Item Search

NameAudit NamePluginCategory
1.10 Ensure 'Install unknown apps' is set to 'Disabled'MobileIron - CIS Google Android v1.6.0 L1MDM

CONFIGURATION MANAGEMENT

1.44 SOL-11.1-020140CIS Solaris 11 X86 STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.45 RHEL-09-214020CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.62 ALMA-09-009810CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.88 OL09-00-000496CIS Oracle Linux 9 STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

3.4.1.7 Ensure ufw default deny firewall policyCIS Debian Linux 10 v2.0.0 L1 ServerUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.8 Ensure ufw default deny firewall policyCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 ServerUnix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.6.9.1 Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled'CIS Microsoft Intune for Windows 11 v5.0.0 L1Windows

ACCESS CONTROL, CONFIGURATION MANAGEMENT

4.6.9.1 Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

ACCESS CONTROL, CONFIGURATION MANAGEMENT

4.10.9.1.3 Ensure 'Prevent installation of devices using drivers that match these device setup classes: Prevent installation of devices using drivers for these device setup' is set to 'IEEE 1394 device setup classes'CIS Microsoft Intune for Windows 11 v5.0.0 BLWindows

SYSTEM AND INFORMATION INTEGRITY

4.10.9.1.6 Ensure 'Prevent installation of devices using drivers that match these device setup classes: Prevent installation of devices using drivers for these device setup' is set to 'IEEE 1394 device setup classes'CIS Microsoft Intune for Windows 10 v5.0.0 BLWindows

SYSTEM AND INFORMATION INTEGRITY

6.2.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Debian Linux 12 v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Ubuntu Linux 24.04 LTS v2.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

18.9.7.1.2 Ensure 'Prevent installation of devices that match any of these device IDs: Prevent installation of devices that match any of these device IDs' is set to 'PCI\CC_0C0A'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

MEDIA PROTECTION

18.9.7.1.2 Ensure 'Prevent installation of devices that match any of these device IDs: Prevent installation of devices that match any of these device IDs' is set to 'PCI\CC_0C0A'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BL NGWindows

MEDIA PROTECTION

AIOS-15-007200 - Apple iOS/iPadOS 15 must not include applications with the following characteristics: access to Siri when the device is locked.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-007300 - Apple iOS/iPadOS 15 allow list must be configured to not include applications with the following characteristics: voice dialing application if available when MD is locked.AirWatch - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-007300 - Apple iOS/iPadOS 15 allow list must be configured to not include applications with the following characteristics: voice dialing application if available when MD is locked.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-007400 - Apple iOS/iPadOS 15 allowlist must be configured to not include applications with the following characteristics: - back up MD data to non-DoD cloud servers (including user and application access to cloud backup services);- transmit MD diagnostic data to non-DoD servers; - allows synchronization of data or applications between devices associated with user; and - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-007400 - Apple iOS/iPadOS 15 allowlist must be configured to not include applications with the following characteristics: - back up MD data to non-DoD cloud servers (including user and application access to cloud backup services);- transmit MD diagnostic data to non-DoD servers; - allows synchronization of data or applications between devices associated with user; and - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-16-007200 - Apple iOS/iPadOS 16 must not include applications with the following characteristics: access to Siri when the device is locked.MobileIron - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-16-007300 - Apple iOS/iPadOS 16 allow list must be configured to not include applications with the following characteristics: allow voice dialing when MD is locked.AirWatch - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-16-007300 - Apple iOS/iPadOS 16 allow list must be configured to not include applications with the following characteristics: allow voice dialing when MD is locked.MobileIron - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-16-007400 - Apple iOS/iPadOS 16 allowlist must be configured to not include applications with the following characteristics: - Backs up MD data to non-DoD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DoD servers; - Allows synchronization of data or applications between devices associated with user; and - Allows unencrypted (or encrypted but not FIPS 140-2/FIPS 140-3 validated) data sharing with other MDs or printers - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-16-007400 - Apple iOS/iPadOS 16 allowlist must be configured to not include applications with the following characteristics: - Backs up MD data to non-DoD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DoD servers; - Allows synchronization of data or applications between devices associated with user; and - Allows unencrypted (or encrypted but not FIPS 140-2/FIPS 140-3 validated) data sharing with other MDs or printers - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.MobileIron - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-007200 - Apple iOS/iPadOS 17 must not include applications with the following characteristics: access to Siri when the device is locked.MobileIron - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

AIOS-17-007400 - Apple iOS/iPadOS 17 allow list must be configured to not include applications with the following characteristics: - backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);- transmits MD diagnostic data to non-DOD servers;- allows synchronization of data or applications between devices associated with user; and- allows unencrypted (or encrypted but not FIPS 140-2/FIPS 140-3 validated) data sharing with other MDs or printers - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-007400 - Apple iOS/iPadOS 17 allow list must be configured to not include applications with the following characteristics: - backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);- transmits MD diagnostic data to non-DOD servers;- allows synchronization of data or applications between devices associated with user; and- allows unencrypted (or encrypted but not FIPS 140-2/FIPS 140-3 validated) data sharing with other MDs or printers - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.MobileIron - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-18-007200 - Apple iOS/iPadOS 18 must not include applications with the following characteristics: access to Siri when the device is locked.MobileIron - DISA Apple iOS/iPadOS 18 v2r3MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-18-007400 - The Apple iOS/iPadOS 18 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DOD servers; - Allows synchronization of data or applications between devices associated with user; - Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers; - Backs up its own data to a remote system; and - Uses artificial intelligence (AI), which processes data in the cloud (off device). Exception: Apple Intelligence Private Cloud Compute (PCC) - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.MobileIron - DISA Apple iOS/iPadOS 18 v2r3MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-18-007400 - The Apple iOS/iPadOS 18 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DOD servers; - Allows synchronization of data or applications between devices associated with user; - Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers; - Backs up its own data to a remote system; and - Uses artificial intelligence (AI), which processes data in the cloud (off device). Exception: Apple Intelligence Private Cloud Compute (PCC) - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Apple iOS/iPadOS 18 v2r3MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-26-007200 - Apple iOS/iPadOS 26 must not include applications with the following characteristics: access to Siri when the device is locked.MobileIron - DISA Apple iOS/iPadOS 26 v1r3MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-26-007400 - Apple iOS/iPadOS 26 allow list must be configured to not include applications with the following characteristicsAirWatch - DISA Apple iOS/iPadOS 26 v1r3MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-26-007400 - Apple iOS/iPadOS 26 allow list must be configured to not include applications with the following characteristicsMobileIron - DISA Apple iOS/iPadOS 26 v1r3MDM

IDENTIFICATION AND AUTHENTICATION

ALMA-09-009810 - AlmaLinux OS 9 must check the GPG signature of locally installed software packages before installation.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

CIS_Red_Hat_Enterprise_Linux_7_v4.0.0_L1_Server.audit from CIS Red Hat Enterprise Linux 7 v4.0.0CIS Red Hat Enterprise Linux 7 v4.0.0 L1 ServerUnix
CIS_Red_Hat_Enterprise_Linux_8_v4.0.0_L1_Server.audit from CIS Red Hat Enterprise Linux 8 v4.0.0CIS Red Hat Enterprise Linux 8 v4.0.0 L1 ServerUnix
CIS_Red_Hat_Enterprise_Linux_8_v4.0.0_L1_Workstation.audit from CIS Red Hat Enterprise Linux 8 v4.0.0CIS Red Hat Enterprise Linux 8 v4.0.0 L1 WorkstationUnix
CIS_Red_Hat_Enterprise_Linux_9_v2.0.0_L2_Workstation.audit from CIS Red Hat Enterprise Linux 9 v2.0.0CIS Red Hat Enterprise Linux 9 v2.0.0 L2 WorkstationUnix
DTAVSEL-003 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x must be configured to enable On-Access scanning.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

O112-BP-024200 - Use of the DBMS installation account must be logged.DISA STIG Oracle 11.2g v2r5 DatabaseOracleDB

CONFIGURATION MANAGEMENT

OL6-00-000009 - The Red Hat Network Service (rhnsd) service must not be running, unless it is being used to query the Oracle Unbreakable Linux Network for updates and information - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000009 - The Red Hat Network Service (rhnsd) service must not be running, unless it is being used to query the Oracle Unbreakable Linux Network for updates and information - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL09-00-000496 - OL 9 must check the GPG signature of locally installed software packages before installation.DISA Oracle Linux 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

RHEL-07-040340 - The Red Hat Enterprise Linux operating system must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-214020 - RHEL 9 must check the GPG signature of locally installed software packages before installation.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020140 - The TFTP service daemon must not be installed unless required.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020140 - The TFTP service daemon must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-100010 - The /etc/zones directory, and its contents, must have the vendor default owner, group, and permissions.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

VM : disable-monitor-controlVMWare vSphere 5.X Hardening GuideVMware

CONFIGURATION MANAGEMENT