Policy Rules
Wartiva Security Controls: 61 Checks
Controls Wartiva wrote for risks the CIS Benchmarks don't cover, found across your security graph: wireless networks, ARP, SSL/TLS, network services, endpoint posture, Active Directory, and exposed devices.
Wartiva writes and maintains these controls itself rather than deriving them from a third-party publication. They cover risks Wartiva sees directly across your security graph, including checks no published benchmark defines.
- Critical 2
- High 39
- Medium 16
- Low 4
No checks match your filter.
Active Directory 3 checks
ARP 2 checks
Device Exposure 7 checks
- Ensure Devices Do Not Have Publicly Exposed Ports
- Ensure No United States NDAA Section 889 Prohibited Dahua Devices Are Present
- Ensure No United States NDAA Section 889 Prohibited Hikvision Devices Are Present
- Ensure No United States NDAA Section 889 Prohibited Huawei Devices Are Present
- Ensure No United States NDAA Section 889 Prohibited Hytera Devices Are Present
- Ensure No United States NDAA Section 889 Prohibited ZTE Devices Are Present
- Ensure No Untrusted-Vendor (ZBT / Shenzhen Zhibotong) Devices Are Present
Endpoint Posture 23 checks
- Ensure The Windows Host Firewall Is Enabled
- Ensure The macOS Application Firewall Is Enabled
- Ensure The Linux Host Firewall Is Enabled
- Ensure Windows Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
- Ensure macOS Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
- Ensure Linux Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway
- Ensure Active Antivirus Protection Is Present
- Ensure Antivirus Is Reporting Its State
- Ensure Windows Security Services Are Healthy
- Ensure Endpoint Agents Are Up To Date
- Ensure Windows Desktop System Drives Are Encrypted
- Ensure macOS Desktop System Drives Are Encrypted
- Ensure Linux Desktop System Drives Are Encrypted
- Ensure Disk Encryption Does Not Use A Weak Cipher
- Ensure Disk Mounts Are Not Critically Full
- Ensure Network Interfaces Are Not Accumulating Errors
- Ensure Endpoints Have No High-Severity Vulnerabilities
- Ensure Installed Applications Have No High-Severity Vulnerabilities
- Ensure Operating System Updates Are Installed Regularly
- Ensure Root Does Not Log In From External Hosts
- Ensure The Built-In Administrator Account Is Not In Use
- Ensure Endpoints Are Not Located In A Sanctioned Country
- Ensure Endpoints Do Not Show Impossible Travel
Network Services 13 checks
- Ensure SSH Servers Are Not Insecurely Configured
- Ensure SMB Services Are Not Insecurely Configured
- Ensure SMTP Servers Require TLS And Are Not Open Relays
- Ensure SNMP Services Do Not Use Default Community Strings
- Ensure NTP Servers Do Not Respond To Monlist Queries
- Ensure Cleartext FTP Services Are Not Present
- Ensure Cleartext Telnet Services Are Not Present
- Ensure AppSocket Printer Services Are Not Present
- Ensure IPP Print Services Have TLS Enabled
- Ensure Raw Printer Ports (TCP 9100) Are Not Open
- Ensure IRC Services Are Not Present
- Ensure Each Network Has Only One DHCP Server
- Ensure Network Services Have No High-Severity Vulnerabilities
SSL/TLS 8 checks
- Ensure Discovered Services Do Not Use Insecure SSL/TLS Versions Or Ciphers
- Ensure Discovered Services Do Not Use Weak SSL/TLS Versions Or Ciphers
- Ensure Discovered Services Do Not Accept Insecure SSL/TLS Versions Or Ciphers
- Ensure Discovered Services Do Not Accept Weak SSL/TLS Cipher Suites
- Ensure Discovered Services Enforce Server Cipher Suite Preference
- Ensure Discovered Services Do Not Present Invalid TLS Certificates
- Ensure Discovered Services' TLS Certificates Are Not Expiring Soon
- Ensure Discovered Services Do Not Present Revoked TLS Certificates
Wireless Networks 5 checks
- Ensure No Possible Evil Twin Attack Is Detected
- Ensure No Insecure Wireless Networks Are Detected Nearby
- Ensure Endpoints Are Not Connected To A Network With A Possible Evil Twin Access Point
- Ensure Endpoints Are Not Connected To Insecure Wireless Networks
- Ensure Endpoints Are Not Connected To A Possible Evil Twin Access Point
See your environment the way it really exists
Wartiva is in early access. Request your spot and talk to the team that built the endpoint platform they always wished they had.