Item Search

NameAudit NamePluginCategory
1.1.1.1 Ensure mounting of cramfs filesystems is disabled (lsmod)CIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

1.1.1.2 Ensure mounting of freevxfs filesystems is disabled (lsmod)CIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

1.1.1.2 Ensure mounting of freevxfs filesystems is disabled (modprobe)CIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

1.1.1.4 Ensure mounting of hfs filesystems is disabled - lsmodCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.1.5 Ensure mounting of hfsplus filesystems is disabled (hfsplus)CIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

1.1.1.5 Ensure mounting of hfsplus filesystems is disabled (lsmod)CIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure mounting of squashfs filesystems is disabled - lsmodCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.1.6 Ensure mounting of udf filesystems is disabled (lsmod)CIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

1.1.1.7 Ensure mounting of udf filesystems is disabled - lsmodCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.1.8 Ensure mounting of FAT filesystems is disabled - /etc/modprobe.d/CIS.confCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.1.8 Ensure mounting of FAT filesystems is disabled - lsmodCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.1.2.16 Set 'Audit Policy: System: IPsec Driver' to 'Success and Failure'CIS Windows 8 L1 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

1.1.3.5.5 Set 'Domain member: Digitally encrypt or sign secure channel data (always)' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.3.7.1 Set 'Microsoft network client: Send unencrypted password to third-party SMB servers' to 'Disabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

1.1.3.7.3 Set 'Microsoft network client: Digitally sign communications (if server agrees)' to 'Enabled'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.3.11.2 Set 'Network security: Minimum session security for NTLM SSP based servers' to 'Require NTLMv2 session security'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.1.18 Ensure sticky bit is set on all world-writable directoriesCIS Amazon Linux v2.1.0 L1Unix

ACCESS CONTROL

2.3 Ensure 'Web and App Activity' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.3.11.9 Ensure 'Network security: Minimum session security for NTLM SSP based (including secure RPC) clients' is set to 'Require NTLMv2 session security, Require 128-bit encryption'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.5 Ensure 'Voice & Audio Activity' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.5 Ensure 'Voice & Audio Activity' is set to 'Disabled'AirWatch - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.6 Ensure 'YouTube Search History' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.7 Ensure 'YouTube Watch History' is set to 'Disabled'AirWatch - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.7 Ensure 'YouTube Watch History' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

2.8 Ensure 'Google Location History' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

3.2 Ensure 'Location' is set to 'Enabled'MobileIron - CIS Google Android v1.6.0 L1MDM

ACCESS CONTROL

3.2.1.20 Ensure 'Allow setting up new nearby devices' is set to 'Disabled'MobileIron - CIS Apple iOS 11 v1.0.0 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.3 Ensure 'Allow third-party cookies' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

3.4 Ensure 'Safe Browsing' is set to 'Enabled'AirWatch - CIS Google Android v1.6.0 L1MDM

SYSTEM AND INFORMATION INTEGRITY

3.8 Ensure that On-Premise SharePoint servers is configured without OneDrive redirection linkages.CIS Microsoft SharePoint 2016 OS v1.1.0Windows

CONFIGURATION MANAGEMENT

4.1.13 Ensure successful file system mounts are collected - 'auditctl mounts (64-bit)'CIS Ubuntu Linux 14.04 LTS Workstation L2 v2.1.0Unix

AUDIT AND ACCOUNTABILITY

5.4.5 Ensure default user shell timeout is 900 seconds or less - /etc/bashrcCIS Amazon Linux v2.1.0 L2Unix

ACCESS CONTROL

18.8.22.1.3 Ensure 'Turn off handwriting recognition error reporting' is set to 'Enabled'CIS Windows 7 Workstation Level 2 v3.2.0Windows

SYSTEM AND INFORMATION INTEGRITY

Ensure default user shell timeout is 900 seconds or less - /etc/profileTenable Cisco Firepower Management Center OS Best Practices AuditUnix

ACCESS CONTROL

Ensure mounting of FAT filesystems is disabled - modprobeTenable Cisco Firepower Management Center OS Best Practices AuditUnix

CONFIGURATION MANAGEMENT

Ensure successful file system mounts are collected - auditctl b64Tenable Cisco Firepower Management Center OS Best Practices AuditUnix

AUDIT AND ACCOUNTABILITY

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows 10 v1507 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows 10 v21H2 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows Server 1903 DC v1.19.9Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows Server v2004 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPasswordMSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows 10 v1507 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows 10 v2004 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) clientsMSCT Windows Server v1909 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows 10 v1507 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows Server v1909 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows Server 2016 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Network security: Minimum session security for NTLM SSP based (including secure RPC) serversMSCT Windows Server v20H2 DC v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Store passwords using reversible encryptionMSCT Windows 10 1809 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Store passwords using reversible encryptionMSCT Windows Server 2019 MS v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY