---
title: Security Controls Beyond the CIS Benchmarks | Wartiva
description: All 61 of Wartiva's own security controls, by control area: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/wartiva.html
updated: 2026-10-07
---

Policy Rules

# Wartiva Security Controls: 61 Checks

Controls Wartiva wrote for risks the CIS Benchmarks don't cover, found across your security graph: wireless networks, ARP, SSL/TLS, network services, endpoint posture, Active Directory, and exposed devices.

Wartiva writes and maintains these controls itself rather than deriving them from a third-party publication. They cover risks Wartiva sees directly across your security graph, including checks no published benchmark defines.

- Critical 2
- High 39
- Medium 16
- Low 4

## [Active Directory](https://wartiva.com/policy-rules/wartiva/active-directory.html) 3 checks

- [Ensure Active Directory Is Not Reporting A Problem State](https://wartiva.com/policy-rules/wartiva/active-directory.html#active-directory-is-not-reporting-a-problem-state)
- [Ensure Desktop Endpoints Are Not Operating As Domain Controllers](https://wartiva.com/policy-rules/wartiva/active-directory.html#desktop-endpoints-are-not-operating-as-domain-controllers)
- [Ensure macOS Active Directory Binding Is Securely Configured](https://wartiva.com/policy-rules/wartiva/active-directory.html#macos-active-directory-binding-is-securely-configured)

## [ARP](https://wartiva.com/policy-rules/wartiva/arp.html) 2 checks

- [Ensure No Conflicting ARP Table Entries Are Present](https://wartiva.com/policy-rules/wartiva/arp.html#no-conflicting-arp-table-entries-are-present)
- [Ensure The Default Gateway Is Not Being ARP Spoofed](https://wartiva.com/policy-rules/wartiva/arp.html#the-default-gateway-is-not-being-arp-spoofed)

## [Device Exposure](https://wartiva.com/policy-rules/wartiva/device-exposure.html) 7 checks

- [Ensure Devices Do Not Have Publicly Exposed Ports](https://wartiva.com/policy-rules/wartiva/device-exposure.html#devices-do-not-have-publicly-exposed-ports)
- [Ensure No United States NDAA Section 889 Prohibited Dahua Devices Are Present](https://wartiva.com/policy-rules/wartiva/device-exposure.html#no-united-states-ndaa-section-889-prohibited-dahua-devices-are-present)
- [Ensure No United States NDAA Section 889 Prohibited Hikvision Devices Are Present](https://wartiva.com/policy-rules/wartiva/device-exposure.html#no-united-states-ndaa-section-889-prohibited-hikvision-devices-are-present)
- [Ensure No United States NDAA Section 889 Prohibited Huawei Devices Are Present](https://wartiva.com/policy-rules/wartiva/device-exposure.html#no-united-states-ndaa-section-889-prohibited-huawei-devices-are-present)
- [Ensure No United States NDAA Section 889 Prohibited Hytera Devices Are Present](https://wartiva.com/policy-rules/wartiva/device-exposure.html#no-united-states-ndaa-section-889-prohibited-hytera-devices-are-present)
- [Ensure No United States NDAA Section 889 Prohibited ZTE Devices Are Present](https://wartiva.com/policy-rules/wartiva/device-exposure.html#no-united-states-ndaa-section-889-prohibited-zte-devices-are-present)
- [Ensure No Untrusted-Vendor (ZBT / Shenzhen Zhibotong) Devices Are Present](https://wartiva.com/policy-rules/wartiva/device-exposure.html#no-untrusted-vendor-zbt-shenzhen-zhibotong-devices-are-present)

## [Endpoint Posture](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html) 23 checks

- [Ensure The Windows Host Firewall Is Enabled](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#the-windows-host-firewall-is-enabled)
- [Ensure The macOS Application Firewall Is Enabled](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#the-macos-application-firewall-is-enabled)
- [Ensure The Linux Host Firewall Is Enabled](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#the-linux-host-firewall-is-enabled)
- [Ensure Windows Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#windows-endpoints-with-a-disabled-firewall-are-not-on-a-network-with-a-publicly)
- [Ensure macOS Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#macos-endpoints-with-a-disabled-firewall-are-not-on-a-network-with-a-publicly-ex)
- [Ensure Linux Endpoints With A Disabled Firewall Are Not On A Network With A Publicly Exposed Gateway](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#linux-endpoints-with-a-disabled-firewall-are-not-on-a-network-with-a-publicly-ex)
- [Ensure Active Antivirus Protection Is Present](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#active-antivirus-protection-is-present)
- [Ensure Antivirus Is Reporting Its State](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#antivirus-is-reporting-its-state)
- [Ensure Windows Security Services Are Healthy](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#windows-security-services-are-healthy)
- [Ensure Endpoint Agents Are Up To Date](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#endpoint-agents-are-up-to-date)
- [Ensure Windows Desktop System Drives Are Encrypted](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#windows-desktop-system-drives-are-encrypted)
- [Ensure macOS Desktop System Drives Are Encrypted](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#macos-desktop-system-drives-are-encrypted)
- [Ensure Linux Desktop System Drives Are Encrypted](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#linux-desktop-system-drives-are-encrypted)
- [Ensure Disk Encryption Does Not Use A Weak Cipher](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#disk-encryption-does-not-use-a-weak-cipher)
- [Ensure Disk Mounts Are Not Critically Full](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#disk-mounts-are-not-critically-full)
- [Ensure Network Interfaces Are Not Accumulating Errors](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#network-interfaces-are-not-accumulating-errors)
- [Ensure Endpoints Have No High-Severity Vulnerabilities](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#endpoints-have-no-high-severity-vulnerabilities)
- [Ensure Installed Applications Have No High-Severity Vulnerabilities](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#installed-applications-have-no-high-severity-vulnerabilities)
- [Ensure Operating System Updates Are Installed Regularly](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#operating-system-updates-are-installed-regularly)
- [Ensure Root Does Not Log In From External Hosts](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#root-does-not-log-in-from-external-hosts)
- [Ensure The Built-In Administrator Account Is Not In Use](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#the-built-in-administrator-account-is-not-in-use)
- [Ensure Endpoints Are Not Located In A Sanctioned Country](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#endpoints-are-not-located-in-a-sanctioned-country)
- [Ensure Endpoints Do Not Show Impossible Travel](https://wartiva.com/policy-rules/wartiva/endpoint-posture.html#endpoints-do-not-show-impossible-travel)

## [Network Services](https://wartiva.com/policy-rules/wartiva/network-services.html) 13 checks

- [Ensure SSH Servers Are Not Insecurely Configured](https://wartiva.com/policy-rules/wartiva/network-services.html#ssh-servers-are-not-insecurely-configured)
- [Ensure SMB Services Are Not Insecurely Configured](https://wartiva.com/policy-rules/wartiva/network-services.html#smb-services-are-not-insecurely-configured)
- [Ensure SMTP Servers Require TLS And Are Not Open Relays](https://wartiva.com/policy-rules/wartiva/network-services.html#smtp-servers-require-tls-and-are-not-open-relays)
- [Ensure SNMP Services Do Not Use Default Community Strings](https://wartiva.com/policy-rules/wartiva/network-services.html#snmp-services-do-not-use-default-community-strings)
- [Ensure NTP Servers Do Not Respond To Monlist Queries](https://wartiva.com/policy-rules/wartiva/network-services.html#ntp-servers-do-not-respond-to-monlist-queries)
- [Ensure Cleartext FTP Services Are Not Present](https://wartiva.com/policy-rules/wartiva/network-services.html#cleartext-ftp-services-are-not-present)
- [Ensure Cleartext Telnet Services Are Not Present](https://wartiva.com/policy-rules/wartiva/network-services.html#cleartext-telnet-services-are-not-present)
- [Ensure AppSocket Printer Services Are Not Present](https://wartiva.com/policy-rules/wartiva/network-services.html#appsocket-printer-services-are-not-present)
- [Ensure IPP Print Services Have TLS Enabled](https://wartiva.com/policy-rules/wartiva/network-services.html#ipp-print-services-have-tls-enabled)
- [Ensure Raw Printer Ports (TCP 9100) Are Not Open](https://wartiva.com/policy-rules/wartiva/network-services.html#raw-printer-ports-tcp-9100-are-not-open)
- [Ensure IRC Services Are Not Present](https://wartiva.com/policy-rules/wartiva/network-services.html#irc-services-are-not-present)
- [Ensure Each Network Has Only One DHCP Server](https://wartiva.com/policy-rules/wartiva/network-services.html#each-network-has-only-one-dhcp-server)
- [Ensure Network Services Have No High-Severity Vulnerabilities](https://wartiva.com/policy-rules/wartiva/network-services.html#network-services-have-no-high-severity-vulnerabilities)

## [SSL/TLS](https://wartiva.com/policy-rules/wartiva/ssl-tls.html) 8 checks

- [Ensure Discovered Services Do Not Use Insecure SSL/TLS Versions Or Ciphers](https://wartiva.com/policy-rules/wartiva/ssl-tls.html#discovered-services-do-not-use-insecure-ssl-tls-versions-or-ciphers)
- [Ensure Discovered Services Do Not Use Weak SSL/TLS Versions Or Ciphers](https://wartiva.com/policy-rules/wartiva/ssl-tls.html#discovered-services-do-not-use-weak-ssl-tls-versions-or-ciphers)
- [Ensure Discovered Services Do Not Accept Insecure SSL/TLS Versions Or Ciphers](https://wartiva.com/policy-rules/wartiva/ssl-tls.html#discovered-services-do-not-accept-insecure-ssl-tls-versions-or-ciphers)
- [Ensure Discovered Services Do Not Accept Weak SSL/TLS Cipher Suites](https://wartiva.com/policy-rules/wartiva/ssl-tls.html#discovered-services-do-not-accept-weak-ssl-tls-cipher-suites)
- [Ensure Discovered Services Enforce Server Cipher Suite Preference](https://wartiva.com/policy-rules/wartiva/ssl-tls.html#discovered-services-enforce-server-cipher-suite-preference)
- [Ensure Discovered Services Do Not Present Invalid TLS Certificates](https://wartiva.com/policy-rules/wartiva/ssl-tls.html#discovered-services-do-not-present-invalid-tls-certificates)
- [Ensure Discovered Services' TLS Certificates Are Not Expiring Soon](https://wartiva.com/policy-rules/wartiva/ssl-tls.html#discovered-services-tls-certificates-are-not-expiring-soon)
- [Ensure Discovered Services Do Not Present Revoked TLS Certificates](https://wartiva.com/policy-rules/wartiva/ssl-tls.html#discovered-services-do-not-present-revoked-tls-certificates)

## [Wireless Networks](https://wartiva.com/policy-rules/wartiva/wireless-networks.html) 5 checks

- [Ensure No Possible Evil Twin Attack Is Detected](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#no-possible-evil-twin-attack-is-detected)
- [Ensure No Insecure Wireless Networks Are Detected Nearby](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#no-insecure-wireless-networks-are-detected-nearby)
- [Ensure Endpoints Are Not Connected To A Network With A Possible Evil Twin Access Point](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#endpoints-are-not-connected-to-a-network-with-a-possible-evil-twin-access-point)
- [Ensure Endpoints Are Not Connected To Insecure Wireless Networks](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#endpoints-are-not-connected-to-insecure-wireless-networks)
- [Ensure Endpoints Are Not Connected To A Possible Evil Twin Access Point](https://wartiva.com/policy-rules/wartiva/wireless-networks.html#endpoints-are-not-connected-to-a-possible-evil-twin-access-point)

## See your environment the way it really exists

Wartiva is in early access. Request your spot and talk to the team that built the endpoint platform they always wished they had.

[Request Early Access](https://wartiva.com/early-access.html)

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
