Item Search

NameAudit NamePluginCategory
1.1.3.9.8 Configure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.4.3 Set 'Deny access to this computer from the network' to 'Guests'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.5 Set 'Create permanent shared objects' to 'No One'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.15 Set 'Create symbolic links' to 'Administrators'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.19 Debug programs = AdministratorsCIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.22 Set 'Profile system performance' to 'NT SERVICE\WdiServiceHost,Administrators'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.28 Set 'Manage auditing and security log' to 'Administrators'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.1.4.39 Configure 'Remove computer from docking station'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.2.1.1 Configure 'Set IP Stateless Autoconfiguration Limits State'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.3.1.1 Configure 'Turn off access to the Store'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.3.1.9 Set 'Turn off printing over HTTP' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.3.2.4 Set 'Do not enumerate connected users on domain-joined computers' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

1.2.4.2.1.3 Set 'Configure use of passwords for fixed data drives' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.9 Set 'Allow data recovery agent' to 'True'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.12 Set 'Configure storage of BitLocker recovery information to AD DS:' to 'Backup recovery passwords and key packages'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.14 Set 'Omit recovery options from the BitLocker setup wizard' to 'True'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.16 Set 'Require use of smart cards on fixed data drives' to 'True'CIS Windows 8 L1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.1.17 Configure 'Deny write access to fixed drives not protected by BitLocker'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.1 Set 'Configure use of hardware-based encryption for operating system drives' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.3 Set 'Configure use of passwords for operating system drives' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.4 Set 'Recovery Key' to 'Do not allow 256-bit recovery key'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.8 Set 'Restrict encryption algorithms and cipher suites allowed for hardware-based encryption' to 'False'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.12 Set 'Configure storage of BitLocker recovery information to AD DS:' to 'Store recovery passwords and key packages'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.18 Set 'Configure TPM startup PIN:' to 'Require startup PIN with TPM'CIS Windows 8 L1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.2.28 Set 'Minimum characters:' to 'Enabled:7 or more characters'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.2.4.2.3.9 Set 'Allow data recovery agent' to 'True'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.3.10 Set 'Choose how BitLocker-protected removable drives can be recovered' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.3.13 Set 'Save BitLocker recovery information to AD DS for removable data drives' to 'False'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.2.3.15 Set 'Configure use of smart cards on removable data drives' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.2.4.5.4 Set 'Always prompt for password upon connection' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.2.4.7.8 Set 'No auto-restart with logged on users for scheduled automatic updates installations' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

1.2.4.9 Set 'Turn off Data Execution Prevention for Explorer' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.4.12 Configure 'Allow deployment operations in special profiles'CIS Windows 8 L1 v1.0.0Windows

CONFIGURATION MANAGEMENT

1.2.4.16 Set 'Allow Remote Shell Access' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

2.13 Configure 'Turn off toast notifications on the lock screen'CIS Windows 8 L1 v1.0.0Windows

ACCESS CONTROL

Audit Account LockoutMSCT Windows 11 v24H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Authentication Policy ChangeMSCT Windows 11 v24H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Group MembershipMSCT Windows 11 v22H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Other Object Access EventsMSCT Windows 11 v22H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Other System EventsMSCT Windows 11 v24H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Other System EventsMSCT Windows 11 v22H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Security System ExtensionMSCT Windows 11 v24H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Sensitive Privilege UseMSCT Windows 11 v24H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit System IntegrityMSCT Windows 11 v22H2 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Enumeration policy for external devices incompatible with Kernel DMA ProtectionMSCT Windows 11 v24H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Enumeration policy for external devices incompatible with Kernel DMA ProtectionMSCT Windows 11 v22H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Mandate the maximum version of SMB - LanmanWorkstationMSCT Windows 11 v24H2 v1.0.0Windows
MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS serversMSCT Windows 11 v24H2 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Profile single processMSCT Windows 10 v22H2 v1.0.0Windows

ACCESS CONTROL

Turn on script scanningMSCT Windows 11 v24H2 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY