Item Search

NameAudit NamePluginCategory
1.1.21 Ensure sticky bit is set on all world-writable directoriesCIS CentOS 6 Server L1 v2.1.0Unix

ACCESS CONTROL

1.1.21 Ensure sticky bit is set on all world-writable directoriesCIS Red Hat 6 Workstation L1 v2.1.0Unix

ACCESS CONTROL

1.3.2 Ensure filesystem integrity is regularly checkedCIS CentOS 7 v3.1.1 Server L1Unix

ACCESS CONTROL

1.3.2 Ensure sudo commands use ptyCIS CentOS Linux 8 Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.3.2 Ensure sudo commands use ptyCIS Ubuntu Linux 20.04 LTS Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.6.1.1 Ensure SELinux is not disabled in bootloader configurationCIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0Unix

ACCESS CONTROL

1.6.1.1 Ensure SELinux is not disabled in bootloader configuration - selinux = 0CIS Amazon Linux v2.1.0 L2Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcingCIS Oracle Linux 6 Workstation L2 v1.1.0Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcingCIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcing - 'Current mode'CIS Ubuntu Linux 16.04 LTS Server L2 v1.1.0Unix

ACCESS CONTROL

1.6.1.2 Ensure the SELinux state is enforcing - 'SELinux status'CIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0Unix

ACCESS CONTROL

1.6.1.6 Ensure no unconfined daemons existCIS Amazon Linux 2 v1.0.0 L2Unix

ACCESS CONTROL

1.6.2 Ensure SELinux is installedCIS Amazon Linux v2.1.0 L2Unix

ACCESS CONTROL

1.6.2.2 Ensure all AppArmor Profiles are enforcing - 'unconfined processes'CIS Ubuntu Linux 14.04 LTS Server L2 v2.1.0Unix

ACCESS CONTROL

1.7.1.1 Ensure AppArmor is installedCIS Ubuntu Linux 20.04 LTS Server L1 v1.0.0Unix

ACCESS CONTROL

1.7.1.2 Ensure SELinux is not disabled in bootloader configurationCIS CentOS Linux 8 Workstation L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.3 Ensure SELinux policy is configured - sestatusCIS CentOS Linux 8 Workstation L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.4 Ensure the SELinux mode is enforcing or permissive - /etc/selinux/configCIS Red Hat EL7 Workstation L1 v3.0.1Unix

ACCESS CONTROL

1.7.1.4 Ensure the SELinux mode is enforcing or permissive - getenforceCIS Red Hat EL7 Server L1 v3.0.1Unix

ACCESS CONTROL

1.7.1.4 Ensure the SELinux state is enforcing - Mode from config file: enforcingCIS CentOS Linux 8 Workstation L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.5 Ensure no unconfined services existCIS Oracle Linux 8 Workstation L2 v1.0.0Unix

ACCESS CONTROL

1.7.1.5 Ensure the SELinux mode is enforcing - /etc/selinux/configCIS Red Hat EL7 Server L2 v3.0.1Unix

ACCESS CONTROL

1.7.1.5 Ensure the SELinux mode is enforcing - getenforceCIS Oracle Linux 7 Server L2 v3.0.0Unix

ACCESS CONTROL

1.7.1.6 Ensure no unconfined services existCIS Oracle Linux 7 Server L1 v3.0.0Unix

ACCESS CONTROL

2.2.11 Ensure 'SEC_PROTOCOL_ERROR_FURTHER_ACTION' Is Set to '(DROP,3)'CIS Oracle Server 18c DB Traditional Auditing v1.1.0OracleDB

ACCESS CONTROL

2.2.13 Ensure 'SEC_PROTOCOL_ERROR_FURTHER_ACTION' Is Set to 'DROP,3'CIS Oracle Server 12c DB Unified Auditing v3.0.0OracleDB

ACCESS CONTROL

2.2.59 (L1) Ensure 'Take ownership of files or other objects' is set to 'Administrators'CIS Microsoft Windows Server 2019 STIG v2.0.0 STIG DCWindows

ACCESS CONTROL

2.3.10.14 (L1) Ensure 'Network access: Shares that can be accessed anonymously' is set to 'None'CIS Microsoft Windows Server 2019 STIG v2.0.0 L1 DCWindows

ACCESS CONTROL

3.2 Ensure 'log_bin_basename' Files Have Appropriate PermissionsCIS MySQL 8.0 Community Database L1 v1.0.0MySQLDB

ACCESS CONTROL

3.2 Ensure Web Console is either secured or removed - 'java:/jaas/jmx-console = true'Redhat JBoss EAP 5.xUnix

ACCESS CONTROL

3.5 Ensure 'relay_log_basename' Files Have Appropriate PermissionsCIS MySQL 8.0 Community Database L1 v1.0.0MySQLDB

ACCESS CONTROL

3.6 Ensure 'general_log_file' Has Appropriate PermissionsCIS MySQL 8.0 Community Database L1 v1.0.0MySQLDB

ACCESS CONTROL

4.6 Ensure No Public Database Links ExistCIS Oracle Server 12c DB Traditional Auditing v3.0.0OracleDB

ACCESS CONTROL

4.6 Ensure No Public Database Links ExistCIS Oracle Server 18c DB Traditional Auditing v1.1.0OracleDB

ACCESS CONTROL

5.3 Reduce the sudo timeout periodCIS Apple macOS 10.15 v1.3.0 L1Unix

ACCESS CONTROL

5.3 Reduce the sudo timeout periodCIS Apple macOS 11 v1.1.0 L1Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/bashrcCIS Oracle Linux 6 Workstation L1 v1.1.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profileCIS Oracle Linux 6 Workstation L1 v1.1.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profileCIS Red Hat 6 Server L1 v2.1.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile.d/*CIS Oracle Linux 6 Server L1 v1.1.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile.d/*CIS Oracle Linux 6 Workstation L1 v1.1.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile.d/*CIS Red Hat 6 Server L1 v2.1.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile.d/*CIS Red Hat 6 Workstation L1 v2.1.0Unix

ACCESS CONTROL

5.4.4 Ensure default user umask is 027 or more restrictive - /etc/profile.d/*.shCIS Amazon Linux 2 v1.0.0 L1Unix

ACCESS CONTROL

5.6 Ensure access to the su command is restrictedCIS SUSE Linux Enterprise 15 Server L1 v1.0.0Unix

ACCESS CONTROL

5.6 Ensure access to the su command is restrictedCIS SUSE Linux Enterprise 15 Workstation L1 v1.0.0Unix

ACCESS CONTROL

7.2 Ensure appropriate database file permissions are setCIS MongoDB 5 L1 OS Windows v1.2.0Windows

ACCESS CONTROL

7.2 Ensure appropriate database file permissions are setCIS MongoDB 6 L1 OS Linux v1.1.0Unix

ACCESS CONTROL

10.4 Set Default umask for Users- '/etc/login.defs'CIS Ubuntu 12.04 LTS Benchmark L1 v1.1.0Unix

ACCESS CONTROL

19.7.26.1 (L1) Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled'CIS Microsoft Windows Server 2019 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL