Item Search

NameAudit NamePluginCategory
6.3.1.4 Ensure auditd service is enabled and activeCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.3.1.4 Ensure auditd service is enabled and activeCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

DG0005-ORACLE11 - Only necessary privileges to the host system should be granted to DBA OS accounts - 'ORA_DBA Group has no unauthorized users'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DG0017-ORACLE11 - A production DBMS installation should not coexist on the same DBMS host with other, non-production DBMS installations - 'All Oracle instances are documented and approved'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0070-ORACLE11 - Unauthorized user accounts should not exist.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

DG0099-ORACLE11 - Access to external DBMS executables should be disabled or restricted - '%ORACLE_HOME%\bin\extproc.exe does not exist'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0099-ORACLE11 - Access to external DBMS executables should be disabled or restricted - '$ORACLE_HOME/bin/extproc does not exist'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0099-ORACLE11 - Access to external DBMS executables should be disabled or restricted - '$ORACLE_HOME/network/admin/tnsnames.ora EXTPROC PROTOCOL=IPC'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0099-ORACLE11 - Access to external DBMS executables should be disabled or restricted - no PROGRAMS = EXTPROC' - tnsnames.oraDISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0152-ORACLE11 - DBMS network communications should comply with PPS usage restrictions - 'Connection Manager is running on approved ports'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0152-ORACLE11 - DBMS network communications should comply with PPS usage restrictions - PORT = 1521, 1575, 1830, 2481, 2482, 2483 or 2484' - cman.oraDISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0191-ORACLE11 - Credentials used to access remote databases should be protected by encryption and restricted to authorized users - '%ORACLE_HOME%\database\PWDorcl.ora permissions are correct'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0195-ORACLE11 - DBMS production application and data directories should be protected from developers on shared production/development DBMS host systems - 'root is not a mamber of the oracle group'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

ACCESS CONTROL

DO5037-ORACLE11 - Oracle SQLNet and listener log files should not be accessible to unauthorized users - '%ORACLE_HOME%\NETWORK\ADMIN\listener.ora LOG_DIRECTORY_{listener} is configured'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

AUDIT AND ACCOUNTABILITY

DO5037-ORACLE11 - Oracle SQLNet and listener log files should not be accessible to unauthorized users - '%ORACLE_HOME%\NETWORK\ADMIN\listener.ora LOG_FILE_{listener} is configured'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

AUDIT AND ACCOUNTABILITY

DO6740-ORACLE11 - The Oracle Listener ADMIN_RESTRICTIONS parameter if present should be set to ON - '$ORACLE_HOME/network/admin/listener.ora ADMIN_RESTRICTIONS_{listener} = on'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI039 - Navigating windows and frames across different domains must be disallowed (Internet zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

ACCESS CONTROL

DTBI044 - Clipboard operations via script must be disallowed (Internet zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI091 - The Java Permissions must be set with High Safety (Trusted Sites zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI119 - File downloads must be disallowed (Restricted Site zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI126 - Functionality to drag and drop or copy and paste files must be disallowed (Restricted Sites zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI136 - Logon options must be configured and enforced (Restricted Sites zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI450 - Java permissions must be disallowed (Locked Down Restricted Sites zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI630 - Internet Explorer Processes for Restrict File Download must be enforced (Reserved).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI635 - Internet Explorer Processes for Restrict File Download must be enforced (Explorer).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI647 - Internet Explorer Processes for restricting pop-up windows must be enforced (Explorer).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI755 - Browser Geolocation functionality must be disallowed.DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI760 - Browser must retain history on exit.DISA STIG Microsoft Internet Explorer 9 v1r15Windows

ACCESS CONTROL

DTBI810 - When uploading files to a server, the local directory path must be excluded (Internet zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI825 - Internet Explorer Processes for notification bars must be enforced (Explorer).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

DTBI835 - Internet Explorer Processes for notification bars must be enforced (IExplore).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

WA000-WI030 IIS6 - The IUSR_machinename account must not have read access to the .inc files or their equivalent. - 'global.asa'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI6028 IIS6 - The Shutdown worker processes Idle Timeout monitor must be enabled.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6080 IIS6 - The AllowRestrictedChars registry key must be disabled.DISA STIG IIS 6.0 Server v6r16Windows

SYSTEM AND INFORMATION INTEGRITY

WA000-WI6092 IIS6 - The PercentUAllowed registry entry must be set properly.DISA STIG IIS 6.0 Server v6r16Windows

SYSTEM AND INFORMATION INTEGRITY

WA000-WI6098 IIS6 - The MaxRequestEntityAllowed metabase value must be defined. - 'IisWebFileSetting'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WA00605 A22 - Error logging must be enabled.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WA00605 W22 - Error logging must be enabled.DISA STIG Apache Site 2.2 Windows v1r13Windows

AUDIT AND ACCOUNTABILITY

WG080 IIS6 - A compiler must not be installed on a production web server. - 'Lcc-win32.exe search'DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT

WG080 IIS6 - A compiler must not be installed on a production web server. - 'msc.exe search'DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT

WG140 IIS6 - A private web sites authentication mechanism must use client certificates. - 'AccessSSLRequireCert Enabled'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG145 IIS6 - The private web server must use an approved DoD certificate validation process. - 'Check W3SVC CertCheckMode'DISA STIG IIS 6.0 Site Checklist v6r16Windows

IDENTIFICATION AND AUTHENTICATION

WG205 A22 - The web document (home) directory must be in a separate partition from the web server's system files.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG205 W22 - The web document (home) directory must be in a separate partition from the web server's system files. - 'ErrorLog'DISA STIG Apache Site 2.2 Windows v1r13Windows

AUDIT AND ACCOUNTABILITY

WG210 A22 - Web content directories must not be anonymously shared.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

ACCESS CONTROL

WG242 W22 - Log file data must contain required data elements.DISA STIG Apache Site 2.2 Windows v1r13Windows

AUDIT AND ACCOUNTABILITY

WG310 A22 - A web site must not contain a robots.txt file - aliasDISA STIG Apache Site 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG310 W22 - A web site must not contain a robots.txt file. - 'DocumentRoot'DISA STIG Apache Site 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG340 A22 - A private web server must utilize an approved TLS version - SSLProtocolDISA STIG Apache Site 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WG342 IIS6 - Public web servers must use TLS if authentication is required. - '128-Bit Encryption Enabled'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION