Item Search

NameAudit NamePluginCategory
1.2 Ensure 'host headers' are on all sitesCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

1.2 Ensure 'host headers' are on all sitesCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

2.1 Ensure 'global authorization rule' is set to restrict accessCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, MEDIA PROTECTION

2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.24 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.24 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.24 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

ACCESS CONTROL

2.2.36 Ensure 'Replace a process level token' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

IDENTIFICATION AND AUTHENTICATION

3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely - DefaultCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND SERVICES ACQUISITION

4.4 Ensure http server is not runningCIS Apple OSX 10.9 L1 v1.3.0Unix

CONFIGURATION MANAGEMENT

4.8 Ensure Handler is not granted Write and Script/Execute - ApplicationsCIS IIS 7 L1 v1.8.0Windows

ACCESS CONTROL

4.11 Ensure 'Dynamic IP Address Restrictions' is enabled - Deny By Conccurent RequestsCIS IIS 7 L1 v1.8.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.11 Ensure 'Dynamic IP Address Restrictions' is enabled - Deny By Request RateCIS IIS 7 L1 v1.8.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.11 Ensure 'Dynamic IP Address Restrictions' is enabled - Not Logging Only ModeCIS IIS 7 L1 v1.8.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

5.3 Ensure 'ETW Logging' is enabledCIS IIS 10 v1.2.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

5.3 Ensure 'ETW Logging' is enabled - Sites logFormat W3CCIS IIS 10 v1.2.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

5.3 Ensure 'ETW Logging' is enabled - Sites logFormat W3C with ETW targetCIS IIS 10 v1.2.1 Level 1Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000130 - An Apache web server, behind a load balancer or proxy server, must produce log records containing the client IP information as the source and destination and not the load balancer or proxy IP information with each event.DISA STIG Apache Server 2.4 Windows Server v3r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000130 - An Apache web server, behind a load balancer or proxy server, must produce log records containing the client IP information as the source and destination and not the load balancer or proxy IP information with each event.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

CIS Microsoft IIS 8 Benchmark v1.5.1 Level 1CIS IIS 8.0 v1.5.1 Level 1Windows
CIS Microsoft IIS 8 Benchmark v1.5.1 Level 2CIS IIS 8.0 v1.5.1 Level 2Windows
DISA_IIS_6.0_Web_Site_v6r16.audit from DISA Microsoft IIS 6.0 Site v6r16 STIGDISA STIG IIS 6.0 Site Checklist v6r16Windows
DISA_STIG_IIS_10.0_Web_Site_v2r14.audit from DISA Microsoft IIS 10.0 Site v2r14 STIGDISA IIS 10.0 Site v2r14Windows
DISA_STIG_MSSQL_2012_Database_v1r20.audit from DISA Microsoft SQL Server Instance 2012 v1r20 STIGDISA STIG SQL Server 2012 Database Audit v1r20MS_SQLDB
EX16-ED-000570 - Exchange must render hyperlinks from email sources from non-.mil domains as unclickable.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-ED-000122 - Active hyperlinks in messages from non .mil domains must be rendered unclickable.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

GEN000100 - The operating system must be a supported release.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN002860 - Audit logs must be rotated daily.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN002860 - Audit logs must be rotated daily.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

IIST-SI-000215 - Mappings to unused and vulnerable scripts on the IIS 10.0 website must be removed.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.DISA IIS 10.0 Server v3r6Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000148 - The IIS 10.0 web server must not be running on a system providing any other role.DISA IIS 10.0 Server v3r6Windows

CONFIGURATION MANAGEMENT

IIST-SV-000148 - The IIS 10.0 web server must not be running on a system providing any other role.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000200 - The IIS 10.0 websites MaxConnections setting must be configured to limit the number of allowed simultaneous session requests.DISA IIS 10.0 Server v2r10Windows

ACCESS CONTROL

IIST-SV-000200 - The IIS 10.0 websites MaxConnections setting must be configured to limit the number of allowed simultaneous session requests.DISA IIS 10.0 Server v3r6Windows

ACCESS CONTROL

IISW-SI-000215 - Mappings to unused and vulnerable scripts on the IIS 8.5 website must be removed.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 8.5 web server must be enabled.DISA IIS 8.5 Server v2r7Windows

AUDIT AND ACCOUNTABILITY

IISW-SV-000148 - The IIS 8.5 web server must not be running on a system providing any other role.DISA IIS 8.5 Server v2r7Windows

CONFIGURATION MANAGEMENT

IISW-SV-000200 - The IIS 8.5 MaxConnections setting must be configured to limit the number of allowed simultaneous session requests.DISA IIS 8.5 Server v2r7Windows

ACCESS CONTROL

SP13-00-000015 - SharePoint must utilize approved cryptography to protect the confidentiality of remote access sessions.DISA Microsoft SharePoint 2013 STIG v2r4Windows

ACCESS CONTROL

SP13-00-000020 - SharePoint must use cryptography to protect the integrity of the remote access session.DISA Microsoft SharePoint 2013 STIG v2r4Windows

ACCESS CONTROL

SP13-00-000120 - SharePoint must maintain the confidentiality of information during aggregation, packaging, and transformation in preparation for transmission. When transmitting data, applications need to leverage transmission protection mechanisms such as TLS, SSL VPNs, or IPSec.DISA Microsoft SharePoint 2013 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SP13-00-000135 - SharePoint must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission, unless the transmitted data is otherwise protected by alternative physical measures.DISA Microsoft SharePoint 2013 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Index Server Web Interface Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6010 IIS6 - The web site must have a unique application pool.DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG130 IIS6 - Programs and features not necessary for operations must be removed.DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT

WG130 W22 - All utility programs, not necessary for operations, must be removed or disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG520 W22 - Web server and/or operating system information must be protected.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT