DISA STIG for Microsoft Dot Net Framework 4.0 v2r6

Audit Details

Name: DISA STIG for Microsoft Dot Net Framework 4.0 v2r6

Updated: 7/30/2025

Authority: DISA STIG

Plugin: Windows

Revision: 1.0

Estimated Item Count: 18

File Details

Filename: DISA_STIG_Microsoft_Dot_Net_Framework_4.0_v2r6.audit

Size: 105 kB

MD5: ae1942918407308976b24bcca5c3e73a
SHA256: 9fefef626c674864878c8ab51d1c0112508e8c5a82744a753025e946a26982f3

Audit Items

DescriptionCategories
APPNET0031 - Digital signatures assigned to strongly named assemblies must be verified.

IDENTIFICATION AND AUTHENTICATION

APPNET0046 - The Trust Providers Software Publishing State must be set to 0x23C00.

IDENTIFICATION AND AUTHENTICATION

APPNET0048 - Developer certificates used with the .NET Publisher Membership Condition must be approved by the ISSO.

IDENTIFICATION AND AUTHENTICATION

APPNET0052 - Encryption keys used for the .NET Strong Name Membership Condition must be protected.

IDENTIFICATION AND AUTHENTICATION

APPNET0055 - CAS and policy configuration files must be backed up.

AUDIT AND ACCOUNTABILITY

APPNET0060 - Remoting Services HTTP channels must utilize authentication and encryption.

SYSTEM AND COMMUNICATIONS PROTECTION

APPNET0061 - .Net Framework versions installed on the system must be supported.

CONFIGURATION MANAGEMENT

APPNET0062 - The .NET CLR must be configured to use FIPS approved encryption modules.

SYSTEM AND COMMUNICATIONS PROTECTION

APPNET0063 - .NET must be configured to validate strong names on full-trust assemblies.

IDENTIFICATION AND AUTHENTICATION

APPNET0064 - .Net applications that invoke NetFx40_LegacySecurityPolicy must apply previous versions of .NET STIG guidance.

CONFIGURATION MANAGEMENT

APPNET0065 - Trust must be established prior to enabling the loading of remote code in .Net 4.

SYSTEM AND COMMUNICATIONS PROTECTION

APPNET0066 - .NET default proxy settings must be reviewed and approved.

CONFIGURATION MANAGEMENT

APPNET0067 - Event tracing for Windows (ETW) for Common Language Runtime events must be enabled.

AUDIT AND ACCOUNTABILITY

APPNET0070 - Software utilizing .Net 4.0 must be identified and relevant access controls configured.

SYSTEM AND COMMUNICATIONS PROTECTION

APPNET0071 - Remoting Services TCP channels must utilize authentication and encryption.

SYSTEM AND COMMUNICATIONS PROTECTION

APPNET0075 - Disable TLS RC4 cipher in .Net

CONFIGURATION MANAGEMENT

APPNET0075 - Update and configure the .NET Framework to support TLS.

CONFIGURATION MANAGEMENT

DISA_STIG_Microsoft_Dot_Net_Framework_4.0_v2r6.audit from DISA Microsoft DotNet Framework 4.0 v2r6 STIG