Item Search

NameAudit NamePluginCategory
1.1 Ensure a separate user and group exist for Cassandra - groupCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

1.1 Ensure a separate user and group exist for Cassandra - passwdCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

ACCESS CONTROL

1.1 Ensure a separate user and group exist for Cassandra - user exists in groupCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

ACCESS CONTROL

1.1.6 Ensure that the scheduler pod specification file ownership is set to root:rootCIS Kubernetes v1.20 Benchmark v1.0.0 L1 MasterUnix

CONFIGURATION MANAGEMENT

1.1.10 Ensure that the Container Network Interface file ownership is set to root:rootCIS Kubernetes v1.20 Benchmark v1.0.0 L1 MasterUnix

CONFIGURATION MANAGEMENT

1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictiveCIS Kubernetes v1.20 Benchmark v1.0.0 L1 MasterUnix

CONFIGURATION MANAGEMENT

1.2.14 Ensure that the admission control plugin NamespaceLifecycle is setCIS Kubernetes v1.20 Benchmark v1.0.0 L1 MasterUnix

ACCESS CONTROL

1.2.15 Ensure that the admission control plugin NamespaceLifecycle is setCIS Kubernetes Benchmark v1.5.1 L1Unix

ACCESS CONTROL

1.2.16 Ensure that the admission control plugin NodeRestriction is setCIS Kubernetes v1.20 Benchmark v1.0.0 L1 MasterUnix

ACCESS CONTROL

1.3.1 Ensure sudo is installedCIS Red Hat EL7 Workstation L1 v3.0.1Unix

CONFIGURATION MANAGEMENT

1.3.2 Ensure sudo commands use ptyCIS Fedora 19 Family Linux Workstation L1 v1.0.0Unix

ACCESS CONTROL

1.3.2 Ensure sudo commands use ptyCIS Red Hat EL7 Server L1 v3.0.1Unix

ACCESS CONTROL

1.3.2 Ensure sudo commands use ptyCIS Red Hat EL7 Workstation L1 v3.0.1Unix

ACCESS CONTROL

1.5 Ensure the Cassandra service is run as a non-root userCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

ACCESS CONTROL

1.13 Ensure there is only one active access key available for any single IAM userCIS Amazon Web Services Foundations L1 1.3.0amazon_aws

IDENTIFICATION AND AUTHENTICATION

1.13 Ensure there is only one active access key available for any single IAM userCIS Amazon Web Services Foundations L1 3.0.0amazon_aws

ACCESS CONTROL

1.16 Ensure IAM policies that allow full '*:*' administrative privileges are not attached - *:* administrative privileges are not attachedCIS Amazon Web Services Foundations L1 1.5.0amazon_aws
2.1 Run BIND as a non-root User - UIDCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

ACCESS CONTROL

2.6 Ensure that the User-ID service account does not have interactive logon rightsCIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto

ACCESS CONTROL

2.6 Ensure that the User-ID service account does not have interactive logon rightsCIS Palo Alto Firewall 10 v1.2.0 L1Palo_Alto

ACCESS CONTROL

3.7.1 Ensure 'Notification Settings' are configured for all 'Managed Apps'MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

ACCESS CONTROL

3.7.1 Ensure 'Notification Settings' are configured for all 'Managed Apps'AirWatch - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

ACCESS CONTROL

4.1 Ensure that a user for the container has been createdCIS Docker v1.6.0 L1 Docker LinuxUnix

ACCESS CONTROL

4.1.4 If proxy kubeconfig file exists ensure ownership is set to root:rootCIS Kubernetes v1.20 Benchmark v1.0.0 L1 WorkerUnix

CONFIGURATION MANAGEMENT

4.1.8 Ensure that the client certificate authorities file ownership is set to root:rootCIS Kubernetes v1.20 Benchmark v1.0.0 L1 WorkerUnix

CONFIGURATION MANAGEMENT

4.3 Ensure excessive function privileges are revokedCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

4.3 Ensure excessive function privileges are revokedCIS PostgreSQL 10 OS v1.0.0Unix

ACCESS CONTROL

5.1.7 Avoid use of system:masters groupCIS Kubernetes v1.20 Benchmark v1.0.0 L1 MasterUnix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

5.2.1 Ensure sudo is installedCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.2.2 Ensure sudo commands use ptyCIS CentOS 6 Server L1 v3.0.0Unix

ACCESS CONTROL

5.2.2 Ensure sudo commands use ptyCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

5.2.2 Ensure sudo commands use ptyCIS CentOS 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.2.2 Ensure sudo commands use ptyCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

ACCESS CONTROL

5.2.5 Minimize the admission of containers with allowPrivilegeEscalationCIS Kubernetes v1.20 Benchmark v1.0.0 L1 MasterUnix

CONFIGURATION MANAGEMENT

5.2.6 Minimize the admission of root containersCIS Kubernetes v1.20 Benchmark v1.0.0 L2 MasterUnix

CONFIGURATION MANAGEMENT

5.7 Ensure access to the su command is restricted - pam_wheel.soCIS Red Hat 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.7 Ensure access to the su command is restricted - wheel group contains rootCIS Red Hat 6 Workstation L1 v3.0.0Unix

ACCESS CONTROL

5.7 Ensure access to the su command is restricted - wheel group contains rootCIS Oracle Linux 6 Server L1 v2.0.0Unix

ACCESS CONTROL

6.1.1 Create baseline of executables that elevate to a different GUID (Not scored)CIS IBM AIX 7.2 L2 v1.1.0Unix

ACCESS CONTROL

6.1.3 Create baseline of executables that elevate directly to a new EUID (not scored)CIS IBM AIX 7.2 L2 v1.1.0Unix

ACCESS CONTROL

6.5 Ensure 'Superuser' Runtime Parameters are ConfiguredCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

6.5 Restrict Access to the su Command - wheel:x:10:root, <user list>'CIS Red Hat Enterprise Linux 5 L1 v2.2.1Unix

ACCESS CONTROL

6.6 Ensure 'User' Runtime Parameters are ConfiguredCIS PostgreSQL 9.5 DB v1.1.0PostgreSQLDB

ACCESS CONTROL

6.6 Ensure 'User' Runtime Parameters are ConfiguredCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

6.10.1.5 Ensure Remote Root-Login is denied via SSHCIS Juniper OS Benchmark v2.0.0 L1Juniper

ACCESS CONTROL

6.11.4 Ensure Console Port is Set as InsecureCIS Juniper OS Benchmark v2.0.0 L2Juniper

ACCESS CONTROL

6.11.5 Ensure Log-out-on-disconnect is Set for ConsoleCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.11.5 Ensure Log-out-on-disconnect is Set for ConsoleCIS Juniper OS Benchmark v2.0.0 L1Juniper

MAINTENANCE

7.2 Ensure a replication-only user is created and used for streaming replicationCIS PostgreSQL 9.6 DB v1.0.0PostgreSQLDB

ACCESS CONTROL