Item Search

NameAudit NamePluginCategory
1.14 IIST-SI-000221CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.16 CISC-ND-000470CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

CONFIGURATION MANAGEMENT

1.25 CISC-ND-000720CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.35 SQLI-22-009600CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDBMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.43 CISC-ND-001470CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

CONFIGURATION MANAGEMENT

1.65 EX19-ED-000235CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.69 CISC-RT-000680CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT ICisco

CONFIGURATION MANAGEMENT

1.75 CISC-RT-000730CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT ICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.78 SQLI-22-018100CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

1.79 SQLI-22-018300CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDBMS_SQLDB

SYSTEM AND SERVICES ACQUISITION

1.139 WN16-CC-000500CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IWindows

MAINTENANCE

1.142 WN16-CC-000530CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IWindows

MAINTENANCE

1.180 RHEL-09-252070CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.207 WN16-SO-000020CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IWindows

CONFIGURATION MANAGEMENT

1.211 RHEL-09-255050CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IUnix

MAINTENANCE

ALMA-09-045125 - AlmaLinux OS 9 must be a supported release.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-14-999999 - The macOS system must be a version supported by the vendor.DISA Apple macOS 14 Sonoma STIG v2r4Unix

SYSTEM AND SERVICES ACQUISITION

CASA-VN-000760 - The Cisco ASA VPN remote access server must be configured to use an approved High Assurance Commercial Solution for Classified (CSfC) cryptographic algorithm for remote access to a classified network.DISA STIG Cisco ASA VPN v2r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-R2-000160 - The Kubernetes API server must have anonymous authentication disabled.DISA Rancher Government Solutions RKE2 STIG v2r7Unix

ACCESS CONTROL

EDGE-00-000045 - The version of Microsoft Edge running on the system must be a supported version.DISA Microsoft Edge STIG v2r5Windows

SYSTEM AND INFORMATION INTEGRITY

FNFG-FW-000005 - The FortiGate firewall must use filters that use packet headers and packet attributes, including source and destination IP addresses and ports.DISA Fortigate Firewall STIG v1r4FortiGate

ACCESS CONTROL

FNFG-FW-000060 - The FortiGate firewall must protect the traffic log from unauthorized deletion of local log files and log records.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

IBMW-LS-000050 - Users in the REST API admin role must be authorized.DISA IBM WebSphere Liberty Server STIG v2r4Unix

ACCESS CONTROL

JUEX-NM-000360 - The Juniper EX switch must be configured to end all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill mission requirements.DISA Juniper EX Series Network Device Management v2r4Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-RT-000950 - The Juniper PE router providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.DISA Juniper EX Series Router v2r1Juniper

CONFIGURATION MANAGEMENT

MD7X-00-004300 - MongoDB must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 UnixUnix

IDENTIFICATION AND AUTHENTICATION

MD7X-00-005200 - MongoDB must protect the confidentiality and integrity of all information at rest.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-007400 - Oracle Database products must be a version supported by the vendor.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

SYSTEM AND SERVICES ACQUISITION

O19C-00-015500 - Oracle Database must use NIST-validated FIPS 140-2/140-3 compliant cryptography for authentication mechanisms.DISA Oracle Database 19c STIG v1r5 UnixUnix

IDENTIFICATION AND AUTHENTICATION

O19C-00-015500 - Oracle Database must use NIST-validated FIPS 140-2/140-3 compliant cryptography for authentication mechanisms.DISA Oracle Database 19c STIG v1r5 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

O19C-00-016000 - Oracle Database must implement NIST FIPS 140-2/140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owner's requirements.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-016800 - Oracle Database must take steps to protect data at rest and ensure confidentiality and integrity of application data.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-010000 - RHEL 8 must be a vendor-supported release.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010140 - RHEL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-08-010470 - There must be no .shosts files on the RHEL 8 operating system.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-020331 - RHEL 8 must not allow blank or null passwords in the system-auth file.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040190 - The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040360 - A File Transfer Protocol (FTP) server package must not be installed unless mission essential on RHEL 8.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-10-700720 - RHEL 10 must not allow unattended or automatic login via the graphical user interface.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

SLES-15-040440 - The SUSE operating system must not allow unattended or automatic logon via SSH.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SQLI-22-009500 - SQL Server must protect the confidentiality and integrity of all information at rest.DISA Microsoft SQL Server 2022 Instance STIG v1r4 MS_SQLDBMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

SQLI-22-009600 - The Service Master Key must be backed up and stored in a secure location that is not on the SQL Server.DISA Microsoft SQL Server 2022 Instance STIG v1r4 MS_SQLDBMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-212010 - Ubuntu 22.04 LTS, when booted, must require authentication upon booting into single-user and maintenance modes.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-255025 - Ubuntu 22.04 LTS must not allow unattended or automatic login via SSH.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-432015 - Ubuntu 22.04 LTS must ensure only users who need access to security functions are part of sudo group.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-671010 - Ubuntu 22.04 LTS must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-24-300022 - Ubuntu 24.04 LTS must be configured so that remote X connections are disabled, unless to fulfill documented and validated mission requirements.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

CONFIGURATION MANAGEMENT

WN11-SO-000165 - Anonymous access to Named Pipes and Shares must be restricted.DISA Microsoft Windows 11 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000205 - The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.DISA Microsoft Windows 11 STIG v2r8Windows

CONFIGURATION MANAGEMENT

ZEBR-11-010800 - Zebra Android 11 devices must have the latest available Zebra Android 11 operating system installed.AirWatch - DISA Zebra Android 11 COBO STIG v1r4MDM

CONFIGURATION MANAGEMENT