Item Search

NameAudit NamePluginCategory
1.4.3.1 Ensure 'aaa authentication enable console' is configured correctlyCIS Cisco ASA 9.x Firewall L1 v1.1.0Cisco

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.4.3.1 Ensure 'aaa authentication enable console' is configured correctlyCIS Cisco Firewall v8.x L1 v4.2.0Cisco

ACCESS CONTROL

1.8.16 Ensure the operating system prevents users from overriding the session idle-delay setting for the graphical user interfaceCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

1.15 APPL-26-000033CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.16 EX19-ED-000094CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.20 SQLD-22-003100CIS Microsoft SQL Server 2022 Database STIG v1.0.0 CAT IIMS_SQLDB

CONFIGURATION MANAGEMENT

1.124 APPL-26-003030CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.126 APPL-15-003020CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.163 OL08-00-020081CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.164 OL08-00-020082CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.348 RHEL-10-700760CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.356 RHEL-10-700840CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.2.1 Ensure 'ACCEPT_MD5_CERTS' Is NOT SetCIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS WindowsWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.1 Ensure 'ACCEPT_MD5_CERTS' Is NOT SETCIS Oracle Database 26ai v1.0.0 L1 RDBMS On Linux Host OS UnixUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.4.7.2.3.1 Ensure 'Always open untrusted database files in Protected View' is set to 'Enabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.8 Ensure 'SQLNET.ENCRYPTION_TYPES_CLIENT' Is Set To 'AES256'CIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS UnixUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.9 Ensure 'SQLNET.ENCRYPTION_TYPES_SERVER' Is Set To AES256CIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS UnixUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.7 Ensure 'REMOTE_OS_ROLES' Is Set To 'FALSE'CIS Oracle Database 26ai v1.0.0 L1 RDBMS On Linux Host OS OracleDBOracleDB

ACCESS CONTROL

2.5 Set 'Do not permanently delete items until the database has been backed up' to 'True'CIS Microsoft Exchange Server 2016 Mailbox v1.0.0Windows

CONTINGENCY PLANNING

3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

ACCESS CONTROL

3.3 Ensure that MongoDB is run using a non-privileged, dedicated service accountCIS MongoDB 7 v1.2.0 L1 UnixUnix

ACCESS CONTROL

3.3 Ensure that MongoDB is run using a non-privileged, dedicated service accountCIS MongoDB 8 v1.0.0 L1 WindowsWindows

ACCESS CONTROL

3.8 Ensure only the default permissions specified by Microsoft are granted to the public server roleCIS SQL Server 2016 Database L1 AWS RDS v1.4.0MS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

4.3 Review Users, Groups, and Roles - Users listCIS IBM DB2 v10 v1.1.0 Linux OS Level 2Unix

ACCESS CONTROL

4.3 Review Users, Groups, and Roles - Users listCIS IBM DB2 v10 v1.1.0 Windows OS Level 2Windows

ACCESS CONTROL

6.3.6 Ensure '3625 (trace flag)' Database Flag for all Cloud SQL SQL Server Instances Is Set to 'on'CIS Google Cloud Platform Foundation v5.0.0 L1GCP

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.10 Restrict Access to SYSCAT.PACKAGESCIS IBM DB2 9 Benchmark v3.0.1 Level 1 DBIBM_DB2DB

ACCESS CONTROL

6.15 Restrict Access to SYSCAT.SECURITYLABELSCIS IBM DB2 9 Benchmark v3.0.1 Level 1 DBIBM_DB2DB

ACCESS CONTROL

18.9.24.5 Ensure 'Default Protections for Recommended Software' is set to 'Enabled' - EXCEL.EXECIS Microsoft Windows 8.1 v2.4.1 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.9.24.5 Ensure 'Default Protections for Recommended Software' is set to 'Enabled' - INFOPATH.EXECIS Microsoft Windows 8.1 v2.4.1 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

18.9.24.5 Ensure 'Default Protections for Recommended Software' is set to 'Enabled' - LYNC.EXECIS Microsoft Windows 8.1 v2.4.1 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

ALMA-09-014430 - AlmaLinux OS 9 must disable the user list at logon for graphical user interfaces.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

AOSX-14-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple Mac OSX 10.14 v2r6Unix

ACCESS CONTROL

APPL-11-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.DISA STIG Apple macOS 11 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

APPL-12-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-26-000033 - The macOS system must disable FileVault automatic login.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-003020 - The macOS system must enforce smart card authentication.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

GEN008140 - The TLS certificate authority file and/or directory (as appropriate) must be owned by rootDISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

MD8X-00-007300 - MongoDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.DISA MongoDB Enterprise Advanced 8.x STIG v1r1 MongoDBMongoDB

CONFIGURATION MANAGEMENT

OH12-1X-000074 - OHS log files must only be accessible by privileged users - permissionsDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

AUDIT AND ACCOUNTABILITY

OH12-1X-000075 - The log information from OHS must be protected from unauthorized modification - permissionsDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

AUDIT AND ACCOUNTABILITY

OH12-1X-000076 - The log information from OHS must be protected from unauthorized deletion - permissionsDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

AUDIT AND ACCOUNTABILITY

OH12-1X-000076 - The log information from OHS must be protected from unauthorized deletion - user/groupDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

AUDIT AND ACCOUNTABILITY

OH12-1X-000185 - The CustomIdentityAlias property of the Node Manager configured to support OHS must be configured for secure communication.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000188 - The listen-port element defined within the config.xml of the OHS Standalone Domain must be configured for secure communication.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OL07-00-010482 - Oracle Linux operating systems version 7.2 or newer with a Basic Input/Output System (BIOS) must require authentication upon booting into single-user and maintenance modes - BIOS must require authentication upon booting into single-user and maintenance modes.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL07-00-010491 - Oracle Linux operating systems version 7.2 or newer using Unified Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user and maintenance modes - UEFI must require authentication upon booting into single-user and maintenance modes.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL08-00-020080 - OL 8 must prevent a user from overriding the session lock-delay setting for the graphical user interface.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-271115 - RHEL 9 must disable the user list at logon for graphical user interfaces.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-10-700760 - RHEL 10 must prevent a user from overriding the session idle-delay setting for the graphical user interface.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL