1.1 Ensure a separate user and group exist for Cassandra - group | CIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0 | Unix | ACCESS CONTROL |
1.1 Ensure a separate user and group exist for Cassandra - group | CIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0 | Unix | ACCESS CONTROL |
1.1 Ensure a separate user and group exist for Cassandra - passwd | CIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0 | Unix | ACCESS CONTROL |
1.1 Ensure a separate user and group exist for Cassandra - user exists in group | CIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0 | Unix | ACCESS CONTROL |
1.1.2 Ensure that the API server pod specification file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Master | Unix | CONFIGURATION MANAGEMENT |
1.1.4 Ensure that the controller manager pod specification file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Master | Unix | CONFIGURATION MANAGEMENT |
1.1.8 Ensure that the etcd pod specification file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Master | Unix | CONFIGURATION MANAGEMENT |
1.1.14 Ensure that the admin.conf file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Master | Unix | CONFIGURATION MANAGEMENT |
1.1.16 Ensure that the scheduler.conf file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Master | Unix | CONFIGURATION MANAGEMENT |
1.1.18 Ensure that the controller-manager.conf file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Master | Unix | CONFIGURATION MANAGEMENT |
1.2.15 Ensure that the admission control plugin PodSecurityPolicy is set | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Master | Unix | ACCESS CONTROL |
1.2.16 Ensure that the admission control plugin PodSecurityPolicy is set | CIS Kubernetes Benchmark v1.5.1 L1 | Unix | ACCESS CONTROL |
1.2.17 Ensure that the admission control plugin NodeRestriction is set | CIS Kubernetes Benchmark v1.5.1 L1 | Unix | ACCESS CONTROL |
1.3.1 Ensure sudo is installed | CIS Red Hat EL7 Server L1 v3.0.1 | Unix | CONFIGURATION MANAGEMENT |
1.3.1 Ensure that the --terminated-pod-gc-threshold argument is set as appropriate | CIS Kubernetes Benchmark v1.5.1 L1 | Unix | CONFIGURATION MANAGEMENT |
1.3.2 Ensure that the --profiling argument is set to false | CIS Kubernetes Benchmark v1.5.1 L1 | Unix | CONFIGURATION MANAGEMENT |
1.3.3 Ensure that the --use-service-account-credentials argument is set to true | CIS Kubernetes Benchmark v1.5.1 L1 | Unix | ACCESS CONTROL |
1.4.1 Ensure that the --profiling argument is set to false | CIS Kubernetes Benchmark v1.5.1 L1 | Unix | CONFIGURATION MANAGEMENT |
1.5 Ensure the Cassandra service is run as a non-root user | CIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0 | Unix | ACCESS CONTROL |
2.1 Run BIND as a non-root User - process -u named | CIS BIND DNS v1.0.0 L1 Caching Only Name Server | Unix | ACCESS CONTROL |
2.1 Run BIND as a non-root User - UID | CIS BIND DNS v1.0.0 L1 Authoritative Name Server | Unix | ACCESS CONTROL |
2.6 Ensure that the --peer-auto-tls argument is not set to true | CIS Kubernetes Benchmark v1.5.1 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
3.7.1 Ensure 'Notification Settings' are configured for all 'Managed Apps' | AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1 | MDM | ACCESS CONTROL |
3.7.1 Ensure 'Notification Settings' are configured for all 'Managed Apps' | MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1 | MDM | ACCESS CONTROL |
4.1.2 Ensure that the kubelet service file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Worker | Unix | CONFIGURATION MANAGEMENT |
4.1.6 Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Worker | Unix | CONFIGURATION MANAGEMENT |
4.1.10 Ensure that the kubelet --config configuration file ownership is set to root:root | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Worker | Unix | CONFIGURATION MANAGEMENT |
4.2 Ensure excessive administrative privileges are revoked | CIS PostgreSQL 10 DB v1.0.0 | PostgreSQLDB | ACCESS CONTROL |
4.4 Ensure excessive DML privileges are revoked | CIS PostgreSQL 10 DB v1.0.0 | PostgreSQLDB | ACCESS CONTROL |
4.4 Ensure excessive DML privileges are revoked | CIS PostgreSQL 9.6 DB v1.0.0 | PostgreSQLDB | ACCESS CONTROL |
4.4 Ensure excessive function privileges are revoked | CIS PostgreSQL 9.5 DB v1.1.0 | PostgreSQLDB | ACCESS CONTROL |
4.5 Ensure excessive DML privileges are revoked | CIS PostgreSQL 9.5 DB v1.1.0 | PostgreSQLDB | ACCESS CONTROL |
5.2.1 Ensure sudo is installed | CIS Oracle Linux 6 Workstation L1 v2.0.0 | Unix | ACCESS CONTROL |
5.2.1 Ensure sudo is installed | CIS CentOS 6 Server L1 v3.0.0 | Unix | ACCESS CONTROL |
5.2.1 Minimize the admission of privileged containers | CIS Kubernetes v1.20 Benchmark v1.0.0 L1 Master | Unix | CONFIGURATION MANAGEMENT |
5.7 Ensure access to the su command is restricted - pam_wheel.so | CIS Oracle Linux 6 Server L1 v2.0.0 | Unix | ACCESS CONTROL |
5.7 Ensure access to the su command is restricted - pam_wheel.so | CIS Oracle Linux 6 Workstation L1 v2.0.0 | Unix | ACCESS CONTROL |
5.7 Ensure access to the su command is restricted - pam_wheel.so | CIS CentOS 6 Server L1 v3.0.0 | Unix | ACCESS CONTROL |
5.7 Ensure access to the su command is restricted - pam_wheel.so | CIS Red Hat 6 Server L1 v3.0.0 | Unix | ACCESS CONTROL |
5.7 Ensure access to the su command is restricted - pam_wheel.so | CIS CentOS 6 Workstation L1 v3.0.0 | Unix | ACCESS CONTROL |
5.7 Ensure access to the su command is restricted - wheel group contains root | CIS Oracle Linux 6 Workstation L1 v2.0.0 | Unix | ACCESS CONTROL |
5.7 Ensure access to the su command is restricted - wheel group contains root | CIS CentOS 6 Workstation L1 v3.0.0 | Unix | ACCESS CONTROL |
5.7 Ensure access to the su command is restricted - wheel group contains root | CIS Red Hat 6 Server L1 v3.0.0 | Unix | ACCESS CONTROL |
5.7 Ensure access to the su command is restricted - wheel group contains root | CIS CentOS 6 Server L1 v3.0.0 | Unix | ACCESS CONTROL |
6.5 Ensure 'Superuser' Runtime Parameters are Configured | CIS PostgreSQL 9.5 DB v1.1.0 | PostgreSQLDB | ACCESS CONTROL |
6.5 Ensure 'Superuser' Runtime Parameters are Configured | CIS PostgreSQL 9.6 DB v1.0.0 | PostgreSQLDB | ACCESS CONTROL |
6.6 Ensure 'User' Runtime Parameters are Configured | CIS PostgreSQL 10 DB v1.0.0 | PostgreSQLDB | ACCESS CONTROL |
7.1 Ensure a replication-only user is created and used for streaming replication | CIS PostgreSQL 10 DB v1.0.0 | PostgreSQLDB | ACCESS CONTROL |
7.2 Ensure a replication-only user is created and used for streaming replication | CIS PostgreSQL 9.5 DB v1.1.0 | PostgreSQLDB | ACCESS CONTROL |
Ensure authentication required for single user mode | Tenable Cisco Firepower Management Center OS Best Practices Audit | Unix | ACCESS CONTROL |