CSCv7|18

Title

Application Software Security

Reference Item Details

Category: Application Software Security

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2 Ensure 'Host headers' are on all sitesWindowsCIS IIS 10 v1.2.1 Level 1
1.3 Do not use development tools in productionUnixCIS Docker 1.6 v1.0.0 L1 Linux
1.3 Ensure 'Directory browsing' is set to DisabledWindowsCIS IIS 10 v1.2.1 Level 1
1.4 Ensure 'application pool identity' is configured for all application poolsWindowsCIS IIS 10 v1.2.1 Level 1
1.4 Ensure Service Runlevel Is Registered And Set CorrectlyUnixCIS PostgreSQL 9.5 OS v1.1.0
1.4 Ensure Service Runlevel Is Registered And Set CorrectlyUnixCIS PostgreSQL 9.6 OS v1.0.0
1.4 Ensure systemd Service Files Are EnabledUnixCIS PostgreSQL 10 OS v1.0.0
2.1 Ensure 'global authorization rule' is set to restrict accessWindowsCIS IIS 10 v1.2.1 Level 1
2.4 Ensure 'forms authentication' is set to use cookies - ApplicationWindowsCIS IIS 10 v1.2.1 Level 2
2.4 Ensure 'forms authentication' is set to use cookies - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
2.5 Ensure 'cookie protection mode' is configured for forms authentication - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
2.5 Ensure 'cookie protection mode' is configured for forms authentication - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
2.6 Ensure aufs storage driver is not usedUnixCIS Docker v1.7.0 L1 Docker - Linux
2.9 Enable user namespace supportUnixCIS Docker v1.7.0 L2 Docker - Linux
2.10 Ensure the default cgroup usage has been confirmedUnixCIS Docker v1.7.0 L2 Docker - Linux
2.17 Ensure that a daemon-wide custom seccomp profile is applied if appropriateUnixCIS Docker v1.7.0 L2 Docker - Linux
3.1 Ensure 'deployment method retail' is setWindowsCIS IIS 10 v1.2.1 Level 1
3.2 Ensure 'debug' is turned off - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
3.2 Ensure 'debug' is turned off - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
3.3 Ensure custom error messages are not off - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
3.3 Ensure custom error messages are not off - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
3.5 Ensure ASP.NET stack tracing is not enabled - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
3.5 Ensure ASP.NET stack tracing is not enabled - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
3.6 Ensure 'httpcookie' mode is configured for session state - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
3.6 Ensure 'httpcookie' mode is configured for session state - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
3.7 Ensure 'cookies' are set with HttpOnly attribute - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
3.7 Ensure 'cookies' are set with HttpOnly attribute - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
4.1 Ensure 'maxAllowedContentLength' is configured - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
4.1 Ensure 'maxAllowedContentLength' is configured - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
4.2 Ensure 'maxURL request filter' is configured - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
4.2 Ensure 'maxURL request filter' is configured - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
4.3 Ensure 'MaxQueryString request filter' is configured - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
4.3 Ensure 'MaxQueryString request filter' is configured - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
4.4 Ensure non-ASCII characters in URLs are not allowed - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 2
4.4 Ensure non-ASCII characters in URLs are not allowed - DefaultWindowsCIS IIS 10 v1.2.1 Level 2
4.5 Ensure Double-Encoded requests will be rejected - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
4.5 Ensure Double-Encoded requests will be rejected - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
4.6 Ensure 'HTTP Trace Method' is disabled - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
4.6 Ensure 'HTTP Trace Method' is disabled - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
4.7 Ensure Unlisted File Extensions are not allowed - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
4.7 Ensure Unlisted File Extensions are not allowed - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
4.8 Ensure Handler is not granted Write and Script/Execute - ApplicationsWindowsCIS IIS 10 v1.2.1 Level 1
4.8 Ensure Handler is not granted Write and Script/Execute - DefaultWindowsCIS IIS 10 v1.2.1 Level 1
4.9 Ensure 'notListedIsapisAllowed' is set to falseWindowsCIS IIS 10 v1.2.1 Level 1
4.10 Ensure 'notListedCgisAllowed' is set to falseWindowsCIS IIS 10 v1.2.1 Level 1
6.3 Ensure 'Postmaster' Runtime Parameters are ConfiguredPostgreSQLDBCIS PostgreSQL 9.5 DB v1.1.0
6.3 Ensure 'Postmaster' Runtime Parameters are ConfiguredPostgreSQLDBCIS PostgreSQL 9.6 DB v1.0.0
6.3 Ensure 'Postmaster' Runtime Parameters are ConfiguredPostgreSQLDBCIS PostgreSQL 10 DB v1.0.0