Item Search

NameAudit NamePluginCategory
2.1.18 Ensure web server services are not in useCIS Oracle Linux 9 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.1.18 Ensure web server services are not in useCIS Oracle Linux 9 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.1.18 Ensure web server services are not in useCIS AlmaLinux OS 9 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.1.18 Ensure web server services are not in useCIS AlmaLinux OS 9 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.1.19 Ensure web server services are not in useCIS Red Hat Enterprise Linux 8 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.2.18 Ensure web server services are not in useCIS Oracle Linux 7 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.2.18 Ensure web server services are not in useCIS Red Hat Enterprise Linux 7 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.2.18 Ensure web server services are not in useCIS Amazon Linux 2 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.2.18 Ensure web server services are not in useCIS CentOS Linux 7 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.2.18 Ensure web server services are not in useCIS CentOS Linux 7 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.11 Ensure 'encryption providers' are locked downCIS IIS 8.0 v1.5.1 Level 2Windows

ACCESS CONTROL

4.1.2 Ensure a trusted certificate and trust chain is installedCIS NGINX v3.0.0 L1 ProxyUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.2 Ensure a trusted certificate and trust chain is installedCIS NGINX v3.0.0 L1 WebserverUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.2 Ensure a trusted certificate and trust chain is installedCIS NGINX v3.0.0 L1 LoadbalancerUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.7 Ensure Unlisted File Extensions are not allowedCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

AS24-U1-000210 - The log data and records from the Apache web server must be backed up onto a different system or media.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

SYSTEM AND INFORMATION INTEGRITY

AS24-U1-000820 - The Apache web server must be protected from being stopped by a non-privileged userDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000360 - The Apache web server must be configured to use a specified IP address and port.DISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix

CONFIGURATION MANAGEMENT

AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

AS24-W1-000210 - The log data and records from the Apache web server must be backed up onto a different system or media.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000360 - The Apache web server must be configured to use a specified IP address and portDISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000360 - The Apache web server must be configured to use a specified IP address and port - IP or Port OnlyDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000360 - The Apache web server must be configured to use a specified IP address and port - Zero IPs OnlyDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000370 - The Apache web server must encrypt passwords during transmission.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

IDENTIFICATION AND AUTHENTICATION

AS24-W1-000370 - The Apache web server must encrypt passwords during transmission.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

IDENTIFICATION AND AUTHENTICATION

AS24-W1-000480 - The Apache web server must accept only system-generated session identifiers.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

IDENTIFICATION AND AUTHENTICATION

ESXI-80-000238 - The ESXi host must require TPM-based configuration encryption.DISA VMware vSphere 8.0 ESXi STIG v2r4 UnixUnix

CONFIGURATION MANAGEMENT

GEN002860 - Audit logs must be rotated daily.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

IIST-SV-000131 - IIS 10.0 Web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SV-000131 - IIS 8.5 Web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

OH12-1X-000240 - OHS must have the LoadModule ossl_module directive enabled to encrypt passwords during transmission.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

IDENTIFICATION AND AUTHENTICATION

OH12-1X-000241 - OHS must use FIPS modules to encrypt passwords during transmission.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

IDENTIFICATION AND AUTHENTICATION

OH12-1X-000242 - OHS must have the SSLEngine, SSLProtocol, and SSLWallet directives enabled and configured to encrypt passwords during transmission - SSLProtocolDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

IDENTIFICATION AND AUTHENTICATION

OH12-1X-000242 - OHS must have the SSLEngine, SSLProtocol, and SSLWallet directives enabled and configured to encrypt passwords during transmission - SSLWalletDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

IDENTIFICATION AND AUTHENTICATION

OH12-1X-000243 - OHS must have the SSLCipherSuite directive enabled to encrypt passwords during transmission.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

IDENTIFICATION AND AUTHENTICATION

OH12-1X-000353 - Debugging and trace information used to diagnose OHS must be disabled.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND INFORMATION INTEGRITY

VCEM-80-000136 - The vCenter ESX Agent Manager service debug parameter must be disabled.DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2Unix

CONFIGURATION MANAGEMENT

VCUI-80-000136 - The vCenter UI service debug parameter must be disabled.DISA VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v2r2Unix

CONFIGURATION MANAGEMENT

VCUI-80-000136 The vCenter UI service debug parameter must be disabled.DISA VMware vSphere 8.0 vCenter Appliance User Interface (UI) STIG v2r1Unix

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Internet Data Connector Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WG050 A22 - The web server password(s) must be entrusted to the SA or Web Manager.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

ACCESS CONTROL

WG255 IIS6 - Access to the web site log files must be restricted.DISA STIG IIS 6.0 Site Checklist v6r16Windows

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

WG385 IIS6 - All web server documentation, sample code, example applications, and tutorials must be removed. - 'Inetpub\AdminScripts'DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT

WG385 IIS6 - All web server documentation, sample code, example applications, and tutorials must be removed. - 'Inetpub\Iissamples'DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT