Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
98 changes: 49 additions & 49 deletions website/docs/tests/cis/readme.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,52 +18,52 @@ These tests verify tenant and organization configuration against CIS Benchmark r

| Test ID | Title | Severity | Category |
| --- | --- | --- | --- |
| [CIS.GH.1.2.2](../CIS.GH.1.2.2) | (L1) Ensure repository creation is limited to specific members | Medium | CIS GH Level 1 |
| [CIS.GH.1.2.3](../CIS.GH.1.2.3) | (L1) Ensure repository deletion is limited to specific users | High | CIS GH Level 1 |
| [CIS.GH.1.2.4](../CIS.GH.1.2.4) | (L1) Ensure issue deletion is limited to specific users | Medium | CIS GH Level 1 |
| [CIS.GH.1.3.2](../CIS.GH.1.3.2) | (L1) Ensure team creation is limited to specific members | Medium | CIS GH Level 1 |
| [CIS.GH.1.3.8](../CIS.GH.1.3.8) | (L1) Ensure strict base permissions are set for repositories | High | CIS GH Level 1 |
| [CIS.M365.1.1.1](../CIS.M365.1.1.1) | (L1) Ensure Administrative accounts are cloud-only | High | CIS E3 Level 1 |
| [CIS.M365.1.1.3](../CIS.M365.1.1.3) | (L1) Ensure that between two and four global admins are designated | High | CIS E3 Level 1 |
| [CIS.M365.1.2.1](../CIS.M365.1.2.1) | (L2) Ensure that only organizationally managed/approved public groups exist | Medium | CIS E3 Level 2 |
| [CIS.M365.1.2.2](../CIS.M365.1.2.2) | (L1) Ensure sign-in to shared mailboxes is blocked | High | CIS E3 Level 1 |
| [CIS.M365.1.3.1](../CIS.M365.1.3.1) | (L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | High | CIS E3 Level 1 |
| [CIS.M365.1.3.3](../CIS.M365.1.3.3) | (L2) Ensure 'External sharing' of calendars is not available | Medium | CIS E3 Level 2 |
| [CIS.M365.1.3.4](../CIS.M365.1.3.4) | Ensure | Unknown | CIS E3 Level 1 |
| [CIS.M365.1.3.5](../CIS.M365.1.3.5) | Ensure internal phishing protection for Forms is enabled | Unknown | CIS E3 Level 1 |
| [CIS.M365.1.3.6](../CIS.M365.1.3.6) | (L2) Ensure the customer lockbox feature is enabled | High | CIS E5 Level 2 |
| [CIS.M365.1.3.7](../CIS.M365.1.3.7) | Ensure | Unknown | CIS E3 Level 2 |
| [CIS.M365.2.1.1](../CIS.M365.2.1.1) | (L2) Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy) | Medium | CIS E5 Level 2 |
| [CIS.M365.2.1.2](../CIS.M365.2.1.2) | (L1) Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.1.3](../CIS.M365.2.1.3) | (L1) Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.1.4](../CIS.M365.2.1.4) | (L2) Ensure Safe Attachments policy is enabled (Only Checks Default Policy) | High | CIS E5 Level 2 |
| [CIS.M365.2.1.5](../CIS.M365.2.1.5) | (L2) Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled | High | CIS E5 Level 2 |
| [CIS.M365.2.1.6](../CIS.M365.2.1.6) | (L1) Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.1.7](../CIS.M365.2.1.7) | (L1) Ensure that an anti-phishing policy has been created (Only Checks Default Policy) | Medium | CIS E5 Level 1 |
| [CIS.M365.2.1.9](../CIS.M365.2.1.9) | (L1) Ensure that DKIM is enabled for all Exchange Online Domains | High | CIS E3 Level 1 |
| [CIS.M365.2.1.11](../CIS.M365.2.1.11) | (L2) Ensure comprehensive attachment filtering is applied | High | CIS E3 Level 2 |
| [CIS.M365.2.1.12](../CIS.M365.2.1.12) | (L1) Ensure the connection filter IP allow list is not used (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.1.13](../CIS.M365.2.1.13) | (L1) Ensure the connection filter safe list is off (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.4.4](../CIS.M365.2.4.4) | (L1) Ensure Zero-hour auto purge for Microsoft Teams is on (Only Checks ZAP is enabled) | Medium | CIS E5 Level 1 |
| [CIS.M365.3.1.1](../CIS.M365.3.1.1) | (L1) Ensure Microsoft 365 audit log search is Enabled | High | CIS E3 Level 1 |
| [CIS.M365.4.1](../CIS.M365.4.1) | Ensure devices without a compliance policy are marked | Unknown | CIS E3 Level 2 |
| [CIS.M365.5.1.2.2](../CIS.M365.5.1.2.2) | Ensure third party integrated applications are not allowed | Unknown | CIS E3 Level 2 |
| [CIS.M365.5.1.2.3](../CIS.M365.5.1.2.3) | Ensure | Unknown | CIS E3 Level 1 |
| [CIS.M365.5.1.3.1](../CIS.M365.5.1.3.1) | Ensure a dynamic group for guest users is created | Unknown | CIS E3 Level 1 |
| [CIS.M365.5.1.5.1](../CIS.M365.5.1.5.1) | Ensure user consent to apps accessing company data on their behalf is not allowed | Unknown | CIS E3 Level 2 |
| [CIS.M365.5.1.5.2](../CIS.M365.5.1.5.2) | Ensure the admin consent workflow is enabled | Unknown | CIS E3 Level 1 |
| [CIS.M365.5.1.6.2](../CIS.M365.5.1.6.2) | Ensure that guest user access is restricted | Unknown | CIS E3 Level 1 |
| [CIS.M365.5.2.3.5](../CIS.M365.5.2.3.5) | Ensure weak authentication methods are disabled | Unknown | CIS E3 Level 1 |
| [CIS.M365.6.5.3](../CIS.M365.6.5.3) | Ensure additional storage providers are restricted in Outlook on the web | Unknown | CIS E3 Level 2 |
| [CIS.M365.7.2.2](../CIS.M365.7.2.2) | Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | Unknown | SharePoint Online |
| [CIS.M365.7.2.5](../CIS.M365.7.2.5) | Ensure that SharePoint guest users cannot share items they don | Unknown | SharePoint Online |
| [CIS.M365.7.2.7](../CIS.M365.7.2.7) | Ensure link sharing is restricted in SharePoint and OneDrive | Unknown | SharePoint Online |
| [CIS.M365.7.2.9](../CIS.M365.7.2.9) | Ensure guest access to a site or OneDrive will expire automatically | Unknown | SharePoint Online |
| [CIS.M365.7.2.11](../CIS.M365.7.2.11) | Ensure the SharePoint default sharing link permission is set | Unknown | SharePoint Online |
| [CIS.M365.7.3.1](../CIS.M365.7.3.1) | Ensure Office 365 SharePoint infected files are disallowed for download | Unknown | SharePoint Online |
| [CIS.M365.8.1.1](../CIS.M365.8.1.1) | (L2) Ensure external file sharing in Teams is enabled for only approved cloud storage services | Medium | CIS M365 v6.0.1 |
| [CIS.M365.8.2.2](../CIS.M365.8.2.2) | (L1) Ensure communication with unmanaged Teams users is disabled | Medium | CIS M365 v6.0.1 |
| [CIS.M365.8.2.3](../CIS.M365.8.2.3) | Ensure external Teams users cannot initiate conversations | Unknown | CIS M365 v6.0.1 |
| [CIS.M365.8.4.1](../CIS.M365.8.4.1) | (L1) Ensure all or a majority of third-party and custom apps are blocked | High | CIS M365 v6.0.1 |
| [CIS.M365.8.5.3](../CIS.M365.8.5.3) | (L1) Ensure only people in my org can bypass the lobby | Medium | CIS E3 Level 1 |
| [CIS.M365.8.6.1](../CIS.M365.8.6.1) | (L1) Ensure users can report security concerns in Teams to internal destination | Medium | CIS E3 Level 1 |
| [CIS.GH.1.2.2](./CIS.GH.1.2.2.md) | (L1) Ensure repository creation is limited to specific members | Medium | CIS GH Level 1 |
| [CIS.GH.1.2.3](./CIS.GH.1.2.3.md) | (L1) Ensure repository deletion is limited to specific users | High | CIS GH Level 1 |
| [CIS.GH.1.2.4](./CIS.GH.1.2.4.md) | (L1) Ensure issue deletion is limited to specific users | Medium | CIS GH Level 1 |
| [CIS.GH.1.3.2](./CIS.GH.1.3.2.md) | (L1) Ensure team creation is limited to specific members | Medium | CIS GH Level 1 |
| [CIS.GH.1.3.8](./CIS.GH.1.3.8.md) | (L1) Ensure strict base permissions are set for repositories | High | CIS GH Level 1 |
| [CIS.M365.1.1.1](./CIS.M365.1.1.1.md) | (L1) Ensure Administrative accounts are cloud-only | High | CIS E3 Level 1 |
| [CIS.M365.1.1.3](./CIS.M365.1.1.3.md) | (L1) Ensure that between two and four global admins are designated | High | CIS E3 Level 1 |
| [CIS.M365.1.2.1](./CIS.M365.1.2.1.md) | (L2) Ensure that only organizationally managed/approved public groups exist | Medium | CIS E3 Level 2 |
| [CIS.M365.1.2.2](./CIS.M365.1.2.2.md) | (L1) Ensure sign-in to shared mailboxes is blocked | High | CIS E3 Level 1 |
| [CIS.M365.1.3.1](./CIS.M365.1.3.1.md) | (L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | High | CIS E3 Level 1 |
| [CIS.M365.1.3.3](./CIS.M365.1.3.3.md) | (L2) Ensure 'External sharing' of calendars is not available | Medium | CIS E3 Level 2 |
| [CIS.M365.1.3.4](./CIS.M365.1.3.4.md) | Ensure | Unknown | CIS E3 Level 1 |
| [CIS.M365.1.3.5](./CIS.M365.1.3.5.md) | Ensure internal phishing protection for Forms is enabled | Unknown | CIS E3 Level 1 |
| [CIS.M365.1.3.6](./CIS.M365.1.3.6.md) | (L2) Ensure the customer lockbox feature is enabled | High | CIS E5 Level 2 |
| [CIS.M365.1.3.7](./CIS.M365.1.3.7.md) | Ensure | Unknown | CIS E3 Level 2 |
| [CIS.M365.2.1.1](./CIS.M365.2.1.1.md) | (L2) Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy) | Medium | CIS E5 Level 2 |
| [CIS.M365.2.1.2](./CIS.M365.2.1.2.md) | (L1) Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.1.3](./CIS.M365.2.1.3.md) | (L1) Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.1.4](./CIS.M365.2.1.4.md) | (L2) Ensure Safe Attachments policy is enabled (Only Checks Default Policy) | High | CIS E5 Level 2 |
| [CIS.M365.2.1.5](./CIS.M365.2.1.5.md) | (L2) Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled | High | CIS E5 Level 2 |
| [CIS.M365.2.1.6](./CIS.M365.2.1.6.md) | (L1) Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.1.7](./CIS.M365.2.1.7.md) | (L1) Ensure that an anti-phishing policy has been created (Only Checks Default Policy) | Medium | CIS E5 Level 1 |
| [CIS.M365.2.1.9](./CIS.M365.2.1.9.md) | (L1) Ensure that DKIM is enabled for all Exchange Online Domains | High | CIS E3 Level 1 |
| [CIS.M365.2.1.11](./CIS.M365.2.1.11.md) | (L2) Ensure comprehensive attachment filtering is applied | High | CIS E3 Level 2 |
| [CIS.M365.2.1.12](./CIS.M365.2.1.12.md) | (L1) Ensure the connection filter IP allow list is not used (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.1.13](./CIS.M365.2.1.13.md) | (L1) Ensure the connection filter safe list is off (Only Checks Default Policy) | Medium | CIS E3 Level 1 |
| [CIS.M365.2.4.4](./CIS.M365.2.4.4.md) | (L1) Ensure Zero-hour auto purge for Microsoft Teams is on (Only Checks ZAP is enabled) | Medium | CIS E5 Level 1 |
| [CIS.M365.3.1.1](./CIS.M365.3.1.1.md) | (L1) Ensure Microsoft 365 audit log search is Enabled | High | CIS E3 Level 1 |
| [CIS.M365.4.1](./CIS.M365.4.1.md) | Ensure devices without a compliance policy are marked | Unknown | CIS E3 Level 2 |
| [CIS.M365.5.1.2.2](./CIS.M365.5.1.2.2.md) | Ensure third party integrated applications are not allowed | Unknown | CIS E3 Level 2 |
| [CIS.M365.5.1.2.3](./CIS.M365.5.1.2.3.md) | Ensure | Unknown | CIS E3 Level 1 |
| [CIS.M365.5.1.3.1](./CIS.M365.5.1.3.1.md) | Ensure a dynamic group for guest users is created | Unknown | CIS E3 Level 1 |
| [CIS.M365.5.1.5.1](./CIS.M365.5.1.5.1.md) | Ensure user consent to apps accessing company data on their behalf is not allowed | Unknown | CIS E3 Level 2 |
| [CIS.M365.5.1.5.2](./CIS.M365.5.1.5.2.md) | Ensure the admin consent workflow is enabled | Unknown | CIS E3 Level 1 |
| [CIS.M365.5.1.6.2](./CIS.M365.5.1.6.2.md) | Ensure that guest user access is restricted | Unknown | CIS E3 Level 1 |
| [CIS.M365.5.2.3.5](./CIS.M365.5.2.3.5.md) | Ensure weak authentication methods are disabled | Unknown | CIS E3 Level 1 |
| [CIS.M365.6.5.3](./CIS.M365.6.5.3.md) | Ensure additional storage providers are restricted in Outlook on the web | Unknown | CIS E3 Level 2 |
| [CIS.M365.7.2.2](./CIS.M365.7.2.2.md) | Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | Unknown | SharePoint Online |
| [CIS.M365.7.2.5](./CIS.M365.7.2.5.md) | Ensure that SharePoint guest users cannot share items they don | Unknown | SharePoint Online |
| [CIS.M365.7.2.7](./CIS.M365.7.2.7.md) | Ensure link sharing is restricted in SharePoint and OneDrive | Unknown | SharePoint Online |
| [CIS.M365.7.2.9](./CIS.M365.7.2.9.md) | Ensure guest access to a site or OneDrive will expire automatically | Unknown | SharePoint Online |
| [CIS.M365.7.2.11](./CIS.M365.7.2.11.md) | Ensure the SharePoint default sharing link permission is set | Unknown | SharePoint Online |
| [CIS.M365.7.3.1](./CIS.M365.7.3.1.md) | Ensure Office 365 SharePoint infected files are disallowed for download | Unknown | SharePoint Online |
| [CIS.M365.8.1.1](./CIS.M365.8.1.1.md) | (L2) Ensure external file sharing in Teams is enabled for only approved cloud storage services | Medium | CIS M365 v6.0.1 |
| [CIS.M365.8.2.2](./CIS.M365.8.2.2.md) | (L1) Ensure communication with unmanaged Teams users is disabled | Medium | CIS M365 v6.0.1 |
| [CIS.M365.8.2.3](./CIS.M365.8.2.3.md) | Ensure external Teams users cannot initiate conversations | Unknown | CIS M365 v6.0.1 |
| [CIS.M365.8.4.1](./CIS.M365.8.4.1.md) | (L1) Ensure all or a majority of third-party and custom apps are blocked | High | CIS M365 v6.0.1 |
| [CIS.M365.8.5.3](./CIS.M365.8.5.3.md) | (L1) Ensure only people in my org can bypass the lobby | Medium | CIS E3 Level 1 |
| [CIS.M365.8.6.1](./CIS.M365.8.6.1.md) | (L1) Ensure users can report security concerns in Teams to internal destination | Medium | CIS E3 Level 1 |
Loading