Item Search

NameAudit NamePluginCategory
1.8.8 Ensure the operating system does not allow an unattended or automatic logon to the system via a graphical user interfaceCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

1.134 ALMA-09-017840CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.142 WN16-CC-000530CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IWindows

MAINTENANCE

1.227 WN16-SO-000260CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IWindows

CONFIGURATION MANAGEMENT

1.228 WN16-SO-000270CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

ADBP-XI-001075 - The Adobe Acrobat Pro XI latest security-related software updates must be installed.DISA Adobe Acrobat Pro XI STIG v1r2Windows

SYSTEM AND INFORMATION INTEGRITY

AIOS-13-999999 - All Apple iOS/iPadOS 13 installations must be removed.AirWatch - DISA Apple iOS/iPadOS 13 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-15-010400 - Apple iOS/iPadOS 15 must require a valid password be successfully entered before the mobile device data is unencrypted.AirWatch - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-010400 - Apple iOS/iPadOS 15 must require a valid password be successfully entered before the mobile device data is unencrypted.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-999999 - All Apple iOS/iPadOS 15 installations must be removed.AirWatch - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-16-010400 - Apple iOS/iPadOS 16 must require a valid password be successfully entered before the mobile device data is unencrypted.AirWatch - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-16-010400 - Apple iOS/iPadOS 16 must require a valid password be successfully entered before the mobile device data is unencrypted.MobileIron - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-16-715000 - All Apple iOS/iPadOS 16 BYOAD installations must be removed.AirWatch - DISA Apple iOS/iPadOS 16 BYOAD v1r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-006950 - Apple iOS/iPadOS 17 must be configured to enforce a passcode reuse prohibition of at least two generations.AirWatch - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-999999 - All Apple iOS/iPadOS 17 installations must be removed.AirWatch - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-18-011200 - iPhone and iPad must have the latest available iOS/iPadOS operating system installed.MobileIron - DISA Apple iOS/iPadOS 18 v2r3MDM

CONFIGURATION MANAGEMENT

AMLS-NM-000450 - The Arista MLS NDM must be using a version supported by the vendor.DISA STIG Arista MLS DCS-7000 Series NDM v1r4Arista

CONFIGURATION MANAGEMENT

APPL-11-004021 - The macOS system must be configured with the sudoers file configured to authenticate users on a per -tty basis.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-13-000016 - The macOS system must be integrated into a directory services infrastructure.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-999999 - The macOS system must be a supported release.DISA STIG Apple macOS 13 v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

ARBA-ND-000245 - AOS must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.DISA HPE Aruba Networking AOS NDM STIG v1r1ArubaOS

CONFIGURATION MANAGEMENT

ARST-ND-000490 - The Arista network device must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirements.DISA Arista MLS EOS 4.X NDM STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000170 - The Arista perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an alternate gateway service provider.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

ACCESS CONTROL

ARST-RT-000170 - The Arista perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an alternate gateway service provider.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

ACCESS CONTROL

ARST-RT-000400 - The Arista router must be configured to block any traffic that is destined to IP core infrastructure.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

CD12-00-000900 - PostgreSQL must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.DISA STIG Crunchy Data PostgreSQL OS v3r1Unix

ACCESS CONTROL

CD12-00-012900 - PostgreSQL products must be a version supported by the vendor.DISA STIG Crunchy Data PostgreSQL OS v3r1Unix

SYSTEM AND SERVICES ACQUISITION

CD16-00-004400 - PostgreSQL must use NIST FIPS 140-2/140-3 validated cryptographic modules for cryptographic operations.DISA Crunchy Data Postgres 16 STIG v1r2 UnixUnix

IDENTIFICATION AND AUTHENTICATION

EX19-ED-000236 - Exchange internal Send connectors must require encryption.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-AP-300159 - The F5 BIG-IP appliance must be configured to use cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

SYSTEM AND COMMUNICATIONS PROTECTION

FGFW-ND-000170 - The FortiGate device must be running an operating system release that is currently supported by the vendor.DISA Fortigate Firewall NDM STIG v1r4FortiGate

CONFIGURATION MANAGEMENT

FGFW-ND-000285 - The FortiGate device must only allow authorized administrators to view or change the device configuration, system files, and other files stored either in the device or on removable media (such as a flash drive).DISA Fortigate Firewall NDM STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003850 - The telnet daemon must not be running.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004640 - The SMTP service must not have a uudecode alias active - '/etc/aliases uudecode alias does not exist'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GOOG-10-999999 - All Google Android 10 installations must be removed.AirWatch - DISA Google Android 10.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-11-010800 - Google Android 11 devices must have the latest available Google Android 11 operating system installed.AirWatch - DISA Google Android 11 COBO v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-011-999999 - All Google Android 11 installations must be removed.AirWatch - DISA Google Android 11 COPE v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-15-010800 - Android 15 devices must have the latest available Google Android 15 operating system installed.AirWatch - DISA Google Android 15 COPE STIG v1r5MDM

CONFIGURATION MANAGEMENT

MADB-10-012600 - MariaDB products must be an enterprise version supported by the vendor.DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDBMySQLDB

SYSTEM AND SERVICES ACQUISITION

OS10-RTR-000180 - The perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an alternate gateway service provider.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

ACCESS CONTROL

UBTU-20-010012 - The Ubuntu operating system must ensure only users who need access to security functions are part of sudo group.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-20-010048 - The Ubuntu operating system must be configured so that remote X connections are disabled, unless to fulfill documented and validated mission requirements.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

CONFIGURATION MANAGEMENT

UBTU-20-010459 - The Ubuntu operating system must disable the x86 Ctrl-Alt-Delete key sequence if a graphical user interface is installed.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

CONFIGURATION MANAGEMENT

WN22-00-000130 - Windows Server 2022 local volumes must use a format that supports NTFS attributes.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL

WN22-SO-000020 - Windows Server 2022 must prevent local accounts with blank passwords from being used from the network.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-SO-000250 - Windows Server 2022 must restrict anonymous access to Named Pipes and Shares.DISA Microsoft Windows Server 2022 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-MS-000140 - Windows Server 2025 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-SO-000210 - Windows Server 2025 must not allow anonymous SID/Name translation.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-SO-000310 - Windows Server 2025 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

ZEBR-14-010800 - Zebra Android 14 devices must have the latest available Zebra Android 14 operating system installed.MobileIron - DISA Zebra Android 14 COBO STIG v1r2MDM

CONFIGURATION MANAGEMENT