Item Search

NameAudit NamePluginCategory
AZLX-23-000130 - Amazon Linux 2023 must be a vendor-supported release.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND INFORMATION INTEGRITY

ESXI-67-000015 - The ESXi host SSH daemon must not allow authentication using an empty password.DISA STIG VMware vSphere 6.7 ESXi OS v1r3Unix

CONFIGURATION MANAGEMENT

ESXI-67-000060 - The virtual switch MAC Address Change policy must be set to reject on the ESXi host.DISA STIG VMware vSphere 6.7 ESXi v1r3VMware

CONFIGURATION MANAGEMENT

ESXI-67-000071 - The SA must verify the integrity of the installation media before installing ESXi.DISA STIG VMware vSphere 6.7 ESXi v1r3VMware

CONFIGURATION MANAGEMENT

ESXI-80-000217 - The ESXi host must configure virtual switch security policies to reject Media Access Control (MAC) address changes.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

CONFIGURATION MANAGEMENT

ESXI-80-000221 - The ESXi host must have all security patches and updates installed.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

CONFIGURATION MANAGEMENT

KNOX-07-003000 - The Samsung must be configured to enable encryption for information at rest on removable storage media.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

MD7X-00-009300 - MongoDB products must be a supported version.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 UnixUnix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010121 - The OL 8 operating system must not have accounts configured with blank or null passwords.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010150 - OL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010830 - OL 8 must not allow users to override SSH environment variables.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020331 - OL 8 must not allow blank or null passwords in the system-auth file.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040010 - OL 8 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL09-00-002161 - OL 9 must not allow unattended or automatic logon via the graphical user interface.DISA Oracle Linux 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

PHTN-40-000188 - The Photon operating system must configure Secure Shell (SSH) to disallow HostbasedAuthentication.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r1Unix

CONFIGURATION MANAGEMENT

Restricting access to the Configuration utility by source IP addressTenable F5 BIG-IP Best Practice AuditF5

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-010030 - All RHEL 8 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-020332 - RHEL 8 must not allow blank or null passwords in the password-auth file.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040000 - RHEL 8 must not have the telnet-server package installed.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-09-212020 - RHEL 9 must require a unique superusers name upon booting into single-user and maintenance modes.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-255050 - RHEL 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

MAINTENANCE

RHEL-09-411100 - The root account must be the only account having unrestricted access to RHEL 9 system.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-10-600560 - RHEL 10 must require users to provide a password for privilege escalation.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010035 - The SUSE operating system must have the crypto-policies package installed.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010190 - SUSE operating systems with a basic input/output system (BIOS) must require authentication upon booting into single-user and maintenance modes.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010200 - SUSE operating systems with Unified Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010510 - FIPS 140-2 mode must be enabled on the SUSE operating system.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-020100 - The SUSE operating system root account must be the only account with unrestricted access to the system.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-020181 - The SUSE operating system must not have accounts configured with blank or null passwords.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SLES-15-020300 - The SUSE operating system must not be configured to allow blank or null passwords.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SLES-15-040020 - There must be no .shosts files on the SUSE operating system.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040060 - The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SLES-15-040061 - The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence for Graphical User Interfaces.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SPLK-CL-000430 - Splunk Enterprise must use TLS 1.2 and SHA-2 or higher cryptographic algorithms.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000440 - Symantec ProxySG must terminate all network connections associated with a communications session at the end of the session or terminate user sessions (nonprivileged session) after 15 minutes of inactivity.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

SYMP-NM-000220 - Symantec ProxySG must use only approved management services protocols.DISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

CONFIGURATION MANAGEMENT

SYMP-NM-000320 - Symantec ProxySG must enable Attack Detection.DISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-211000 - Ubuntu 22.04 LTS must be a vendor-supported release.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-211015 - Ubuntu 22.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-215030 - Ubuntu 22.04 LTS must not have the "rsh-server" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-24-300025 - Ubuntu 24.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence if a graphical user interface is installed.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

CONFIGURATION MANAGEMENT

UBTU-24-300027 - Ubuntu 24.04 LTS must not have accounts configured with blank or null passwords.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

CONFIGURATION MANAGEMENT

UBTU-24-600030 - Ubuntu 24.04 LTS must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCPG-67-000012 - VMware Postgres must require authentication on all connections.DISA STIG VMware vSphere 6.7 PostgreSQL v1r2Unix

IDENTIFICATION AND AUTHENTICATION

VCPG-67-000999 - The version of PostgreSQL running on the system must be a supported version.DISA STIG VMware vSphere 6.7 PostgreSQL v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

WN11-00-000045 - The Windows 11 system must use an antivirus program.DISA Microsoft Windows 11 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN11-00-000240 - Administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.DISA Microsoft Windows 11 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN11-CC-000345 - The Windows Remote Management (WinRM) service must not use Basic authentication.DISA Microsoft Windows 11 STIG v2r8Windows

MAINTENANCE

ZEBR-10-010800 - Zebra Android 10 devices must have the latest available Zebra Android 10 operating system installed.MobileIron - DISA Zebra Android 10 COPE v1r2MDM

CONFIGURATION MANAGEMENT

ZEBR-10-999999 - All Zebra Android 10 installations must be removed.AirWatch - DISA Zebra Android 10 COBO v1r2MDM

CONFIGURATION MANAGEMENT