Item Search

NameAudit NamePluginCategory
1.1.5 Ensure that the --insecure-bind-address argument is not setCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.6 - AirWatch - Disable Passcode Unlock for FingerprintsAirWatch - CIS Apple iOS 8 v1.0.0 L2MDM

ACCESS CONTROL

1.1.7 - MobileIron - Disable 'Wi-Fi'MobileIron - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

1.1.8 - MobileIron - Disable 'Bluetooth'MobileIron - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

1.1.9 - AirWatch - Disable 'Location Services' - WiFi Location ServicesAirWatch - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

1.1.12 - MobileIron - Turn off VPN when not neededMobileIron - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

1.1.13 - MobileIron - Turn off VPN when not neededMobileIron - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.1.17 - MobileIron - Disable 'Unknown sources' - Samsung SAFEMobileIron - CIS Google Android 4 v1.0.0 L1MDM

ACCESS CONTROL

1.1.18 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

ACCESS CONTROL

1.1.31 Ensure that the --authorization-mode argument is set to NodeCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

ACCESS CONTROL

1.1.32 Ensure that the --authorization-mode argument is set to NodeCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

ACCESS CONTROL

1.2.2 - AirWatch - Enable Fraudulent Website WarningAirWatch - CIS Apple iOS 8 v1.0.0 L1MDM

ACCESS CONTROL

1.2.2 - MobileIron - Enable 'Show security warnings' - 'Samsung SAFE'MobileIron - CIS Google Android 4 v1.0.0 L1MDM

ACCESS CONTROL

1.2.3.6 Set 'Enable RPC Endpoint Mapper Client Authentication' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

1.2.4 - AirWatch - Disable Auto Fill for Names and PasswordsAirWatch - CIS Apple iOS 8 v1.0.0 L2MDM

ACCESS CONTROL

1.2.4.5.2 Configure 'Allow users to connect remotely by using Remote Desktop Services'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.5 - AirWatch - Enable 'Block pop-ups'AirWatch - CIS Google Android 4 v1.0.0 L1MDM

ACCESS CONTROL

1.2.9 - AirWatch - Turn On Do Not TrackAirWatch - CIS Apple iOS 9 v1.0.0 L2MDM

ACCESS CONTROL

1.2.9 - MobileIron - Turn On Do Not TrackMobileIron - CIS Apple iOS 8 v1.0.0 L2MDM

ACCESS CONTROL

1.2.9 - MobileIron - Turn On Do Not TrackMobileIron - CIS Apple iOS 9 v1.0.0 L2MDM

ACCESS CONTROL

2.1.5 Ensure that the --read-only-port argument is set to 0CIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.12 Ensure that the --cadvisor-port argument is set to 0CIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

CONFIGURATION MANAGEMENT

2.1.13 Ensure that the --cadvisor-port argument is set to 0CIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.2.11 Disable Apache services - Make sure that /etc/apache/httpd.conf does not exist. Note this check is only applicable for Apache 1.xCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

2.4.1 Disable Remote Apple EventsCIS Apple macOS 10.13 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.4.8 Disable File Sharing - SMBCIS Apple macOS 10.12 L1 v1.2.0Unix

CONFIGURATION MANAGEMENT

3.1.9 Disable instance discoverabilityCIS IBM DB2 v10 v1.1.0 Windows OS Level 1Windows

CONFIGURATION MANAGEMENT

3.1.9 Disable instance discoverabilityCIS IBM DB2 v10 v1.1.0 Windows OS Level 2Windows

CONFIGURATION MANAGEMENT

3.1.14 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

ACCESS CONTROL

3.2 Ensure that MongoDB only listens for network connections on authorized interfacesCIS MongoDB 3.4 L1 Windows Audit v1.0.0Windows

CONFIGURATION MANAGEMENT

3.2 Restrict Recursive Queries - Caching Name ServerCIS BIND DNS v3.0.1 Caching Only Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.7 Disable unused task schedulerCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS LinuxUnix

CONFIGURATION MANAGEMENT

4.5 Ensure ftp server is not runningCIS Apple OSX 10.11 El Capitan L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

4.6 Ensure nfs server is not runningCIS Apple macOS 10.12 L1 v1.2.0Unix

CONFIGURATION MANAGEMENT

5.1 Securely Authenticate Zone TransfersCIS BIND DNS v3.0.1 Authoritative Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.2 Disable login: Prompts on Serial Ports - Check if x is added to the flag field for ttyaCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

6.15 Configure Mail Transfer Agent for Local-Only ModeCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

7.5.1 Disable DCCPCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

7.5.4 Disable TIPCCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

8.2.6 Accept Remote rsyslog Messages Only on Designated Log Hosts - ModLoad imtcp.so - Syslog ServerCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

8.4 Disable the HTTP Statistics ServerCIS BIND DNS v3.0.1 Authoritative Name ServerUnix

CONFIGURATION MANAGEMENT

8.5 Remove default databasesCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS LinuxUnix

CONFIGURATION MANAGEMENT

9.2 Remove Unused SchemasCIS IBM DB2 v10 v1.1.0 Database Level 2IBM_DB2DB

CONFIGURATION MANAGEMENT

9.10 Check for Presence of User .rhosts FilesCIS Solaris 10 L1 v5.2Unix

CONFIGURATION MANAGEMENT

9.10 Check for Presence of User .rhosts FilesCIS Solaris 11 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

18.5.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT

18.8.37.2 Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

IDENTIFICATION AND AUTHENTICATION

18.9.59.3.3.1 Ensure 'Do not allow COM port redirection' is set to 'Enabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT

18.9.59.3.3.3 Ensure 'Do not allow LPT port redirection' is set to 'Enabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT

18.9.59.3.3.4 Ensure 'Do not allow supported Plug and Play device redirection' is set to 'Enabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT