Reference

Wartiva Policy Rules

All 720 checks Wartiva runs: the CIS Benchmarks for macOS Tahoe, Windows 11, and Ubuntu 24.04 LTS, plus Wartiva's own controls. Each lists what it finds, why it matters, and how to fix it.

Wartiva mirrors compressed endpoint state to the cloud, so every rule runs there instead of on your users' machines. When a rule fails, Wartiva records a finding and saves a copy of the object exactly as it appeared at the moment of discovery: defensible evidence for audits. Each finding's remediation instructions can become a ready-to-run bash or PowerShell script, safety-reviewed by AI, that you approve or automate. Configuration rules are evaluated every time the object changes; search rules run on a schedule.

Make the catalog yours: disable any rule, change its severity, and add your own. Edit or write the Rego (OPA) behind configuration rules, add search and path rules, and test them against mock data in the Wartiva UI before they go live. Wartiva's AI policy assistant can tailor rules or draft new ones for your environment. You can also list the rules through the API.

Every check lists its finding (what Wartiva flags), why it matters and its impact, how to fix it in the settings and from the command line, its severity, and its mappings to the benchmark section, risk, and MITRE ATT&CK tactic. Checks are also mapped to the CIS Controls v8, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, CMMC 2.0, and PCI DSS v4.0.1 requirements they provide evidence for.

Matching checks appear under their benchmark section.

CIS Apple macOS 26 Tahoe Benchmark 90 checks

CIS Benchmark checks for Apple macOS 26 Tahoe: software updates, System Settings, logging and auditing, network configuration, system access, and applications.

CIS Microsoft Windows 11 Stand-alone Benchmark 484 checks

CIS Benchmark checks for stand-alone Microsoft Windows 11: account and local policies, system services, Windows Firewall, audit policy, and administrative templates.

CIS Ubuntu Linux 24.04 LTS Benchmark 85 checks

CIS Benchmark checks for Ubuntu Linux 24.04 LTS: filesystems, services, networking, the host firewall, access control, and logging and auditing.

Wartiva Security Controls 61 checks

Controls Wartiva wrote for risks the CIS Benchmarks don't cover, found across your security graph: wireless networks, ARP, SSL/TLS, network services, endpoint posture, Active Directory, and exposed devices.

See how your fleet scores against every rule

Wartiva is in early access. Request your spot and run all 720 checks across your endpoints, with evidence your auditors can use.

Request Early Access