Item Search

NameAudit NamePluginCategory
1.1.1 Enable 'aaa new-model'CIS Cisco IOS 16 L1 v1.1.1Cisco
1.1.2 Enable 'aaa authentication login'CIS Cisco IOS 15 L1 v4.0.1Cisco

IDENTIFICATION AND AUTHENTICATION

1.1.3 Enable 'aaa authentication enable default'CIS Cisco IOS 16 L1 v1.1.0Cisco
1.1.4 Set 'login authentication for 'line con 0'CIS Cisco IOS 15 L1 v4.0.1Cisco

IDENTIFICATION AND AUTHENTICATION

1.1.5 Set 'login authentication for 'line tty'CIS Cisco IOS 16 L1 v1.1.1Cisco
1.1.5 Set 'login authentication for 'line tty'CIS Cisco IOS 15 L1 v4.0.1Cisco

IDENTIFICATION AND AUTHENTICATION

1.1.8 Set 'aaa accounting connection'CIS Cisco IOS 16 L2 v1.1.2Cisco
1.4 Ensure that the underlying Internet Information Services (IIS) Authentication module is set to use Kerberos as its Auth ProviderCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.4 Ensure that the underlying Internet Information Services (IIS) Authentication module is set to use Kerberos as its Authentication ProviderCIS Microsoft SharePoint 2019 OS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.3.11.3 Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows Server 2016 MS L1 v1.3.0Windows
2.3.11.3 Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise (Release 20H2) v1.10.1 L1 + BL + NGWindows
2.3.11.3 Ensure 'Network Security: Allow PKU2U authentication requests to this computer to use online identities' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise (Release 21H1) v1.11.0 L1 + BL + NGWindows
3.1 Ensure 'Server Authentication' Property is set to 'Windows Authentication Mode'CIS SQL Server 2016 Database L1 DB v1.3.0MS_SQLDB
3.1 Ensure 'Server Authentication' Property is set to 'Windows Authentication Mode'CIS SQL Server 2019 Database L1 DB v1.2.0MS_SQLDB
4.2 Ensure claims-based authentication is used for all web applications and zones of a SharePoint 2016 farmCIS Microsoft SharePoint 2016 OS v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

4.3 Ensure Windows Authentication uses Kerberos and not the NT Lan Manager (NTLM) authentication protocolCIS Microsoft SharePoint 2016 OS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.3 Ensure Windows Authentication uses Kerberos and not the NT Lan Manager (NTLM) authentication protocolCIS Microsoft SharePoint 2016 OS v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

6.2.2 Ensure no legacy '+' entries exist in /etc/passwdCIS Distribution Independent Linux Server L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure no legacy '+' entries exist in /etc/passwdCIS Oracle Linux 6 Server L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure no legacy '+' entries exist in /etc/passwdHuawei EulerOS 2 Workstation L1 v1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure no legacy '+' entries exist in /etc/passwdCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure no legacy '+' entries exist in /etc/passwdCIS CentOS 6 Server L1 v2.1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.3 Ensure no legacy '+' entries exist in /etc/shadowCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

6.2.3 Ensure no legacy '+' entries exist in /etc/shadowCIS CentOS 6 Server L1 v2.1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.3 Ensure no legacy '+' entries exist in /etc/shadowCIS CentOS 6 Workstation L1 v2.1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.3 Ensure no legacy '+' entries exist in /etc/shadowCIS Distribution Independent Linux Server L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.3 Ensure no legacy '+' entries exist in /etc/shadowCIS Distribution Independent Linux Workstation L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.4 Ensure no legacy '+' entries exist in /etc/groupCIS CentOS 6 Server L1 v2.1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.4 Ensure no legacy '+' entries exist in /etc/groupHuawei EulerOS 2 Server L1 v1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.4 Ensure no legacy '+' entries exist in /etc/groupHuawei EulerOS 2 Workstation L1 v1.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.4 Ensure no legacy '+' entries exist in /etc/groupCIS Amazon Linux v2.1.0 L1Unix

IDENTIFICATION AND AUTHENTICATION

18.2.1 (L1) Ensure LAPS AdmPwd GPO Extension / CSE is installedCIS Microsoft Windows 8.1 v2.4.0 L1Windows
18.2.1 Ensure LAPS AdmPwd GPO Extension / CSE is installed (MS only)CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.2.0Windows
18.2.1 Ensure LAPS AdmPwd GPO Extension / CSE is installed (MS only)CIS Windows Server 2012 MS L1 v2.2.0Windows
18.2.3 (L1) Ensure 'Enable Local Admin Password Management' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.0 L1 BitlockerWindows
18.2.3 Ensure 'Enable Local Admin Password Management' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 20H2) v1.10.1 L1 + BLWindows
18.2.3 Ensure 'Enable Local Admin Password Management' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v1.0.0 L1 + BL + NGWindows
18.2.3 Ensure 'Enable Local Admin Password Management' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v1.0.0 L1 + NGWindows
18.2.3 Ensure 'Enable Local Admin Password Management' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 2004) v1.9.1 L1Windows
18.2.3 Ensure 'Enable Local Admin Password Management' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 21H1) v1.11.0 L1Windows
18.2.3 Ensure 'Enable Local Admin Password Management' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 20H2) v1.10.1 L1 + NGWindows
18.8.28.3 Ensure 'Do not enumerate connected users on domain-joined computers' is set to 'Enabled'CIS Microsoft Windows Server 2016 MS L1 v1.3.0Windows
18.8.28.3 Ensure 'Do not enumerate connected users on domain-joined computers' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 20H2) v1.10.1 L1 + BL + NGWindows
18.8.28.3 Ensure 'Do not enumerate connected users on domain-joined computers' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 20H2) v1.10.1 L1 + BLWindows
18.9.6.1 Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'CIS Microsoft Windows Server 2016 MS L1 v1.3.0Windows
18.9.6.1 Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 20H2) v1.10.1 L1 + NGWindows
18.9.6.1 Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 21H1) v1.11.0 L1 + NGWindows
18.9.6.1 Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 20H2) v1.10.1 L1 + BLWindows
18.9.6.1 Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise (Release 21H1) v1.11.0 L1 + BLWindows
Ensure no legacy '+' entries exist in /etc/groupTenable Cisco Firepower Management Center OS Best Practices AuditUnix

IDENTIFICATION AND AUTHENTICATION