Item Search

NameAudit NamePluginCategory
1.15 APPL-14-000033CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.15 APPL-15-000033CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.104 ALMA-09-014430CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.125 APPL-14-003030CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.157 OL08-00-020032CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.162 OL08-00-020080CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

2.1 Prevent Database Users from Logging into the Operating SystemCIS IBM DB2 12.1 v1.0.0 Database Level 1IBM_DB2DB

ACCESS CONTROL, MEDIA PROTECTION

2.1.3 Ensure 'ACCEPT_SHA1_CERTS' Is Configured CorrectlyCIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS WindowsWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.2 Ensure 'ACCEPT_SHA1_CERTS' Is NOT SetCIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS UnixUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.2 Ensure 'ACCEPT_SHA1_CERTS' Is NOT SetCIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS WindowsWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.8 Ensure 'REMOTE_OS_ROLES' Is Set to 'FALSE'CIS Oracle Server 18c DB Traditional Auditing v1.1.0OracleDB

IDENTIFICATION AND AUTHENTICATION

3.01 Files in $ORACLE_HOME/bin - 'Verify and set ownership'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows
3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2008 R2 DB Engine L1 v1.7.0MS_SQLDB

ACCESS CONTROL

3.24 .htaccess - 'Verify and set permissions'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows
3.25 dads.conf - 'Verify and set permissions'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows
4.2.1 Restrict Access to SYSCAT.AUDITPOLICIESCIS IBM DB2 12.1 v1.0.0 Database Level 1IBM_DB2DB

ACCESS CONTROL, MEDIA PROTECTION

4.10 Ensure all accounts that can log in have passwordsCIS PostgreSQL 18 v1.0.0 L1 Database PostgreSQLDBPostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

6.5 Restrict Access to SYSCAT.EVENTSCIS IBM DB2 9 Benchmark v3.0.1 Level 2 DBIBM_DB2DB

ACCESS CONTROL

6.5 Restrict Access to SYSCAT.EVENTSCIS IBM DB2 9 Benchmark v3.0.1 Level 1 DBIBM_DB2DB

ACCESS CONTROL

6.15 Restrict Access to SYSCAT.SECURITYLABELSCIS IBM DB2 9 Benchmark v3.0.1 Level 2 DBIBM_DB2DB

ACCESS CONTROL

6.18 Restrict Access to SYSCAT.SECURITYPOLICYEXEMPTIONSCIS IBM DB2 9 Benchmark v3.0.1 Level 1 DBIBM_DB2DB

ACCESS CONTROL

6.24 Restrict Access to SYSCAT.SCHEMATACIS IBM DB2 9 Benchmark v3.0.1 Level 2 DBIBM_DB2DB

ACCESS CONTROL

7.15 Secure the SQLADM authorityCIS IBM DB2 9 Benchmark v3.0.1 Level 1 DBIBM_DB2DB
AOSX-14-003025 - The macOS system must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.DISA STIG Apple Mac OSX 10.14 v2r6Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple macOS 11 v1r5Unix

ACCESS CONTROL

APPL-11-001060 - The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities to verify the establishment of protected sessions.DISA STIG Apple macOS 11 v1r5Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-001060 - The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions - PIV credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities to verify the establishment of protected sessions.DISA STIG Apple macOS 12 v1r9Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-14-001060 - The macOS system must set smart card certificate trust to moderate.DISA Apple macOS 14 Sonoma STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-15-000033 - The macOS system must disable FileVault automatic login.DISA Apple macOS 15 Sequoia STIG v1r7Unix

ACCESS CONTROL

APPL-15-001060 - The macOS system must set smart card certificate trust to moderate.DISA Apple macOS 15 Sequoia STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-15-003020 - The macOS system must enforce smart card authentication.DISA Apple macOS 15 Sequoia STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

APPL-15-003030 - The macOS system must allow smart card authentication.DISA Apple macOS 15 Sequoia STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

EX19-ED-000094 - Exchange queue database must reside on a dedicated partition.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-AS-000161 - To protect against data mining, The BIG-IP ASM module must be configured to prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields when providing content filtering to virtual servers.DISA F5 BIG-IP Application Security Manager STIG v2r2F5

ACCESS CONTROL

F5BI-AS-000165 - To protect against data mining, The BIG-IP ASM module must be configured to detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields when providing content filtering to virtual servers.DISA F5 BIG-IP Application Security Manager STIG v2r2F5

ACCESS CONTROL

MD3X-00-001100 - MongoDB must be configured in accordance with the security configuration settings based on DoD security configuration and implementation guidance, including STIGs, NSA configuration guides, CTOs, DTMs, and IAVMs.DISA STIG MongoDB Enterprise Advanced 3.x v2r3 OSUnix

CONFIGURATION MANAGEMENT

OH12-1X-000074 - OHS log files must only be accessible by privileged users - user/groupDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

AUDIT AND ACCOUNTABILITY

OL08-00-020032 - OL 8 must disable the user list at logon for graphical user interfaces.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020082 - OL 8 must prevent a user from overriding the session lock-enabled setting for the graphical user interface.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

PPS9-00-010800 - The EDB Postgres Advanced Server must generate audit records when security objects are modified.EDB PostgreSQL Advanced Server DB Audit v2r3PostgreSQLDB

AUDIT AND ACCOUNTABILITY

RHEL-08-020032 - RHEL 8 must disable the user list at logon for graphical user interfaces.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-10-700840 - RHEL 10 must disable the user list at login for graphical user interfaces.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

SHPT-00-000640 - Applications must support organizational requirements to employ cryptographic mechanisms to protect information in storage.DISA STIG SharePoint 2010 v1r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SPLK-CL-000235 - Splunk Enterprise must notify analysts of applicable events for Tier 2 CSSP and JRSS only.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

ACCESS CONTROL

TCAT-AS-000970 - Idle timeout for the management application must be set to 10 minutes.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

TCAT-AS-001680 - ALLOW_BACKSLASH must be set to false.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG040 A22 - Public web server resources must not be shared with private assets.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG040 A22 - Public web server resources must not be shared with private assets.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WN12-AD-000009-DC - The directory server supporting (directly or indirectly) system access or resource authorization must run on a machine dedicated to that function - ServicesDISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN22-DC-000130 - Windows Server 2022 domain controllers must run on a machine dedicated to that function.DISA Microsoft Windows Server 2022 STIG v2r10Windows

CONFIGURATION MANAGEMENT