Item Search

NameAudit NamePluginCategory
1.1.1.1 Ensure mounting of cramfs filesystems is disabled - lsmodCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.1 Ensure mounting of cramfs filesystems is disabled - lsmodCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.2 Ensure mounting of freevxfs filesystems is disabled - lsmodCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.3 Ensure mounting of jffs2 filesystems is disabled - lsmodCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.4 Ensure mounting of FAT filesystems is limited - lsmod fatCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.4 Ensure mounting of FAT filesystems is limited - lsmod vfatCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.4 Ensure mounting of FAT filesystems is limited - modprobe msdosCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.1.4 Ensure mounting of hfs filesystems is disabled - lsmodCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.3 Ensure nodev option set on /tmp partitionCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.7 Ensure separate partition exists for /var/tmpCIS Debian Family Server L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.14 Ensure nodev option set on /home partitionCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.1.19 Ensure nosuid option set on removable media partitionsCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.2.14 Ensure that the admission control plugin NamespaceLifecycle is setCIS Kubernetes v1.23 Benchmark v1.0.1 L1 MasterUnix

CONFIGURATION MANAGEMENT

1.5.1 Ensure bootloader password is set - password_pbkdf2CIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.5.1 Ensure bootloader password is set - superusersCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.5.2 Ensure permissions on bootloader config are configured - /boot/grub2/grub.cfgCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.5.2 Ensure permissions on bootloader config are configured - /boot/grub2/user.cfgCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.5.3 Ensure authentication required for single user modeCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.5.3 Ensure authentication required for single user mode - /usr/lib/systemd/system/emergency.serviceCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.6.4 Ensure core dumps are restricted - /etc/sysctl.confCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.6.4 Ensure core dumps are restricted - limits.conf limits.dCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.6.4 Ensure core dumps are restricted - sysctlCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.8 Ensure Retired JUNOS Devices are Disposed of SecurelyCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

1.8.1.2 Ensure local login warning banner is configured properlyCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.9 Ensure GDM is removed or login is configured - banner message enabledCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.9 Ensure GDM is removed or login is configured - banner textCIS Debian Family Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.10 Ensure GDM is removed or login is configured - banner message textCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

1.10 Ensure GDM is removed or login is configured - gdm user-dbCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.2.1 Ensure IP forwarding is disabled - sysctl.conf ipv4CIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.2.2 Ensure packet redirect sending is disabled - 'net.ipv4.conf.all.send_redirects = 0'CIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.1 Ensure source routed packets are not accepted - sysctl net.ipv4.conf.all.accept_source_routeCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.1 Ensure source routed packets are not accepted - sysctl net.ipv4.conf.default.accept_source_routeCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.6 Ensure bogus ICMP responses are ignored - sysctl net.ipv4.icmp_ignore_bogus_error_responsesCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.7 Ensure Reverse Path Filtering is enabled - sysctl net.ipv4.conf.all.rp_filterCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.8 Ensure TCP SYN Cookies is enabled - sysctl net.ipv4.tcp_syncookiesCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.3.9 Ensure IPv6 router advertisements are not accepted - sysctl net.ipv6.conf.all.accept_raCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.3 Ensure events that modify date and time information are collected - 'auditctl /etc/localtime'CIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.3 Ensure events that modify date and time information are collected - 'auditctl adjtimex (64-bit)'CIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - /etc/apparmor.d/CIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - /etc/apparmor/CIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/apparmor.d/CIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.6 Ensure events that modify the system's Mandatory Access Controls are collected - auditctl /etc/selinux/CIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

4.1.9 Ensure discretionary access control permission modification events are collected - b32 setxattrCIS Fedora 19 Family Linux Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.1.1 Ensure cron daemon is enabled and running - is-enabledCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.1.3 Ensure permissions on /etc/cron.hourly are configuredCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.2.16 Ensure SSH LoginGraceTime is set to one minute or lessCIS Debian Family Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.4.3 Ensure default group for the root account is GID 0CIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.6 Ensure access to the su command is restricted - pam_wheel.soCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.2.4 Ensure root PATH IntegrityCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

7.1 Ensure that the minimum number of manager nodes have been created in a swarmCIS Docker v1.6.0 L1 Docker SwarmUnix

CONFIGURATION MANAGEMENT