Item Search

NameAudit NamePluginCategory
1.10.6 Ensure 'logging history severity level' is set to greater than or equal to '5'CIS Cisco Firewall v8.x L1 v4.2.0Cisco

AUDIT AND ACCOUNTABILITY

3.2.4 Ensure suspicious packets are logged - 'net.ipv4.conf.default.log_martians = 1'CIS Amazon Linux v2.0.0 L1Unix

AUDIT AND ACCOUNTABILITY

3.3 Configure Security Auditing Flags - 'audit successful/failed administrative events'CIS Apple OSX 10.11 El Capitan L2 v1.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.3 Ensure events that modify date and time information are collected - auditctl b32 clock_settimeCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.3 Ensure events that modify date and time information are collected - auditctl b64 clock_settimeCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.3 Ensure events that modify date and time information are collected - b32 adjtimexCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify the system's network environment are collected - /etc/issueCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify the system's network environment are collected - auditctl /etc/issueCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.5 Ensure events that modify the system's network environment are collected - auditctl /etc/sysconfig/networkCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.6 Ensure events that modify the system's network environment are collected - issue.netCIS Amazon Linux v2.0.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.7 Ensure login and logout events are collected - auditctl /var/log/tallylogCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.8 Ensure login and logout events are collected - /var/log/lastlogCIS Amazon Linux v2.0.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.8 Ensure session initiation information is collected - /var/log/btmpCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.9 Ensure discretionary access control permission modification events are collected - auditctl b64 xattrCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.9 Ensure session initiation information is collected - wtmpCIS Amazon Linux v2.0.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - chmod/fchmod/fchmodatCIS Amazon Linux v2.0.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.10 Ensure discretionary access control permission modification events are collected - setxattr/lsetxattr/fsetxattr/removexattrCIS Amazon Linux v2.0.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - b64 EPERMCIS Amazon Linux v2.0.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.11 Ensure unsuccessful unauthorized file access attempts are collected - EACCESCIS Amazon Linux v2.0.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.1.13 Ensure file deletion events by users are collected - auditctl b32 deleteCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.13 Ensure file deletion events by users are collected - b64 deleteCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure changes to system administration scope (sudoers) is collected - sudoers.dCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure file deletion events by users are collectedCIS Oracle Linux 6 Server L2 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure file deletion events by users are collected - auditctl b64 unlinkCIS Distribution Independent Linux Workstation L2 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure file deletion events by users are collected - auditctl b64 unlinkCIS Distribution Independent Linux Server L2 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure file deletion events by users are collected - b64CIS CentOS 6 Workstation L2 v2.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.14 Ensure file deletion events by users are collected - b64 unlinkCIS Distribution Independent Linux Workstation L2 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

4.1.16 Ensure kernel module loading and unloading is collected - auditctl init_module, delete_moduleCIS Oracle Linux 7 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure kernel module loading and unloading is collected - b64 init_module/delete_moduleCIS Amazon Linux v2.0.0 L2Unix

AUDIT AND ACCOUNTABILITY

4.2.2.1 Ensure journald is configured to send logs to rsyslogCIS Oracle Linux 7 Server L1 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.12 init.ora - 'Specify redo logging must be successful.'CIS Oracle 9/10 OS Audit L1 v2.01Unix

AUDIT AND ACCOUNTABILITY

7.2 Specify file handler in logging.properties (check if java.util.logging.ConsoleHandler exists inin default)CIS Apache Tomcat 8 L1 v1.0.1Unix

AUDIT AND ACCOUNTABILITY

7.2 Specify file handler in logging.properties (check if java.util.logging.ConsoleHandler logging is enabled in web application)CIS Apache Tomcat 8 L1 v1.0.1Unix

AUDIT AND ACCOUNTABILITY

7.3 Ensure className is set correctly in context.xmlCIS Apache Tomcat 7 L2 v1.1.0 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

8.2 Configure a Logging File Channel - category configCIS BIND DNS v3.0.0 Authoritative Name ServerUnix

AUDIT AND ACCOUNTABILITY

8.2 Configure a Logging File Channel - category dnssecCIS BIND DNS v3.0.0 Authoritative Name ServerUnix

AUDIT AND ACCOUNTABILITY

8.2 Configure a Logging File Channel - category xfer-outCIS BIND DNS v3.0.0 Authoritative Name ServerUnix

AUDIT AND ACCOUNTABILITY

8.2 Configure a Logging File Channel - logging sectionCIS BIND DNS v3.0.0 Authoritative Name ServerUnix

AUDIT AND ACCOUNTABILITY

8.3.1 Centralized Logging and ReportingCIS Fortigate Level 2 v1.0.0FortiGate

AUDIT AND ACCOUNTABILITY

17.3.1 Ensure 'Audit Process Creation' is set to 'Success'CIS Windows 7 Workstation Level 1 + Bitlocker v3.1.0Windows

AUDIT AND ACCOUNTABILITY

17.3.1 Ensure 'Audit Process Creation' is set to 'Success'CIS Microsoft Windows Server 2008 Member Server Level 1 v3.1.0Windows

AUDIT AND ACCOUNTABILITY

17.3.1 Ensure 'Audit Process Creation' is set to 'Success'CIS Microsoft Windows Server 2008 R2 Domain Controller Level 1 v3.1.0Windows

AUDIT AND ACCOUNTABILITY

17.6.1 Ensure 'Audit File Share' is set to 'Success and Failure'CIS Windows 7 Workstation Level 1 + Bitlocker v3.1.0Windows

AUDIT AND ACCOUNTABILITY

17.6.2 Ensure 'Audit Other Object Access Events' is set to 'Success and Failure'CIS Windows 7 Workstation Level 1 + Bitlocker v3.1.0Windows

AUDIT AND ACCOUNTABILITY

17.6.2 Ensure 'Audit Other Object Access Events' is set to 'Success and Failure'CIS Windows 7 Workstation Level 1 v3.1.0Windows

AUDIT AND ACCOUNTABILITY

BSI-100-2: S 4.106: Activation of system logging: /etc/rsyslog.conf - *.err;kern.warning;auth.err;daemon.errBSI-100-2 Red Hat Linux 2005Unix

AUDIT AND ACCOUNTABILITY

BSI-100-2: S 4.344: Monitoring of Windows Vista, Windows 7 and Windows Server 2008 systems: Audit account management (Success, Failure)BSI-100-2 Windows 2005Windows

AUDIT AND ACCOUNTABILITY

BSI-100-2: S 4.344: Monitoring of Windows Vista, Windows 7 and Windows Server 2008 systems: Audit policy change (Success, Failure)BSI-100-2 Windows 2005Windows

AUDIT AND ACCOUNTABILITY

BSI-100-2: S 4.344: Monitoring of Windows Vista, Windows 7 and Windows Server 2008 systems: Audit privilege use (Failure)BSI-100-2 Windows 2005Windows

AUDIT AND ACCOUNTABILITY

BSI-100-2: S 4.344: Monitoring of Windows Vista, Windows 7 and Windows Server 2008 systems: Audit process tracking (No auditing)BSI-100-2 Windows 2005Windows

AUDIT AND ACCOUNTABILITY