Item Search

NameAudit NamePluginCategory
1.4.7 Ensure the operating system is not configured to reboot the system when Ctrl-Alt-Delete is pressed seven times within two secondsCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.5.22 Ensure the operating system is not configured to reboot the system when Ctrl-Alt-Delete is pressedCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.006-01 - Policy must require that administrative user accounts not be used with applications that access the internet.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

1.8.10 Ensure the operating system is not configured to reboot the system when Ctrl-Alt-Delete is pressed when using a graphical user interfaceCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

7.1.14 Ensure there are no ".shosts" files on the operating systemCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

7.1.15 Ensure there are no "shosts.equiv" files on the operating systemCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

DG0001-ORACLE11 - Vendor supported software is evaluated and patched against newly found vulnerabilities.DISA STIG Oracle 11 Installation v9r1 LinuxUnix
DG0001-ORACLE11 - Vendor supported software is evaluated and patched against newly found vulnerabilities.DISA STIG Oracle 11 Installation v9r1 WindowsWindows
DG0128-ORACLE11 - DBMS default accounts should be assigned custom passwords - 'No default accounts are OPEN'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0167-ORACLE11 - Sensitive data served by the DBMS should be protected by encryption when transmitted across the network.DISA STIG Oracle 11 Installation v9r1 LinuxUnix
DG0167-ORACLE11 - Sensitive data served by the DBMS should be protected by encryption when transmitted across the network.DISA STIG Oracle 11 Installation v9r1 WindowsWindows
DO3538-ORACLE11 - The Oracle REMOTE_OS_AUTHENT parameter should be set to FALSE - 'remote_os_authent = false'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO3539-ORACLE11 - The Oracle REMOTE_OS_ROLES parameter should be set to FALSE - 'remote_os_roles = false'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'LSNRCTL Security'DISA STIG Oracle 11 Installation v9r1 LinuxUnix
DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'LSNRCTL Security'DISA STIG Oracle 11 Installation v9r1 WindowsWindows
DTBI002 - IE9 - The installed version of IE must be a supported version.DISA STIG Microsoft Internet Explorer 9 v1r15Windows
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - -+IncludesNOEXEC|-IncludesDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - +IncludesDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - NoneDISA STIG Apache Server 2.2 Unix v1r11Unix
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - NoneDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - Options NoneDISA STIG Apache Server 2.2 Unix v1r11Unix
WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - Options NoneDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA155 IIS6 - Classified web servers must be afforded physical security commensurate with the classification of its content.DISA STIG IIS 6.0 Server v6r16Windows
WA155 W22 - Classified web servers will be afforded physical security commensurate with the classification of its content.DISA STIG Apache Server 2.2 Windows v1r13Windows
WG190 A22 - Web server software must be a vendor-supported version.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG190 A22 - Web server software must be a vendor-supported version.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND INFORMATION INTEGRITY

WG200 IIS6 - Non-administrators must not be allowed access to the directory tree, the shell, or other utilities. - 'cmd.exe'DISA STIG IIS 6.0 Server v6r16Windows
WG200 IIS6 - Non-administrators must not be allowed access to the directory tree, the shell, or other utilities. - 'command.com'DISA STIG IIS 6.0 Server v6r16Windows
WG200 W22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities. - 'System32\cmd.exe'DISA STIG Apache Server 2.2 Windows v1r13Windows
WG200 W22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities. - 'System32\command.com'DISA STIG Apache Server 2.2 Windows v1r13Windows
WG200 W22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities. - 'System32\dllcache\cmd.exe'DISA STIG Apache Server 2.2 Windows v1r13Windows
WG230 A22 - Web server administration must be performed over a secure path or at the local console.DISA STIG Apache Site 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG235 A22 - Web Administrators must only use encrypted connections for Document Root directory uploads.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix
WG235 A22 - Web Administrators must only use encrypted connections for Document Root directory uploads.DISA STIG Apache Site 2.2 Unix v1r11Unix
WG235 IIS6 - Web Administrators must secure encrypted connections for Document Root directory uploads.DISA STIG IIS 6.0 Site Checklist v6r16Windows
WG235 W22 - Web Administrators must only use encrypted connections for Document Root directory uploads.DISA STIG Apache Site 2.2 Windows v1r13Windows
WG290 A22 - Web client access to the content directories must be restricted to read and execute - aliasDISA STIG Apache Site 2.2 Unix v1r11Unix
WG290 A22 - Web client access to the content directories must be restricted to read and execute - script aliasDISA STIG Apache Site 2.2 Unix v1r11Unix
WG290 A22 - Web client access to the content directories must be restricted to read and execute - script alias matchDISA STIG Apache Site 2.2 Unix v1r11Unix
WG290 IIS6 - The web client account access to the content and scripts directories must be limited to read and execute.DISA STIG IIS 6.0 Site Checklist v6r16Windows
WG290 W22 - The web client account access to the content and scripts directories must be limited to read and execute. - 'Alias'DISA STIG Apache Site 2.2 Windows v1r13Windows
WG290 W22 - The web client account access to the content and scripts directories must be limited to read and execute. - 'DocumentRoot'DISA STIG Apache Site 2.2 Windows v1r13Windows
WG290 W22 - The web client account access to the content and scripts directories must be limited to read and execute. - 'ScriptAlias'DISA STIG Apache Site 2.2 Windows v1r13Windows
WG290 W22 - The web client account access to the content and scripts directories must be limited to read and execute. - 'ScriptAliasMatch'DISA STIG Apache Site 2.2 Windows v1r13Windows
WG360 A22 - Symbolic links must not be used in the web content directory tree - confDISA STIG Apache Site 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG385 A22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG385 IIS6 - All web server documentation, sample code, example applications, and tutorials must be removed. - 'Inetpub\AdminScripts'DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT

WG385 IIS6 - All web server documentation, sample code, example applications, and tutorials must be removed. - 'Inetpub\Iissamples'DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT

WG385 W22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. - 'httpd-manual'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG385 W22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. - 'test-cgi'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT