Item Search

NameAudit NamePluginCategory
1.3 Ensure 'Directory browsing' is set to DisabledCIS IIS 10 v1.2.1 Level 1Windows

CONFIGURATION MANAGEMENT

1.38 IIST-SI-000258CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

2.2.10 Ensure HTTP server is not enabledCIS Debian 9 Server L1 v1.0.1Unix

CONFIGURATION MANAGEMENT

2.2.10 Ensure HTTP server is not enabledCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

2.2.10 Ensure HTTP server is not enabledCIS SUSE Linux Enterprise Server 11 L1 v2.1.1Unix

CONFIGURATION MANAGEMENT

2.2.10 Ensure HTTP server is not enabledCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

CONFIGURATION MANAGEMENT

2.2.22 Ensure 'Generate security audits' is set to 'LOCAL SERVICE, NETWORK SERVICE'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL NGWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.3 Ensure 'forms authentication' require SSL - ApplicationsCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.3 Ensure 'forms authentication' require SSL - DefaultCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.1.2.1 Ensure 'sameSiteCookie' attribute is set to 'Strict'CIS IBM WebSphere Liberty v1.0.0 L1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

4.1.3.1 Ensure 'samesite' SameSite attribute is set to 'Strict' for additional cookiesCIS IBM WebSphere Liberty v1.0.0 L1Unix

CONFIGURATION MANAGEMENT

4.2 Ensure 'maxURL request filter' is configured - ApplicationsCIS IIS 10 v1.2.1 Level 2Windows

SYSTEM AND SERVICES ACQUISITION

4.2 Ensure 'maxURL request filter' is configured - DefaultCIS IIS 10 v1.2.1 Level 2Windows

SYSTEM AND SERVICES ACQUISITION

6.2 (L2) Ensure 'Enable JavaScript' is 'Disabled'CIS MacOS Safari v2.0.0 L2Unix

CONFIGURATION MANAGEMENT

7.14 Ensure TLS Cipher Suite ordering is configuredCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

7.15 Ensure TLS Cipher Suite ordering is configuredCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

8.1.16 Set 'Only allow approved domains to use ActiveX controls without prompt' to 'Enabled:Enable'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

8.3.20 Set 'Only allow approved domains to use ActiveX controls without prompt' to 'Enabled:Enable'CIS IE 9 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

BIND-9X-001360 - The BIND 9.x server implementation must prohibit the forwarding of queries to servers controlled by organizations outside of the U.S. government.DISA BIND 9.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

CIS_Microsoft_IIS_10.0_Site_STIG_v1.0.0_CAT_I.audit from CIS Microsoft IIS 10.0 Site STIG v1.0.0CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IWindows
CIS_Microsoft_IIS_10.0_Site_STIG_v1.0.0_CAT_II.audit from CIS Microsoft IIS 10.0 Site STIG v1.0.0CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows
DISA_STIG_Apache_Site-2.4_Unix_v2r6_Middleware.audit from DISA Apache Server 2.4 UNIX Site v2r6 STIGDISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix
DTBI039 - Navigating windows and frames across different domains must be disallowed (Internet zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

ACCESS CONTROL

DTBI129 - Navigating windows and frames across different domains must be disallowed (Restricted Sites zone).DISA STIG Microsoft Internet Explorer 9 v1r15Windows

ACCESS CONTROL

IIST-SV-000115 - The log information from the IIS 10.0 web server must be protected from unauthorized modification or deletion.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000119 - The IIS 10.0 web server must not be both a website server and a proxy server.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IIST-SV-000119 - The IIS 10.0 web server must not be both a website server and a proxy server.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000132 - The IIS 10.0 web server must separate the hosted applications from hosted web server management functionality.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000132 - The IIS 10.0 web server must separate the hosted applications from hosted web server management functionality.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000139 - The IIS 10.0 web server Indexing must only index web content.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IIST-SV-000220 - The Request Smuggling filter must be enabled.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IISW-SV-000132 - The IIS 8.5 web server must separate the hosted applications from hosted web server management functionality.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SV-000139 - The IIS 8.5 web server Indexing must only index web content.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SV-000156 - All accounts installed with the IIS 8.5 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 8.5 Server v2r7Windows

CONFIGURATION MANAGEMENT

JUEX-NM-000490 - The Juniper EX switch must use an an NTP service that is hosted by a trusted source or a DOD-compliant enterprise or local NTP server.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

OH12-1X-000229 - The OHS DocumentRoot directory must be in a separate partition from the OHS ServerRoot directory.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000230 - The OHS DocumentRoot directory must be on a separate partition from OS root partition.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

SHPT-00-000760 - SharePoint must implement security functions as largely independent modules to avoid unnecessary interactions between modules - Internet & Extranet assigned to diff App PoolsDISA STIG SharePoint 2010 v1r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG205 A22 - The web document (home) directory must be in a separate partition from the web server's system files.DISA STIG Apache Site 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG205 W22 - The web document (home) directory must be in a separate partition from the web server's system files. - 'CustomLog'DISA STIG Apache Site 2.2 Windows v1r13Windows

AUDIT AND ACCOUNTABILITY

WG235 A22 - Web Administrators must only use encrypted connections for Document Root directory uploads.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix
WG235 A22 - Web Administrators must only use encrypted connections for Document Root directory uploads.DISA STIG Apache Site 2.2 Unix v1r11Unix
WG260 A22 - Only web sites that have been fully reviewed and tested must exist on a production web server.DISA STIG Apache Site 2.2 Unix v1r11Unix
WG260 A22 - Only web sites that have been fully reviewed and tested must exist on a production web server.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix
WG260 W22 - Only web sites that have been fully reviewed and tested must exist on a production web server.DISA STIG Apache Site 2.2 Windows v1r13Windows
WG610 A22 - Web sites must utilize ports, protocols, and services according to PPSM guidelines.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix
WG610 A22 - Web sites must utilize ports, protocols, and services according to PPSM guidelines.DISA STIG Apache Site 2.2 Unix v1r11Unix
WG610 W22 - Web sites must utilize ports, protocols, and services according to PPSM guidelines.DISA STIG Apache Site 2.2 Windows v1r13Windows