Item Search

NameAudit NamePluginCategory
1.1 Remove extraneous files and directories (SERVER_DIR/webapps/host-manager.xml)CIS Apache Tomcat 7 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

1.1 Remove extraneous files and directories (SERVER_DIR/webapps/manager)CIS Apache Tomcat 7 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

1.1 Remove extraneous files and directories (WEBAPP_DIR/webdav)CIS Apache Tomcat 7 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

1.1.1 Ensure 'Cross-origin HTTP Authentication prompts' is set to 'Disabled'CIS Google Chrome L1 v3.0.0Windows

CONFIGURATION MANAGEMENT

1.4 Remove all non-essential services from the host - RPMCIS Docker 1.12.0 v1.0.0 L1 LinuxUnix

CONFIGURATION MANAGEMENT

1.11 Ensure 'Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes' is set to 'Disabled'CIS Google Chrome L1 v3.0.0Windows

CONFIGURATION MANAGEMENT

1.11 Ensure 'Unknown sources' is set to DisabledAirWatch - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

1.13 Ensure 'Smart Lock' is set to DisabledMobileIron - CIS Google Android 7 v1.0.0 L2MDM

CONFIGURATION MANAGEMENT

1.16 Ensure 'Speak passwords' is set to DisabledMobileIron - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

1.26 Ensure 'Add users when device is locked' is set to DisabledAirWatch - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

1.26 Ensure 'Add users when device is locked' is set to DisabledMobileIron - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

1.28 Ensure 'Allow import of data from other browsers on each Microsoft Edge launch' is set to 'Disabled'CIS Microsoft Edge L1 v2.0.0Windows

CONFIGURATION MANAGEMENT

1.100 Ensure 'Enhanced Security Mode configuration for Intranet zone sites' is set to 'Disabled'CIS Microsoft Edge L2 v2.0.0Windows

CONFIGURATION MANAGEMENT

1.116 Ensure 'Spell checking provided by Microsoft Editor' is set to 'Disabled'CIS Microsoft Edge L2 v2.0.0Windows

CONFIGURATION MANAGEMENT

1.117 Ensure 'Standalone Sidebar Enabled' is set to 'Disabled'CIS Microsoft Edge L1 v2.0.0Windows

CONFIGURATION MANAGEMENT

2.3.16.1 (L1) Ensure 'System settings: Optional subsystems' is set to 'Defined: (blank)'CIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.1Windows

CONFIGURATION MANAGEMENT

2.3.16.1 (L1) Ensure 'System settings: Optional subsystems' is set to 'Defined: (blank)'CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

CONFIGURATION MANAGEMENT

2.4 Ensure 'Signed-out search activity' is set to DisabledAirWatch - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

2.4.1 Disable Remote Apple EventsCIS Apple OSX 10.9 L1 v1.3.0Unix

CONFIGURATION MANAGEMENT

2.4.4 Disable Printer SharingCIS Apple OSX 10.9 L1 v1.3.0Unix

CONFIGURATION MANAGEMENT

2.4.7 Disable Bluetooth SharingCIS Apple OSX 10.9 L1 v1.3.0Unix

CONFIGURATION MANAGEMENT

2.5.14.2.2 Ensure 'Do not display 'Publish to GAL' button' is set to 'Enabled'CIS Microsoft Office Enterprise v1.1.0 L1Windows

CONFIGURATION MANAGEMENT

2.8 Ensure 'YouTube Search History' is set to DisabledAirWatch - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

2.9 Ensure 'YouTube Watch History' is set to DisabledMobileIron - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

2.10 Ensure 'Google Location History' is set to DisabledMobileIron - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

2.16 Control the number of manager nodes in a swarmCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

3.2.1.13 Ensure 'Allow trusting new enterprise app authors' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.2.1.14 Ensure 'Allow USB accessories while the device is locked' is set to 'Disabled'AirWatch - CIS Apple iOS 12 v1.0.0 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

4.2.9 Ensure sshd GSSAPIAuthentication is disabledCIS CentOS Linux 7 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

4.2.21 Ensure sshd PermitUserEnvironment is disabledCIS CentOS Linux 7 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

4.7 Do not use update instructions alone in the DockerfileCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.7 Do not use update instructions alone in the DockerfileCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.10 Do not store secrets in DockerfilesCIS Docker 1.13.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

5.3 Verify that containers are running only a single main processCIS Docker 1.6 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

5.29 Do not use Docker's default bridge docker0CIS Docker 1.13.0 v1.0.0 L2 DockerUnix

CONFIGURATION MANAGEMENT

6.2.1 Ensure all forms of mail forwarding are blocked and/or disabledCIS Microsoft 365 Foundations E3 L1 v3.0.0microsoft_azure

CONFIGURATION MANAGEMENT

6.7 Ensure NFS and RPC are not enabled - nfs-kernel-serverCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

6.7 Ensure NFS and RPC are not enabled - rpcbindCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

7.3.2 Ensure OneDrive sync is restricted for unmanaged devicesCIS Microsoft 365 Foundations E3 L2 v3.0.0microsoft_azure

CONFIGURATION MANAGEMENT

9.3 Disable deploy on startup of applicationsCIS Apache Tomcat 7 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

18.10.56.3.3.6 (L2) Ensure 'Do not allow supported Plug and Play device redirection' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

18.10.56.3.3.6 (L2) Ensure 'Do not allow supported Plug and Play device redirection' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v3.0.0 L2Windows

CONFIGURATION MANAGEMENT

18.10.92.2.3 (L1) Ensure 'Enable features introduced via servicing that are off by default' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v3.0.0 L1 + BLWindows

CONFIGURATION MANAGEMENT

19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v3.0.0 L1 + BL + NGWindows

CONFIGURATION MANAGEMENT

19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v3.0.0 L1 NGWindows

CONFIGURATION MANAGEMENT

19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

20.14 (L1) Ensure 'WLAN and WWAN is Disabled in BIOS'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT