Item Search

NameAudit NamePluginCategory
1.39 CISC-RT-000580CIS Cisco NX OS Switch RTR STIG v1.1.0 CAT IIICisco

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.81 CISC-RT-000880CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.1 Set 'logging on'CIS Cisco IOS 15 L1 v4.1.1Cisco

AUDIT AND ACCOUNTABILITY

AIX7-00-002057 - AIX audit logs must be rotated daily.DISA IBM AIX 7.x STIG v3r2Unix

CONFIGURATION MANAGEMENT

CISC-L2-000020 - The Cisco switch must uniquely identify and authenticate all network-connected endpoint devices before establishing any connection.DISA Cisco IOS Switch L2S STIG v3r1Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-L2-000030 - The Cisco switch must authenticate all VLAN Trunk Protocol (VTP) messages with a hash function using the most secured cryptographic algorithm available.DISA Cisco IOS Switch L2S STIG v3r1Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-L2-000150 - The Cisco switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs.DISA Cisco IOS Switch L2S STIG v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000160 - The Cisco switch must have Storm Control configured on all host-facing switchports.DISA Cisco IOS Switch L2S STIG v3r1Cisco

CONFIGURATION MANAGEMENT

CISC-L2-000180 - The Cisco switch must implement Rapid Spanning Tree Protocol (STP) where VLANs span multiple switches with redundant links.DISA Cisco IOS Switch L2S STIG v3r1Cisco

CONFIGURATION MANAGEMENT

CISC-L2-000210 - The Cisco switch must have all disabled switch ports assigned to an unused VLAN.DISA Cisco IOS Switch L2S STIG v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000220 - The Cisco switch must not have the default VLAN assigned to any host-facing switch ports.DISA Cisco IOS Switch L2S STIG v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000250 - The Cisco switch must have all user-facing or untrusted ports configured as access switch ports.DISA Cisco IOS Switch L2S STIG v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000100 - The Cisco switch must be configured to automatically audit account modification.DISA Cisco IOS Switch NDM STIG v3r7Cisco

ACCESS CONTROL

CISC-ND-000110 - The Cisco switch must be configured to automatically audit account disabling actions.DISA Cisco IOS Switch NDM STIG v3r7Cisco

ACCESS CONTROL

CISC-ND-000120 - The Cisco switch must be configured to automatically audit account removal actions.DISA Cisco IOS Switch NDM STIG v3r7Cisco

ACCESS CONTROL

CISC-ND-000210 - The Cisco device must be configured to audit all administrator activity.DISA Cisco IOS Switch NDM STIG v3r7Cisco

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

CISC-ND-000280 - The Cisco switch must produce audit records containing information to establish when (date and time) the events occurred.DISA Cisco IOS Switch NDM STIG v3r7Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-000460 - The Cisco switch must be configured to limit privileges to change the software resident within software libraries.DISA Cisco IOS Switch NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT

CISC-ND-000620 - The Cisco switch must only store cryptographic representations of passwords.DISA Cisco IOS Switch NDM STIG v3r7Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-ND-000720 - The Cisco switch must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA Cisco IOS Switch NDM STIG v3r7Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000880 - The Cisco switch must be configured to automatically audit account enabling actions.DISA Cisco IOS Switch NDM STIG v3r7Cisco

ACCESS CONTROL

CISC-ND-000980 - The Cisco switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.DISA Cisco IOS Switch NDM STIG v3r7Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001200 - The Cisco switch must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA Cisco IOS Switch NDM STIG v3r7Cisco

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

CISC-ND-001370 - The Cisco switch must be configured to use at least two authentication servers to authenticate users prior to granting administrative access.DISA Cisco IOS Switch NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT

CISC-ND-001410 - The Cisco switch must be configured to support organizational requirements to conduct backups of the configuration when changes occur.DISA Cisco IOS Switch NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

CISC-RT-000050 - The Cisco switch must be configured to enable routing protocol authentication using FIPS 198-1 algorithms with keys not exceeding 180 days of lifetime.DISA Cisco IOS Switch RTR STIG v3r3Cisco

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

CISC-RT-000060 - The Cisco switch must be configured to have all inactive Layer 3 interfaces disabled.DISA Cisco IOS Switch RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000180 - The Cisco switch must be configured to have Internet Control Message Protocol (ICMP) mask reply messages disabled on all external interfaces.DISA Cisco IOS Switch RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000200 - The Cisco switch must be configured to log all packets that have been dropped at interfaces via an access control list (ACL).DISA Cisco IOS Switch RTR STIG v3r3Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000210 - The Cisco switch must be configured to produce audit records containing information to establish where the events occurred.DISA Cisco IOS Switch RTR STIG v3r3Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000220 - The Cisco switch must be configured to produce audit records containing information to establish the source of the events.DISA Cisco IOS Switch RTR STIG v3r3Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000250 - The Cisco perimeter switch must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.DISA Cisco IOS Switch RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000320 - The Cisco perimeter switch must be configured to filter traffic destined to the enclave in accordance with the guidelines contained in DoD Instruction 8551.1.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000660 - The Cisco PE switch providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.DISA Cisco IOS Switch RTR STIG v3r3Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-RT-000740 - The Cisco PE switch must be configured with Unicast Reverse Path Forwarding (uRPF) loose mode enabled on all CE-facing interfaces.DISA Cisco IOS Switch RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000800 - The Cisco multicast switch must be configured to bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.DISA Cisco IOS Switch RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000860 - The Cisco multicast Designated switch (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups that have been approved by the organization.DISA Cisco IOS Switch RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000870 - The Cisco multicast Designated switch (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join a multicast group only from sources that have been approved by the organization.DISA Cisco IOS Switch RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000880 - The Cisco multicast Designated switch (DR) must be configured to limit the number of mroute states resulting from Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Host Membership Reports.DISA Cisco IOS Switch RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

DISA_F5_BIG-IP_AFM_v2r2.audit from DISA F5 BIG-IP Advanced Firewall Manager v2r2 STIGDISA F5 BIG-IP Advanced Firewall Manager STIG v2r2F5
DISA_F5_BIG-IP_APM_v2r4.audit from DISA F5 BIG-IP Access Policy Manager v2r4 STIGDISA F5 BIG-IP Access Policy Manager STIG v2r4F5
DISA_F5_BIG-IP_LTM_v2r4.audit from DISA F5 BIG-IP Local Traffic Manager v2r4 STIGDISA F5 BIG-IP Local Traffic Manager STIG v2r4F5
DISA_STIG_Docker_Enterprise_2.x_Linux_Unix_UCP_v2r2.audit from DISA Docker Enterprise 2.x Linux/UNIX v2r2 STIGDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix
DISA_STIG_Microsoft_Excel_2010_v1r11.audit for Microsoft Excel 2010, from DISA STIG Microsoft Excel 2010 v1r11DISA STIG Office 2010 Excel v1r11Windows
DISA_STIG_Microsoft_Publisher_2016_v1r3.audit for Microsoft Publisher 2016, from DISA STIG Microsoft Publisher 2016 v1r3DISA STIG Microsoft Publisher 2016 v1r3Windows
DISA_STIG_Microsoft_Windows_2012_Server_DNS_v2r7.audit from DISA Microsoft Windows 2012 Server Domain Name System v2r7 STIGDISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows
DISA_STIG_Splunk_Enterprise_7.x_for_Windows_OS_v3r2.audit from DISA Splunk Enterprise 7.x for Windows v3r2 STIGDISA STIG Splunk Enterprise 7.x for Windows v3r2 OSWindows
DISA_STIG_Splunk_Enterprise_8.x_for_Linux_OS_v2r3.audit from DISA Splunk Enterprise 8.x for Linux v2r3 STIGDISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix
DISA_STIG_VMware_vSphere_7.0_Photon_OS_v1r4.audit from DISA VMware vSphere 7.0 vCenter Appliance Photon OS v1r4 STIGDISA STIG VMware vSphere 7.0 Photon OS v1r4Unix
DISA_VMware_vSphere_8.0_vCenter_Appliance_Lookup_Service_STIG_v2r1.audit from DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r1DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r1Unix