Item Search

NameAudit NamePluginCategory
1.2.8 Ensure prevent hosts from accessing their cloud recordings is set to enabledCIS Zoom L2 v1.0.0Zoom

CONFIGURATION MANAGEMENT

1.4 Ensure That There Are Only GCP-Managed Service Account Keys for Each Service AccountCIS Google Cloud Platform v3.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

1.7 Ensure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or FewerCIS Google Cloud Platform v3.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION

1.13 Ensure API Keys Are Restricted To Use by Only Specified Hosts and AppsCIS Google Cloud Platform v3.0.0 L2GCP

PLANNING, SYSTEM AND SERVICES ACQUISITION

1.17 Ensure Secrets are Not Stored in Cloud Functions Environment Variables by Using Secret ManagerCIS Google Cloud Platform v3.0.0 L1GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3 Ensure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket LockCIS Google Cloud Platform v3.0.0 L2GCP

ACCESS CONTROL, MEDIA PROTECTION

2.3.23.2 (L1) Ensure 'Block signing into Office' is set to 'Enabled: Org ID only'CIS Microsoft Intune for Office v1.1.0 L1Windows

ACCESS CONTROL

2.4 Ensure Log Metric Filter and Alerts Exist for Project Ownership Assignments/ChangesCIS Google Cloud Platform v3.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

2.4.3 (L2) Ensure Microsoft Defender for Cloud Apps is enabled and configuredCIS Microsoft 365 Foundations v4.0.0 L2 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.11 Ensure That the Log Metric Filter and Alerts Exist for SQL Instance Configuration ChangesCIS Google Cloud Platform v3.0.0 L2GCP

AUDIT AND ACCOUNTABILITY

3.4 Ensure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSECCIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.5 Ensure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSECCIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.7 Ensure That RDP Access Is Restricted From the InternetCIS Google Cloud Platform v3.0.0 L2GCP

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.10 Use Identity Aware Proxy (IAP) to Ensure Only Traffic From Google IP Addresses are 'Allowed'CIS Google Cloud Platform v3.0.0 L2GCP

ACCESS CONTROL

4.7 Ensure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)CIS Google Cloud Platform v3.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.8 Ensure Compute Instances Are Launched With Shielded VM EnabledCIS Google Cloud Platform v3.0.0 L2GCP

CONFIGURATION MANAGEMENT

4.11 Ensure That Compute Instances Have Confidential Computing EnabledCIS Google Cloud Platform v3.0.0 L2GCP

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.1 Ensure That Cloud Storage Bucket Is Not Anonymously or Publicly AccessibleCIS Google Cloud Platform v3.0.0 L1GCP

ACCESS CONTROL, MEDIA PROTECTION

6.2.5 Ensure that the 'Log_min_messages' Flag for a Cloud SQL PostgreSQL Instance is set at minimum to 'Warning'CIS Google Cloud Platform v3.0.0 L1GCP

AUDIT AND ACCOUNTABILITY

6.3.6 Ensure '3625 (trace flag)' database flag for all Cloud SQL Server instances is set to 'on'CIS Google Cloud Platform v3.0.0 L1GCP

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

61.1 (L2) Ensure 'Disallow Cloud Notification' is set to 'Allow'CIS Microsoft Intune for Windows 11 v4.0.0 L2Windows

CONFIGURATION MANAGEMENT

AIOS-12-004200 - Apple iOS must not allow backup to remote systems (iCloud document and data synchronization).MobileIron - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-12-004200 - Apple iOS must not allow backup to remote systems (iCloud document and data synchronization).AirWatch - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-12-011300 - Apple iOS must implement the management setting: Disable Allow Shared Albums.AirWatch - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-13-011300 - Apple iOS/iPadOS must implement the management setting: Disable Allow Shared Albums.AirWatch - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-14-009500 - Apple iOS/iPadOS must implement the management setting: Disable Allow Shared Albums.AirWatch - DISA Apple iOS/iPadOS 14 v1r3MDM

CONFIGURATION MANAGEMENT

APPL-13-002037 - The macOS system must be configured to disable the Cloud Storage Setup services.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

Do not suggest third-party content in Windows spotlightMSCT Windows 10 v21H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Do not suggest third-party content in Windows spotlightMSCT Windows 11 v1.0.0Windows

CONFIGURATION MANAGEMENT

Do not suggest third-party content in Windows spotlightMSCT Windows 11 v24H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Do not suggest third-party content in Windows spotlightMSCT Windows 10 v21H1 v1.0.0Windows

CONFIGURATION MANAGEMENT

Do not suggest third-party content in Windows spotlightMSCT Windows 10 1803 v1.0.0Windows

CONFIGURATION MANAGEMENT

Do not suggest third-party content in Windows spotlightMSCT Windows 10 v20H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

GOOG-09-003900 - The Google Android Pie must be configured to not allow backup of all applications and configuration data to remote systems.MobileIron - DISA Google Android 9.x v2r1MDM

ACCESS CONTROL

GOOG-10-003900 - Google Android 10 must be configured to not allow backup of all applications and configuration data to remote systems.MobileIron - DISA Google Android 10.x v2r1MDM

ACCESS CONTROL

GOOG-11-003900 - Google Android 11 must be configured to not allow backup of all applications and configuration data to remote systems.MobileIron - DISA Google Android 11 COPE v2r1MDM

ACCESS CONTROL

GOOG-11-003900 - Google Android 11 must be configured to not allow backup of all applications and configuration data to remote systems.MobileIron - DISA Google Android 11 COBO v2r1MDM

ACCESS CONTROL

GOOG-11-003900 - Google Android 11 must be configured to not allow backup of all applications and configuration data to remote systems.AirWatch - DISA Google Android 11 COBO v2r1MDM

ACCESS CONTROL

GOOG-15-008600 - Google Android 15 must be configured to not allow backup of [all applications, configuration data] to remote systems.AirWatch - DISA Google Android 15 COBO v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-15-008600 - Google Android 15 must be configured to not allow backup of [all applications, configuration data] to remote systems.MobileIron - DISA Google Android 15 COBO v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

HONW-09-003900 - The Honeywell Mobility Edge Android Pie device must be configured to not allow backup of all applications and configuration data to remote systems.MobileIron - DISA Honeywell Android 9.x COBO v1r2MDM

ACCESS CONTROL

MOTO-09-003900 - The Motorola Android Pie must be configured to not allow backup of all applications and configuration data to remote systems.AirWatch - DISA Motorola Android Pie.x COBO v1r2MDM

ACCESS CONTROL

MOTO-09-003900 - The Motorola Android Pie must be configured to not allow backup of all applications and configuration data to remote systems.AirWatch - DISA Motorola Android Pie.x COPE v1r2MDM

ACCESS CONTROL

MS.AAD.3.2v1 - If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.CISA SCuBA Microsoft 365 Entra ID v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

MSFT-11-003900 - Microsoft Android 11 must be configured to not allow backup of all applications and configuration data to remote systems.AirWatch - DISA Microsoft Android 11 COBO v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

MSFT-11-003900 - Microsoft Android 11 must be configured to not allow backup of all applications and configuration data to remote systems.MobileIron - DISA Microsoft Android 11 COBO v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

MSFT-11-003900 - Microsoft Android 11 must be configured to not allow backup of all applications and configuration data to remote systems.MobileIron - DISA Microsoft Android 11 COPE v1r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

WN10-CC-000197 - Microsoft consumer experiences must be turned off.DISA Microsoft Windows 10 STIG v3r4Windows

CONFIGURATION MANAGEMENT

WN11-CC-000197 - Microsoft consumer experiences must be turned off.DISA Microsoft Windows 11 STIG v2r3Windows

CONFIGURATION MANAGEMENT

ZEBR-11-003900 - Zebra Android 11 must be configured to not allow backup of all applications and configuration data to remote systems.MobileIron - DISA Zebra Android 11 COBO v1r3MDM

ACCESS CONTROL