Reference
Wartiva Policy Rules
All 720 checks Wartiva runs: the CIS Benchmarks for macOS Tahoe, Windows 11, and Ubuntu 24.04 LTS, plus Wartiva's own controls. Each lists what it finds, why it matters, and how to fix it.
Wartiva mirrors compressed endpoint state to the cloud, so every rule runs there instead of on your users' machines. When a rule fails, Wartiva records a finding and saves a copy of the object exactly as it appeared at the moment of discovery: defensible evidence for audits. Each finding's remediation instructions can become a ready-to-run bash or PowerShell script, safety-reviewed by AI, that you approve or automate. Configuration rules are evaluated every time the object changes; search rules run on a schedule.
Make the catalog yours: disable any rule, change its severity, and add your own. Edit or write the Rego (OPA) behind configuration rules, add search and path rules, and test them against mock data in the Wartiva UI before they go live. Wartiva's AI policy assistant can tailor rules or draft new ones for your environment. You can also list the rules through the API.
Every check lists its finding (what Wartiva flags), why it matters and its impact, how to fix it in the settings and from the command line, its severity, and its mappings to the benchmark section, risk, and MITRE ATT&CK tactic. Checks are also mapped to the CIS Controls v8, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, CMMC 2.0, and PCI DSS v4.0.1 requirements they provide evidence for.
Matching checks appear under their benchmark section.
No checks match your search.
CIS Apple macOS 26 Tahoe Benchmark 90 checks
CIS Benchmark checks for Apple macOS 26 Tahoe: software updates, System Settings, logging and auditing, network configuration, system access, and applications.
- 1 Install Updates 6 checks
- 2 System Settings 47 checks
- 3 Logging and Auditing 4 checks
- 4 Network Configurations 3 checks
- 5 System Access 22 checks
- 6 Applications 8 checks
CIS Microsoft Windows 11 Stand-alone Benchmark 484 checks
CIS Benchmark checks for stand-alone Microsoft Windows 11: account and local policies, system services, Windows Firewall, audit policy, and administrative templates.
- 1 Account Policies 11 checks
- 2.2 User Rights Assignment 38 checks
- 2.3 Security Options 53 checks
- 5 System Services 44 checks
- 9 Windows Defender Firewall with Advanced Security 14 checks
- 17 Advanced Audit Policy Configuration 27 checks
- 18.1 Control Panel 4 checks
- 18.4 MS Security Guide 6 checks
- 18.5 MSS (Legacy) 12 checks
- 18.6 Network 27 checks
- 18.7 Printers 18 checks
- 18.8 Start Menu and Taskbar 2 checks
- 18.9 System 57 checks
- 18.10 Windows Components 158 checks
- 18.11 Custom Settings 2 checks
- 19 Administrative Templates (User) 11 checks
CIS Ubuntu Linux 24.04 LTS Benchmark 85 checks
CIS Benchmark checks for Ubuntu Linux 24.04 LTS: filesystems, services, networking, the host firewall, access control, and logging and auditing.
- 1 Initial Setup 30 checks
- 2 Services 31 checks
- 3 Network 1 check
- 4 Host Based Firewall 2 checks
- 5 Access Control 9 checks
- 6 Logging and Auditing 10 checks
- 7 System Maintenance 2 checks
Wartiva Security Controls 61 checks
Controls Wartiva wrote for risks the CIS Benchmarks don't cover, found across your security graph: wireless networks, ARP, SSL/TLS, network services, endpoint posture, Active Directory, and exposed devices.
- Active Directory 3 checks
- ARP 2 checks
- Device Exposure 7 checks
- Endpoint Posture 23 checks
- Network Services 13 checks
- SSL/TLS 8 checks
- Wireless Networks 5 checks
See how your fleet scores against every rule
Wartiva is in early access. Request your spot and run all 720 checks across your endpoints, with evidence your auditors can use.