Item Search

NameAudit NamePluginCategory
1.1.5.2.9 Set 'Windows Firewall: Private: Allow unicast response' to 'No'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.6.5 - TCP/IP Tuning - 'ipforwarding = 0'CIS AIX 5.3/6.1 L2 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.6.8 - TCP/IP Tuning - 'directed_broadcast = 0'CIS AIX 5.3/6.1 L2 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.6.9 - TCP/IP Tuning - 'tcp_pmtu_discover = 0'CIS AIX 5.3/6.1 L2 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

1.6.20 - TCP/IP Tuning - 'tcp_mssdflt <= 1448'CIS AIX 5.3/6.1 L2 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.3 Allow Docker to make changes to iptablesCIS Docker 1.12.0 v1.0.0 L1 DockerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

2.6.4 Enable Firewall Stealth ModeCIS Apple OSX 10.9 L1 v1.3.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.6.5 Review Application Firewall RulesCIS Apple OSX 10.9 L1 v1.3.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Ensure source routed packets are not accepted - /etc/sysctl ipv4 all accceptCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Ensure source routed packets are not accepted - /etc/sysctl ipv4 default acceptCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.2 Ensure ICMP redirects are not accepted - /etc/sysctl ipv4 default acceptCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.2 Ensure ICMP redirects are not accepted - sysctl ipv4 all acceptCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.3 Ensure secure ICMP redirects are not accepted - sysctl ipv4 default secureCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.3 Restrict Access to Cache 'trusted, local IP network'CIS ISC BIND 9.0/9.5 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.3 Restrict Access to Cache 'trusted, localnets'CIS ISC BIND 9.0/9.5 v2.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.8 Ensure TCP SYN Cookies is enabled - sysctlCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1 Ensure IPv6 router advertisements are not accepted - sysctl ipv6 default acceptCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.2 Ensure IPv6 redirects are not accepted - /etc/sysctl ipv6 default acceptCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.14 sockthreshCIS IBM AIX 7.1 L1 v2.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.3 Ensure base chains exist - 'hook forward'CIS Red Hat EL8 Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.3 Ensure base chains exist - 'hook input'CIS Red Hat EL8 Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.5 Ensure outbound and established connections are configured - incoming, establishedCIS Red Hat EL8 Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.5 Ensure outbound and established connections are configured - outgoing, establishedCIS Red Hat EL8 Server L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.3.6 Ensure default deny firewall policy - Chain FORWARDCIS Red Hat EL8 Server L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.4.1.1 Ensure default deny firewall policy - Chain OUTPUTCIS Red Hat EL8 Server L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.4.1.2 Ensure loopback traffic is configured - Input drop allCIS Red Hat EL8 Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.4.1.4 Ensure firewall rules exist for all open portsCIS Red Hat EL8 Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.4.2.1 Ensure IPv6 default deny firewall policy - 'Chain INPUT'CIS Red Hat EL8 Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.4.4.2.3 Ensure IPv6 outbound and established connections are configuredCIS Red Hat EL8 Workstation L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.1.5 Ensure default zone is setCIS Oracle Linux 7 Workstation L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.5 Ensure a table existsCIS Oracle Linux 7 Workstation L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.6 Ensure base chains exist - forwardCIS Oracle Linux 7 Server L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.6 Ensure base chains exist - inputCIS Oracle Linux 7 Server L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.7 Ensure loopback traffic is configured - iif loCIS Oracle Linux 7 Server L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.7 Ensure loopback traffic is configured - ip saddrCIS Oracle Linux 7 Server L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.8 Ensure outbound and established connections are configured - inputCIS Oracle Linux 7 Server L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.2.8 Ensure outbound and established connections are configured - outputCIS Oracle Linux 7 Workstation L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.3.3.3 Ensure IPv6 outbound and established connections are configuredCIS Oracle Linux 7 Server L1 v3.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

3.5.6 (L2) Ensure 'MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds' is set to 'Enabled: 300,000 or 5 minutes (recommended)'CIS Microsoft Intune for Windows 10 v3.0.1 L2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.2.5 ipforwardingCIS IBM AIX 7.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.2.10 ipsrcroutesendCIS IBM AIX 7.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.2.13 nonlocsrcrouteCIS IBM AIX 7.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.2.14 sockthreshCIS IBM AIX 7.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.2.15 tcp_pmtu_discoverCIS IBM AIX 7.2 L1 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

7.7 Ensure Firewall is active - iptables-persistent run level 4CIS Debian Linux 7 L1 v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

18.5.2 (L1) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level' is set to 'Enabled: Highest protection, source routing is completely disabled'CIS Microsoft Windows 10 Enterprise v3.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.5.2 (L1) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level' is set to 'Enabled: Highest protection, source routing is completely disabled'CIS Microsoft Windows 11 Enterprise v3.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.5.3 (L1) Ensure 'MSS: (DisableIPSourceRouting) IP source routing protection level' is set to 'Enabled: Highest protection, source routing is completely disabled'CIS Microsoft Windows Server 2022 v3.0.0 L1 Member ServerWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.5.3 (L1) Ensure 'MSS: (DisableIPSourceRouting) IP source routing protection level' is set to 'Enabled: Highest protection, source routing is completely disabled'CIS Microsoft Windows Server 2016 v3.0.0 L1 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.5.5 (L2) Ensure 'MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds' is set to 'Enabled: 300,000 or 5 minutes (recommended)'CIS Microsoft Windows Server 2019 STIG v2.0.0 L2 MSWindows

SYSTEM AND COMMUNICATIONS PROTECTION