Item Search

NameAudit NamePluginCategory
DG0187-ORACLE11 - DBMS software libraries should be periodically backed up - '$ORACLE_BASE files are being backed up'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONTINGENCY PLANNING

OL08-00-010020 - OL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010050 - OL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010140 - OL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010141 - OL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must have a unique name for the grub superusers account when booting into single-user mode and maintenance.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010149 - OL 8 operating systems booted with a BIOS must have a unique name for the grub superusers account when booting into single-user and maintenance modes.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010159 - The OL 8 "pam_unix.so" module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010181 - OL 8 must implement a FIPS 140-3-compliant systemwide cryptographic policy.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010182 - OL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010185 - The OL 8 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-010250 - The OL 8 "/var/log" directory must be owned by root.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010292 - The OL 8 SSH server must be configured to use strong entropy.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010300 - OL 8 system commands must have mode 755 or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010320 - OL 8 system commands must be group-owned by root or a system account.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010370 - YUM must be configured to prevent the installation of patches, service packs, device drivers, or OL 8 system components that have not been digitally signed using a certificate that is recognized and approved by the organization.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010379 - OL 8 must specify the default "include" directory for the /etc/sudoers file.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010400 - OL 8 must implement certificate status checking for multifactor authentication.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010410 - OL 8 must accept Personal Identity Verification (PIV) credentials.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010424 - OL 8 must not let Meltdown and Spectre exploit critical vulnerabilities in modern processors.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010430 - OL 8 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010570 - OL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010580 - OL 8 must prevent special devices on nonroot local partitions.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010590 - OL 8 file systems that contain user home directories must not execute binary files.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010600 - OL 8 file systems must not interpret character or block special devices from untrusted file systems.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010672 - OL 8 must disable acquiring, saving, and processing core dumps.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010720 - All OL 8 local interactive users must have a home directory assigned in the "/etc/passwd" file.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010741 - OL 8 must be configured so that all files and directories contained in local interactive user home directories are group-owned by a group of which the home directory owner is a member.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-010770 - All OL 8 local initialization files must have mode "0740" or less permissive.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-020012 - OL 8 systems below version 8.2 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020018 - OL 8 systems below version 8.2 must prevent system messages from being presented when three unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020020 - OL 8 systems below version 8.2 must log user name information when unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020021 - OL 8 systems, versions 8.2 and above, must log user name information when unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020060 - OL 8 must automatically lock graphical user sessions after 15 minutes of inactivity.DISA Oracle Linux 8 STIG v2r8Unix

ACCESS CONTROL

OL08-00-020180 - OL 8 passwords for new users or password changes must have a 24 hours/one day minimum password lifetime restriction in "/etc/shadow".DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020290 - OL 8 must prohibit the use of cached authentications after one day.DISA Oracle Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020320 - OL 8 must not have unnecessary accounts.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040124 - OL 8 must mount "/tmp" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040159 - All OL 8 networked systems must have SSH installed.DISA Oracle Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-040170 - The x86 Ctrl-Alt-Delete key sequence must be disabled on OL 8.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040180 - OL 8 must disable the debug-shell systemd service.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040230 - OL 8 must not respond to Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040240 - OL 8 must not forward IPv6 source-routed packets.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040259 - OL 8 must not enable IPv4 packet forwarding unless the system is a router.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040261 - OL 8 must not accept router advertisements on all IPv6 interfaces.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040282 - OL 8 must restrict the use of "ptrace" to descendant processes.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040320 - The graphical display manager must not be installed on OL 8 unless approved.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040330 - OL 8 network interfaces must not be in promiscuous mode.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040340 - OL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040341 - The OL 8 SSH daemon must prevent remote hosts from connecting to the proxy display.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

OL08-00-040380 - OL 8 must not have the "iprutils" package installed if not required for operational support.DISA Oracle Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT