Item Search

NameAudit NamePluginCategory
1.38 ESXI-80-000211CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT III UnixUnix

CONFIGURATION MANAGEMENT

1.123 WN16-CC-000350CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.242 WN16-SO-000450CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.355 RHEL-09-651030CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IIIUnix

CONFIGURATION MANAGEMENT

APPL-14-001029 - The macOS system must configure audit retention to seven days.DISA Apple macOS 14 Sonoma STIG v2r4Unix

AUDIT AND ACCOUNTABILITY

AZLX-23-002020 - Amazon Linux 2023 must use a separate file system for the system audit data path.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY

CISC-RT-000236 - The Cisco switch must be configured to advertise a hop limit of at least 32 in Switch Advertisement messages for IPv6 stateless auto-configuration deployments.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

Configuring a pre-login or post-login message banner for the BIG-IP or Enterprise Manager system - Banner EnabledTenable F5 BIG-IP Best Practice AuditF5

ACCESS CONTROL

Configuring a pre-login or post-login message banner for the BIG-IP or Enterprise Manager system - Banner TextTenable F5 BIG-IP Best Practice AuditF5

ACCESS CONTROL

EDGE-00-000001 - User control of proxy settings must be disabled.DISA Microsoft Edge STIG v2r5Windows

ACCESS CONTROL

EDGE-00-000052 - The download location prompt must be configured.DISA Microsoft Edge STIG v2r5Windows

CONFIGURATION MANAGEMENT

FFOX-00-000015 - Firefox development tools must be disabled.DISA STIG Mozilla Firefox MacOS v6r7Unix

SYSTEM AND INFORMATION INTEGRITY

FNFG-FW-000035 - The FortiGate firewall must generate traffic log entries containing information to establish the source of the events, such as the source IP address at a minimum.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

JUEX-L2-000250 - The Juniper EX switch must not have any access interfaces assigned to a VLAN configured as native for any trunked interface.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-RT-000160 - The Juniper router must be configured to have all inactive interfaces disabled.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

JUEX-RT-000190 - The Juniper perimeter router must not be configured to redistribute static routes to an alternate gateway service provider into BGP or an IGP peering with the NIPRNet or to other autonomous systems.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

JUEX-RT-000230 - The Juniper multicast Rendezvous Point (RP) router must be configured to filter Protocol Independent Multicast (PIM) Join messages received from the Designated Router (DR) for any undesirable multicast groups.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

OL08-00-010171 - OL 8 must have the "policycoreutils" package installed.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010292 - The OL 8 SSH server must be configured to use strong entropy.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010376 - OL 8 must prevent kernel profiling by nonprivileged users.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-020024 - OL 8 must limit the number of concurrent sessions to 10 for all accounts and/or account types.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL09-00-000002 - OL 9 must use a separate file system for the system audit data path.DISA Oracle Linux 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

OL09-00-000005 - OL 9 must use a separate file system for /var.DISA Oracle Linux 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

OL09-00-000006 - OL 9 must use a separate file system for /var/log.DISA Oracle Linux 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

RHEL-08-010472 - RHEL 8 must have the packages required to use the hardware random number generator entropy gatherer service.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010540 - RHEL 8 must use a separate file system for /var.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010541 - RHEL 8 must use a separate file system for /var/log.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010542 - RHEL 8 must use a separate file system for the system audit data path.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-030601 - RHEL 8 must enable auditing of processes that start prior to the audit daemon.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

RHEL-08-030602 - RHEL 8 must allocate an audit_backlog_limit of sufficient size to capture processes that start prior to the audit daemon.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

RHEL-08-030742 - RHEL 8 must disable network management of the chrony daemon.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040022 - RHEL 8 must disable the controller area network (CAN) protocol.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040024 - RHEL 8 must disable the transparent inter-process communication (TIPC) protocol.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040026 - RHEL 8 must disable IEEE 1394 (FireWire) Support.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-09-231195 - RHEL 9 must disable mounting of cramfs.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-651035 - RHEL 9 must be configured so that the file integrity tool verifies extended attributes.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-10-000520 - RHEL 10 must use a separate file system for the system audit data path.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

SLES-15-010410 - The SUSE operating system must be configured to use Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

SLES-15-040040 - The SUSE operating system file integrity tool must be configured to verify Access Control Lists (ACLs).DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

UBTU-24-100020 - Ubuntu 24.04 LTS must not have the "ntp" package installed.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

CONFIGURATION MANAGEMENT

VCSA-80-000277 - The vCenter Server must be isolated from the public internet but must still allow for patch notification and delivery.DISA VMware vSphere 8.0 vCenter STIG v2r4 VMwareVMware

CONFIGURATION MANAGEMENT

VCSA-80-000299 - The vCenter Server must disable CDP/LLDP on distributed switches.DISA VMware vSphere 8.0 vCenter STIG v2r4 VMwareVMware

CONFIGURATION MANAGEMENT

VMCH-80-000199 Virtual machines (VMs) must have shared salt values disabled.DISA VMware vSphere 8.0 Virtual Machine STIG v2r1VMware

CONFIGURATION MANAGEMENT

WN11-SO-000055 - The maximum age for machine account passwords must be configured to 30 days or less.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-UC-000015 - Toast notifications to the lock screen must be turned off.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN25-CC-000030 - Windows Server 2025 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT

WN25-CC-000060 - Windows Server 2025 must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Microsoft Windows Server 2025 STIG v1r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-CC-000200 - Windows Server 2025 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT

ZEBR-11-011000 - Zebra Android 11 devices must be configured to disable the use of third-party keyboards.AirWatch - DISA Zebra Android 11 COBO STIG v1r4MDM

CONFIGURATION MANAGEMENT

ZEBR-11-011100 - Zebra Android 11 devices must be configured to enable Common Criteria Mode (CC Mode).AirWatch - DISA Zebra Android 11 COBO STIG v1r4MDM

CONFIGURATION MANAGEMENT