPC Encryption KeyCIS Solaris 11.2 L1 v1.1.0Unix
2.3 Establish a Secure Baseline - Make sure that /network/smtp:sendmail only allows local connections (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that application/graphical-login/cde-login is only limited to local connectionsCIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that application/management/seaport:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that application/management/wbem only allows local connections (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that application/print/rfc1179:default is only limited to local connectionsCIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/ftp:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/nfs/server:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/cde-calendar-manager is only limited to local connectionsCIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/mdcomm:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/meta is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/rpc/rstat:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/shell:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that network/telnet:default is disabled (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.3 Establish a Secure Baseline - Make sure that system/webconsole:console only allows local connections (netservices limited)CIS Solaris 10 L1 v5.2Unix
2.4 Disable NIS Server Services - domainCIS Solaris 11.2 L1 v1.1.0Unix
2.4 Only enable rlogin/rsh/rcp if absolutely necessary (shell)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.5 Disable NIS Client Services - clientCIS Solaris 11 L1 v1.1.0Unix
2.5 Disable NIS Client Services - clientCIS Solaris 11.1 L1 v1.0.0Unix
2.5 Only enable TFTP if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

2.8 Disable Removable Volume Manager - smserverCIS Solaris 11 L1 v1.1.0Unix
2.9 Disable automount ServiceCIS Solaris 11 L1 v1.1.0Unix
2.10 Disable Apache ServiceCIS Solaris 11 L1 v1.1.0Unix
3.1 Disable login prompts on serial ports (ttyd0)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.1.4 Disable data links supportCIS IBM DB2 9 Benchmark v3.0.1 Level 1 DBIBM_DB2DB
3.7 Only enable other RPC-based services if absolutely necessary (rpc_lockd_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.8 Only enable the NFS server if absolutely necessary (mountd_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.8 Only enable the NFS server if absolutely necessary (nfs_server_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.12 Only enable NIS if absolutely necessary (nis_ypxfrd_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.13 Only enable NIS client daemons if absolutely necessary (nis_client_enable)CIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

3.14 Only enable the printer daemons if absolutely necessaryCIS FreeBSD v1.0.5Unix

CONFIGURATION MANAGEMENT

5.6 Ensure ssh is not run within containersCIS Docker Community Edition v1.1.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

6.1 Disable login: Services on Serial Ports 'terma'CIS Solaris 11 L1 v1.1.0Unix
6.1 Disable login: Services on Serial Ports 'termb'CIS Solaris 11 L1 v1.1.0Unix