+ All Categories
Home > Documents > CIS MS Windows Server 2008 R2 MS V2.1.0

CIS MS Windows Server 2008 R2 MS V2.1.0

Date post: 09-Mar-2016
Category:
Upload: berrezeg-mahieddine
View: 244 times
Download: 1 times
Share this document with a friend
Description:
benchmark cis

of 65

Transcript
  • CIS MS Windows Server2008 R2 MS V2.1.0November 3, 2014 at 1:47pm EST

    [michaelwillison]RESEARCHConfidential: The following report contains confidential information. Do not distribute,email, fax, or transfer via any electronic mechanism unless it has been approved by therecipient company's security policy. All copies and backups of this document should besaved on protected storage at all times. Do not share any of the information containedwithin this report with anyone unless they are authorized to view the information. Violatingany of the previous instructions is grounds for termination.

  • Table of Contents

    CIS MS Windows Server 2008 R2 MS V2.1.0 i

    Table of ContentsAbout This Report ................................................................................................................................................................................................1

    Chapter 1 ............................................................................................................................................................................................................................21.1 - Data CIS_MS_Windows_Server_2008_R2_MS_V2.1.0 .............................................................................................................................................. 21.2 - Data CIS_MS_Windows_Server_2008_R2_MS_V2.1.0 ...........................................................................................................................................48

  • About This Report

    CIS MS Windows Server 2008 R2 MS V2.1.0 1

    About This ReportThis report is a template used for reporting on the results from CIS compliance scans with theCIS_MS_Windows_Server_2008_R2_MS_V2.1.0 audit file. The Center for Internet Security is an organizationthat works with end users, vendors, and auditors to develop a set of 'best practice' security standards forconfiguring operating systems and applications. These 'best practices' are known as 'CIS Benchmarks'.

    Tenable Network Security is a CIS member and has submitted several audit policies for certification againstspecific benchmarks. The policies included in CIS_MS_Windows_Server_2008_R2_MS_V2.1.0 have beenapproved and have been certified by CIS staff members. Tenable has submitted example positive andnegative test cases for each of the unique test criteria for CIS_MS_Windows_Server_2008_R2_MS_V2.1.0benchmarks.

    The CIS_MS_Windows_Server_2008_R2_MS_V2.1.0 CIS audit file contains a description of how toperform the scan. When performing managed scans with SecurityCenter, some CIS audits requireadditional patch audits and vulnerability checks. Any additional requirements for completing an audit withCIS_MS_Windows_Server_2008_R2_MS_V2.1.0 are included with the audit file description text. In somecases, multiple scans may be required to be performed.

    When performing audit scans with SecurityCenter, the CIS_MS_Windows_Server_2008_R2_MS_V2.1.0must first be uploaded to SecurityCenter. Next, the appropriate credentials must be added, afterwhich a scan policy can be created. Finally, a scan can be scheduled. As part of the post scan jobs,the 'Auto-Run Reports' can be enabled automatically, running this report on the data collected for theCIS_MS_Windows_Server_2008_R2_MS_V2.1.0.

    If there are several audit scans and the auditor would like the data in a single report forCIS_MS_Windows_Server_2008_R2_MS_V2.1.0, then editing the report template is required. When editingthe report template, first go to Reports and select the CIS_MS_Windows_Server_2008_R2_MS_V2.1.0 report,then click on the 'Edit' button. Navigate to the definition, and select 'Find / Update' link in the top center of thescreen.

    In the top search filter, select 'Audit File' and 'is not set', then click 'Save'. The filter will then move to justbelow the 'Add Filter' link. Next, under 'Update Actions', select 'Audit File' and select 'is set to'. A new box willappear with a drop-down list, select the CIS_MS_Windows_Server_2008_R2_MS_V2.1.0 and click 'Save'.Note that the results will be displayed in the windows on the bottom. Click the 'Update' button just above theresults box. The screen will update with a specified number of filters updated. Now you can close the windowand submit the report. Next, launch the report. This report sometimes can take a while depending on thelength of the CIS_MS_Windows_Server_2008_R2_MS_V2.1.0 and the number of systems checked.

    This .audit is designed to query the MS Windows Server 2008 R2 OS as defined by CIS in theCIS_Microsoft_Windows_Server_2008_R2_Benchmark_v2.1.0.pdf https://benchmarks.cisecurity.org/tools2/windows/CIS_Microsoft_Windows_Server_2008_R2_Benchmark_v2.1.0.pdf

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 2

    Chapter 1

    1.1 - Data CIS_MS_Windows_Server_2008_R2_MS_V2.1.0

    Section Matrix Summary

    System Count Passed Manual Failed7 Days 22 26 5 16

    14 Days 0 0 0 0

    21 Days 0 0 0 0

    28 Days 3 11 0 3

    > 29 Days 16 119 38 15

    Compliance By Subnet (Top 10)

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 3

    Failed Check Summary

    Plugin Name Severity Total1.12.13 Increase the entropy in session identifiers High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.12.12 Force SSL for all applications High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.12.9 Do not allow custom header status messages High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.12.8 Do not allow additional path delimiters (verify ALLOW_ENCODED_SLASH is set to false) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.12.8 Do not allow additional path delimiters (verify ALLOW_BACKSLASH isset to false) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.11.3 Disable deploy on startup applications High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.11.2 Disabling auto deployment of applications High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.12.7 Turn off session facade recycling High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.12.6 Enable strict servlet Compliance High 1

    Hosts in Repository 'net_10_31_112':

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 4

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.12.4 Force SSL when accessing the manager application High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.11.1 Starting Tomcat with Security Manager High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.1.27 Default account passwords - 'Change the default password for 'XDB' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.26 Default account passwords - 'Change the default password for'WMSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.25 Default account passwords - 'Change the default password for'WKSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.23 Default account passwords - 'Change the default password for 'WK_TEST' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.22 Default account passwords - 'Change the default password for'SYSTEM' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.20 Default account passwords - 'Change the default password for'SPATIAL_WFS_ADMIN_USR' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 5

    Plugin Name Severity Total1.1.19 Default account passwords - 'Change the default password for'SPATIAL_CSW_ADMIN_USR' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.18 Default account passwords - 'Change the default password for 'SI_INFORMTN_SCHEMA' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.17 Default account passwords - 'Change the default password for'OWBSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.16 Default account passwords - 'Change the default password for'OWBSYS_AUDIT' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.15 Default account passwords - 'Change the default password for'OUTLN' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.14 Default account passwords - 'Change the default password for'ORDSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.13 Default account passwords - 'Change the default password for'ORDPLUGINS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.12 Default account passwords - 'Change the default password for'ORDDATA' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 6

    Plugin Name Severity Total1.1.11 Default account passwords - 'Change the default password for'ORACLE_OCM' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.10 Default account passwords - 'Change the default password forOLAPSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.8 Default account passwords - 'Change the default password for MDSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.7 Default account passwords - 'Change the default password forMDDATA' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.6 Default account passwords - 'Change the default password forEXFSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.5 Default account passwords - 'Change the default password for DIP' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.3 Default account passwords - 'Change the default password forCTXSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.2 Default account passwords - 'Change the default password forAPPQOSSYS' High 1

    Hosts in Repository 'net_172_26_22':

    172.26.22.127

    Plugin Name Severity Total1.1.2.4 Require Timeout for Login Sessions - 'console timeout < 10' High 1

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 7

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.2.4 Require Timeout for Login Sessions - 'ssh timeout < 10' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.5.4 Require Authorized Read SNMP Community Strings and AccessControl - 'snmp-server host' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.5.4 Require Authorized Read SNMP Community Strings and AccessControl - 'snmp-server community' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.5.3 Require SNMP Trap Server When SNMP is Used - 'snmp-server host' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.5.2 Forbid SNMP Traps High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.5.1 Forbid SNMP Read Access High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.3.4 Require ASDM Banner High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.3.3 Require MOTD Banner High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.3.2 Require Login Banner High 1

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 8

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.3.1 Require EXEC Banner High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.2.5 Require SSH Access Control High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.2.2 Require ASDM Management Access Control High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.1.5 Require AAA Accounting (aaa accounting command privilege) High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.1.4 Require AAA Command Authorization - 'aaa authorization command tacacs+_server_group local' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.1.4 Require AAA Command Authorization - 'aaa authorization command local' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.1.4 Require AAA Command Authorization - 'aaa authorization execauthentication-server' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.1.3 Require Defined AAA Servers and Protocols - 'aaa-server timeout' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.1.3 Require Defined AAA Servers and Protocols - 'aaa-server host' High 1

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 9

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.1.2 Require AAA Authentication for Console and Other InteractiveManagement Protocols - 'Secure-http-client' High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.5.6 Require AES128 or better encryption for SNMPv3 Access High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.5.5 Require Group for SNMPv3 Access High 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

    Plugin Name Severity Total1.1.5.11 Require AES128 or Better Encryption for SNMPv3 Access - 'All SNMPusers > AES 128 encryption' High 2

    Hosts in Repository 'net_10_31_102':

    10.31.102.250 - MAC Address: a4:0c:c3:74:68:40 DNS Name: c2960.net.melcara.int10.31.102.253 - MAC Address: a8:b1:d4:f4:8f:c0 DNS Name: vlan102-core.net.melcara.int

    Plugin Name Severity Total1.1.3 Installing Apache High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.17 Logging. (/etc/logrotate.d/httpd) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.17 Logging. (CustomLog) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.17 Logging. (ErrorLog) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.17 Logging. (LogLevel) High 1

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 10

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.16 Software Information Leakage Protection. (ErrorDocument 500 /custom500.html) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.16 Software Information Leakage Protection. (ErrorDocument 405 /custom405.html) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.16 Software Information Leakage Protection. (ErrorDocument 404 /custom404.html) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.16 Software Information Leakage Protection. (ErrorDocument 403 /custom403.html) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.16 Software Information Leakage Protection. (ErrorDocument 401 /custom401.html) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.16 Software Information Leakage Protection. (ErrorDocument 400 /custom400.html) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.16 Software Information Leakage Protection. (ServerSignature Off) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.16 Software Information Leakage Protection. (ServerTokens Prod) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 11

    Plugin Name Severity Total1.15 Implementing Mod_SSL. (/usr/local/apache2/conf/httpd.conf 'SSLProtocol all -SSLv2') High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.14 Buffer Overflow Protection Tuning. (LimitRequestLine) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.14 Buffer Overflow Protection Tuning. (LimitRequestFieldSize) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.14 Buffer Overflow Protection Tuning. (LimitRequestFields) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.14 Buffer Overflow Protection Tuning. (LimitRequestBody) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.13 Denial of Service Prevention Tuning. (AcceptFilter https) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.13 Denial of Service Prevention Tuning. (AcceptFilter http) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.13 Denial of Service Prevention Tuning. (KeepAliveTimeout) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.13 Denial of Service Prevention Tuning. (KeepAlive) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 12

    Plugin Name Severity Total1.13 Denial of Service Prevention Tuning. (Timeout) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.12 Restrict File Extensions. High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.11 Restrict HTTP Protocol Version. (RewriteRUle) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.11 Restrict HTTP Protocol Version. (RewriteCond) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.11 Restrict HTTP Protocol Version. (RewriteEngine) High 1

    Hosts in Repository 'net_10_31_112':

    10.31.112.10 - MAC Address: 00:0c:29:43:f9:3b

    Plugin Name Severity Total1.1.1 Enforce password history (>=24) High 7

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.1.3 Minimum password age (>=1) High 7

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.1.4 Minimum password length (>=8) High 8

    Hosts in Repository 'net_172_26_23':

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 13

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.1 Use the Latest OS Release - Check if Solaris 10 10/09 release is installed High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.98 - MAC Address: 00:50:56:bd:69:2c DNS Name: solaris9.target.tenablesecurity.com

    Plugin Name Severity Total1.1 Establish firewall configuration standards (inetd_enable) High 2

    Hosts in Repository 'net_172_26_48':

    172.26.48.94 - MAC Address: 00:50:56:bd:6a:81 DNS Name: wsus.adsitarget.tenablesecurity.com172.26.48.96 - MAC Address: 00:50:56:bd:4f:12

    Plugin Name Severity Total1.12.14 Require trusted path for credential entry = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.13 Enumerate administrator accounts on elevation = Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.11 RPC Endpoint Mapper Client Authentication = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.10 Restrictions for Unauthenticated RPC Clients = Enabled and Authenticated High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.9 Solicited Remote Assistance = Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.8 Offer Remote Assistance = Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 14

    Plugin Name Severity Total1.12.6 Do not process the run once list = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.5 Do not process the legacy run list = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.4 Turn off Data Execution Prevention for Explorer = Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.3 Allow Remote Shell Access = Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.2 Require a Password When a Computer Wakes (Plugged In) = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.1 Require a Password When a Computer Wakes (On Battery) = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.11.7 Turn off Windows Update device driver searching = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.10.3 Do not allow drive redirection = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.10.2 Set client connection encryption level = Enabled to High Level High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.10.1 Always prompt client for password upon connection = Enabled High 1

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 15

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.3 Minimum Password Age: Minimum of 1 day High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.1 Enforce Password History: minimum of 24 passwords High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.14 Require trusted path for credential entry: Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.13 Enumerate administrator accounts on elevation: Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.11 RPC Endpoint Mapper Client Authentication: Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.10 Restrictions for Unauthenticated RPC Clients: Enabled and Authenticated High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.9 Solicited Remote Assistance: Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.8 Offer Remote Assistance: Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.6 Do not process the run once list: Enabled High 1

    Hosts in Repository 'net_172_26_48':

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 16

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.5 Do not process the legacy run list: Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.3 Allow Remote Shell Access: Disabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.11.7 Turn off Windows Update device driver searching: Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.10.3 Do not allow drive redirection: Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.4 Minimum Password Length: Minimum of 12 characters High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.4 Minimum Password Length: at least 8 characters High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.3 Minimum Password Age: at least 1 day High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.1 Enforce Password History: at least 24 passwords remembered High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.7 Registry policy processing High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 17

    Plugin Name Severity Total1.13.9 Screen Saver timeout = at most 900 seconds High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.13.8 Force specific screen saver = scrnsave.scr High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.13.7 Password protect the screen saver = Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.5 Password Must Meet Complexity Requirements: Enabled High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.4 Minimum Password Length: 8 characters High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.3 Minimum Password Age: 1 day High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.1.1 Enforce Password History: 24 passwords High 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.12.11 Disable remote Desktop Sharing High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.10 Require trusted path for credential entry High 8

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 18

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.8 Turn off Autoplay High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.7 RPC Endpoint Mapper Client Authentication High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.6 Restrictions for Unauthenticated RPC clients High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.5 Solicited Remote Assistance High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 19

    Plugin Name Severity Total1.12.4 Offer Remote Assistance High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.2 Do not process the run once list High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.1 Do not process the legacy run list High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.11.7 Turn off Windows Update device driver searching High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.11.6 Turn off the Windows Messenger Customer Experience ImprovementProgram High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 20

    172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.11.5 Turn off Search Companion content file updates High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.11.4 Turn off printing over HTTP High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.11.3 Turn off Internet download for Web publishing and online orderingwizards High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.11.2 Turn off the 'Publish to Web' task for files and folders High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.11.1 Turn off downloading of print drivers over HTTP High 8

    Hosts in Repository 'net_172_26_23':

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 21

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.10.4 Do not allow passwords to be saved High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.10.2 Set client connection encryption level High 9

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.10.1 Always prompt client for password upon connection High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.3 Registry policy processing (NoBackgroundPolicy) High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 22

    172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.12.3 Registry policy processing (NoGPOListChanges) High 8

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.84 - MAC Address: 00:50:56:bd:46:04 DNS Name: winsevm.lab.tenable NetBIOS Name: FM\SQL08172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.1.5 Password must meet complexity requirements High 7

    Hosts in Repository 'net_172_26_23':

    172.26.23.13 - MAC Address: 00:50:56:bd:76:73 DNS Name: wsus.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\WSUS172.26.23.27 - MAC Address: 00:50:56:bd:76:61 DNS Name: s11c.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S11C172.26.23.33 - MAC Address: 00:50:56:bd:76:3d DNS Name: s3d.lab.tenablesecurity.com NetBIOS Name: WORKGROUP\S3D172.26.23.47 - DNS Name: winsevm.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\WINSEVM172.26.23.58 - MAC Address: 00:50:56:bd:61:43172.26.23.73 - DNS Name: s7d.lab.tenablesecurity.com NetBIOS Name: UNKNOWN\S7D172.26.23.107 - NetBIOS Name: UNKNOWN\WINSEVM

    Plugin Name Severity Total1.1.24 Disable Mounting of udf Filesystems - '/etc/modprobe.d/CIS - install udf /bin/true' High 9

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.23 Disable Mounting of squashfs Filesystems - '/etc/modprobe.d/CIS - install squashfs /bin/true' High 9

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.22 Disable Mounting of hfsplus Filesystems - '/etc/modprobe.d/CIS - install hfsplus /bin/true' High 9

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 23

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.21 Disable Mounting of hfs Filesystems - '/etc/modprobe.d/CIS - install hfs /bin/true' High 9

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.20 Disable Mounting of jffs2 Filesystems - '/etc/modprobe.d/CIS - install jffs2 /bin/true' High 9

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.19 Disable Mounting of freevxfs Filesystems - '/etc/modprobe.d/CIS - install freevxfs /bin/true' High 9

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.18 Disable Mounting of cramfs Filesystems - '/etc/modprobe.d/CIS - install cramfs /bin/true' High 9

    Hosts in Repository 'net_172_26_48':

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 24

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.23 Disable Mounting of squashfs Filesystems '/etc/modprobe.d/CIS - install squashfs /bin/true' High 2

    Hosts in Repository 'net_172_26_48':

    172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.22 Disable Mounting of hfsplus Filesystems '/etc/modprobe.d/CIS - install hfsplus /bin/true' High 2

    Hosts in Repository 'net_172_26_48':

    172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.21 Disable Mounting of hfs Filesystems '/etc/modprobe.d/CIS - install hfs /bin/true' High 2

    Hosts in Repository 'net_172_26_48':

    172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.20 Disable Mounting of jffs2 Filesystems '/etc/modprobe.d/CIS - install jffs2 /bin/true' High 2

    Hosts in Repository 'net_172_26_48':

    172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.19 Disable Mounting of freevxfs Filesystems '/etc/modprobe.d/CIS - install freevxfs /bin/true' High 2

    Hosts in Repository 'net_172_26_48':

    172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com

    Plugin Name Severity Total1.1.18 Disable Mounting of cramfs Filesystems '/etc/modprobe.d/CIS - install cramfs /bin/true' High 2

    Hosts in Repository 'net_172_26_48':

    172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 25

    Plugin Name Severity Total1.1.24 Disable Mounting of udf Filesystems - '/etc/modprobe.d/CIS.conf - install udf /bin/true' High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.34 - MAC Address: 00:50:56:be:27:eb DNS Name: fedora10.target.tenablesecurity.com172.26.48.35 - MAC Address: 00:50:56:be:27:ff DNS Name: fedora11.target.tenablesecurity.com172.26.48.37 - MAC Address: 00:50:56:be:28:15 DNS Name: fedora15.target.tenablesecurity.com172.26.48.38 - MAC Address: 00:50:56:be:28:16 DNS Name: fedora16.target.tenablesecurity.com172.26.48.39 - MAC Address: 00:50:56:be:28:18 DNS Name: fedora17.target.tenablesecurity.com

    Plugin Name Severity Total1.1.23 Disable Mounting of squashfs Filesystems - '/etc/modprobe.d/CIS.conf- install squashfs /bin/true' High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.34 - MAC Address: 00:50:56:be:27:eb DNS Name: fedora10.target.tenablesecurity.com172.26.48.35 - MAC Address: 00:50:56:be:27:ff DNS Name: fedora11.target.tenablesecurity.com172.26.48.37 - MAC Address: 00:50:56:be:28:15 DNS Name: fedora15.target.tenablesecurity.com172.26.48.38 - MAC Address: 00:50:56:be:28:16 DNS Name: fedora16.target.tenablesecurity.com172.26.48.39 - MAC Address: 00:50:56:be:28:18 DNS Name: fedora17.target.tenablesecurity.com

    Plugin Name Severity Total1.1.22 Disable Mounting of hfsplus Filesystems - '/etc/modprobe.d/CIS.conf - install hfsplus /bin/true' High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.34 - MAC Address: 00:50:56:be:27:eb DNS Name: fedora10.target.tenablesecurity.com172.26.48.35 - MAC Address: 00:50:56:be:27:ff DNS Name: fedora11.target.tenablesecurity.com172.26.48.37 - MAC Address: 00:50:56:be:28:15 DNS Name: fedora15.target.tenablesecurity.com172.26.48.38 - MAC Address: 00:50:56:be:28:16 DNS Name: fedora16.target.tenablesecurity.com172.26.48.39 - MAC Address: 00:50:56:be:28:18 DNS Name: fedora17.target.tenablesecurity.com

    Plugin Name Severity Total1.1.21 Disable Mounting of hfs Filesystems - '/etc/modprobe.d/CIS.conf - install hfs /bin/true' High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.34 - MAC Address: 00:50:56:be:27:eb DNS Name: fedora10.target.tenablesecurity.com172.26.48.35 - MAC Address: 00:50:56:be:27:ff DNS Name: fedora11.target.tenablesecurity.com172.26.48.37 - MAC Address: 00:50:56:be:28:15 DNS Name: fedora15.target.tenablesecurity.com172.26.48.38 - MAC Address: 00:50:56:be:28:16 DNS Name: fedora16.target.tenablesecurity.com172.26.48.39 - MAC Address: 00:50:56:be:28:18 DNS Name: fedora17.target.tenablesecurity.com

    Plugin Name Severity Total1.1.20 Disable Mounting of jffs2 Filesystems - '/etc/modprobe.d/CIS.conf - install jffs2 /bin/true' High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.34 - MAC Address: 00:50:56:be:27:eb DNS Name: fedora10.target.tenablesecurity.com172.26.48.35 - MAC Address: 00:50:56:be:27:ff DNS Name: fedora11.target.tenablesecurity.com172.26.48.37 - MAC Address: 00:50:56:be:28:15 DNS Name: fedora15.target.tenablesecurity.com172.26.48.38 - MAC Address: 00:50:56:be:28:16 DNS Name: fedora16.target.tenablesecurity.com172.26.48.39 - MAC Address: 00:50:56:be:28:18 DNS Name: fedora17.target.tenablesecurity.com

    Plugin Name Severity Total1.1.19 Disable Mounting of freevxfs Filesystems - '/etc/modprobe.d/CIS.conf - install freevxfs /bin/true' High 5

    Hosts in Repository 'net_172_26_48':

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 26

    172.26.48.34 - MAC Address: 00:50:56:be:27:eb DNS Name: fedora10.target.tenablesecurity.com172.26.48.35 - MAC Address: 00:50:56:be:27:ff DNS Name: fedora11.target.tenablesecurity.com172.26.48.37 - MAC Address: 00:50:56:be:28:15 DNS Name: fedora15.target.tenablesecurity.com172.26.48.38 - MAC Address: 00:50:56:be:28:16 DNS Name: fedora16.target.tenablesecurity.com172.26.48.39 - MAC Address: 00:50:56:be:28:18 DNS Name: fedora17.target.tenablesecurity.com

    Plugin Name Severity Total1.1.18 Disable Mounting of cramfs Filesystems - '/etc/modprobe.d/CIS.conf - install cramfs /bin/true' High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.34 - MAC Address: 00:50:56:be:27:eb DNS Name: fedora10.target.tenablesecurity.com172.26.48.35 - MAC Address: 00:50:56:be:27:ff DNS Name: fedora11.target.tenablesecurity.com172.26.48.37 - MAC Address: 00:50:56:be:28:15 DNS Name: fedora15.target.tenablesecurity.com172.26.48.38 - MAC Address: 00:50:56:be:28:16 DNS Name: fedora16.target.tenablesecurity.com172.26.48.39 - MAC Address: 00:50:56:be:28:18 DNS Name: fedora17.target.tenablesecurity.com

    Plugin Name Severity Total1.1.24 Disable Mounting of udf Filesystems High 4

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.23 Disable Mounting of squashfs Filesystems High 4

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.22 Disable Mounting of hfsplus Filesystems High 4

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.21 Disable Mounting of hfs Filesystems High 4

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.20 Disable Mounting of jffs2 Filesystems High 4

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.78

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 27

    172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.19 Disable Mounting of freevxfs Filesystems High 4

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.18 Disable Mounting of cramfs Filesystems High 4

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.17 Set Sticky Bit on All World-Writable Directories High 3

    Hosts in Repository 'net_172_26_48':

    172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.16 Add noexec Option to /dev/shm Partition High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.15 Add nosuid Option to /dev/shm Partition High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 28

    172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.14 Add nodev Option to /dev/shm Partition High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.13 Add nosuid Option to Removable Media Partitions High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com

    Plugin Name Severity Total1.1.12 Add noexec Option to Removable Media Partitions High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com

    Plugin Name Severity Total1.1.11 Add nodev Option to Removable Media Partitions High 5

    Hosts in Repository 'net_172_26_48':

    172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com

    Plugin Name Severity Total1.1.10 Add nodev Option to /home High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 29

    172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.9 Create Separate Partition for /home High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.8 Create Separate Partition for /var/log/audit High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.7 Create Separate Partition for /var/log High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 30

    Plugin Name Severity Total1.1.6 Bind Mount the /var/tmp directory to /tmp High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.5 Create Separate Partition for /var High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.4 Set noexec option for /tmp Partition High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.3 Set nosuid option for /tmp Partition High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 31

    172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.2 Set nodev option for /tmp Partition High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Plugin Name Severity Total1.1.1 - Create Separate Partition for /tmp High 13

    Hosts in Repository 'net_172_26_48':

    172.26.48.24 - DNS Name: centos6.target.tenablesecurity.com172.26.48.25 - DNS Name: centos6x64.target.tenablesecurity.com172.26.48.45 - MAC Address: 00:50:56:be:27:e0 DNS Name: rhel3.target.tenablesecurity.com172.26.48.46 - MAC Address: 00:50:56:be:27:e3 DNS Name: rhel4.target.tenablesecurity.com172.26.48.47 - MAC Address: 00:50:56:be:27:d8 DNS Name: lce.target.tenablesecurity.com172.26.48.48 - MAC Address: 00:50:56:be:27:d5 DNS Name: pvs.target.tenablesecurity.com172.26.48.49 - MAC Address: 00:50:56:be:27:d9 DNS Name: securitycenter.target.tenablesecurity.com172.26.48.50 - MAC Address: 00:50:56:be:27:f4 DNS Name: rhel5x86.target.tenablesecurity.com172.26.48.51 - MAC Address: 00:50:56:be:27:ee DNS Name: rhel5x64.target.tenablesecurity.com172.26.48.52 - MAC Address: 00:50:56:be:27:e5 DNS Name: rhel6x86.target.tenablesecurity.com172.26.48.53 - DNS Name: rhel6x64.target.tenablesecurity.com172.26.48.78172.26.48.79 - MAC Address: 00:50:56:bd:28:3e DNS Name: webapp1.target.tenablesecurity.com

    Manual Check Required Summary

    Plugin Name Severity Total1.1 Require Current Software - 'show version' Medium 1

    Hosts in Repository 'net_172.26.0':

    172.26.0.17 - MAC Address: 00:24:dc:0e:3b:88

    Plugin Name Severity Total1.1.1.4 Require AAA Command Authorization - 'List All Commands' Medium 1

    Hosts in Repository 'net_10_31_254':

    10.31.254.254 - DNS Name: asa-inside.net.melcara.int

  • Chapter 1

    CIS MS Windows Server 2008 R2 MS V2.1.0 32

    Plugin Name Severity Total1.1 Use the Latest Package Updates Medium 3

    Hosts in Repository 'net_172_26_48':

    172.26.48.98 - MAC Address: 00:50:56:bd:69:2c DNS Name: solaris9.target.tenablesecurity.com172.26.48.99 - MAC Address: 0:50:56:bd:7a:18 DNS Name: solaris10.target.tenablesecurity.com172.26.48.100 - MAC Address: 0:50:56:bd:23:c7 DNS Name: solaris11.target.tenablesecurity.com

    Plugin Name Severity Total1.1.2 Do not connect to the Internet when setting up a Mac Medium 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.86 - MAC Address: 00:50:56:bd:74:b5 DNS Name: osx108.target.tenablesecurity.com NetBIOS Name: UNKNOWN\OSX108

    Plugin Name Severity Total1.1.1 Securely erase the Mac OS X partition before installation Medium 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.86 - MAC Address: 00:50:56:bd:74:b5 DNS Name: osx108.target.tenablesecurity.com NetBIOS Name: UNKNOWN\OSX108

    Plugin Name Severity Total1.13.3 Notify antivirus programs when opening attachments = Enabled Medium 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS Name: TARGET\WIN7X64

    Plugin Name Severity Total1.13.2 Hide mechanisms to remove zone information = Enabled Medium 1

    Hosts in Repository 'net_172_26_48':

    172.26.48.75 - MAC Address: 00:50:56:be:27:da DNS Name: win7x64.target.tenablesecurity.com NetBIOS N


Recommended