Item Search

NameAudit NamePluginCategory
1.1.2.1 Ensure /tmp is a separate partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.2 Ensure nodev option set on /tmp partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.2.3 Ensure nosuid option set on /dev/shm partitionCIS Debian Linux 12 v1.1.0 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.2.4 Ensure noexec option set on /dev/shm partitionCIS Debian Linux 12 v1.1.0 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.3 Ensure noexec option set on /tmp partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.3.2 Ensure nodev option set on /home partitionCIS Debian Linux 12 v1.1.0 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.4 Ensure nosuid option set on /tmp partitionCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.6.4 Ensure noexec option set on /var/log partitionCIS Debian Linux 12 v1.1.0 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.2.7.4 Ensure noexec option set on /var/log/audit partitionCIS Debian Linux 12 v1.1.0 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

1.1.3.2 Ensure nodev option set on /var partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.3.3 Ensure nosuid option set on /var partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.4.1 Ensure separate partition exists for /var/tmpCIS Debian 10 Server L2 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.4.3 Ensure noexec option set on /var/tmp partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.4.4 Ensure nosuid option set on /var/tmp partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.5.3 Ensure noexec option set on /var/log partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.5.4 Ensure nosuid option set on /var/log partitionCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.6.4 Ensure nosuid option set on /var/log/audit partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.7.2 Ensure nodev option set on /home partitionCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.1.7.3 Ensure nosuid option set on /home partitionCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.3.1.2 Ensure AppArmor is enabled in the bootloader configurationCIS Debian Linux 12 v1.1.0 L1 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

1.6.1.2 Ensure AppArmor is enabled in the bootloader configurationCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.6.1.3 Ensure all AppArmor Profiles are in enforce or complain modeCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

1.7.5 Ensure permissions on /etc/issue are configuredCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

3.2 Ensure that docker.service file permissions are appropriately setCIS Docker v1.6.0 L2 Docker LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

3.6 Ensure that /etc/docker directory permissions are set to 755 or more restrictivelyCIS Docker v1.6.0 L1 Docker LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

3.6 Ensure that /etc/docker directory permissions are set to 755 or more restrictivelyCIS Docker v1.6.0 L2 Docker LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

3.7.2.7 /etc/passwdCIS IBM AIX 7.1 L1 v2.1.0Unix

ACCESS CONTROL, MEDIA PROTECTION

3.7.2.9 /etc/ssh/sshd_configCIS IBM AIX 7.1 L1 v2.1.0Unix

ACCESS CONTROL, MEDIA PROTECTION

3.16 Ensure that the Docker socket file permissions are set to 660 or more restrictivelyCIS Docker v1.6.0 L1 Docker LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

3.16 Ensure that the Docker socket file permissions are set to 660 or more restrictivelyCIS Docker v1.6.0 L2 Docker LinuxUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.2 Ensure permissions on /etc/crontab are configuredCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.1.5 Ensure permissions on /etc/cron.weekly are configuredCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.1.6 Ensure permissions on /etc/cron.monthly are configuredCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.1.8 Ensure cron is restricted to authorized usersCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.1.9 Ensure at is restricted to authorized usersCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.2.1 Ensure permissions on /etc/ssh/sshd_config are configuredCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.2.2 Ensure permissions on SSH private host key files are configuredCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.2.4 Ensure SSH access is limitedCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.2.4 Ensure SSH access is limitedCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.3.7 Ensure access to the su command is restrictedCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.5.2 Ensure system accounts are securedCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.5.3 Ensure default group for the root account is GID 0CIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

5.2.4.4 Ensure the audit log directory is 0750 or more restrictiveCIS Debian 10 Workstation L2 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.1.5 Ensure permissions on /etc/shadow are configuredCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.1.9 Ensure permissions on /etc/shells are configuredCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.1.13 Ensure SUID and SGID files are reviewedCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.2.4 Ensure shadow group is emptyCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.2.11 Ensure local interactive user home directories are configuredCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.2.11 Ensure local interactive user home directories are configuredCIS Debian 10 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.2.12 Ensure local interactive user dot files access is configuredCIS Debian 10 Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION