Item Search

NameAudit NamePluginCategory
OL08-00-010019 - OL 8 must ensure cryptographic verification of vendor software packages.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010040 - OL 8 must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system via an SSH logon.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010090 - OL 8, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010130 - The OL 8 shadow password suite must be configured to use a sufficient number of hashing rounds.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010140 - OL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user mode and maintenance.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010141 - OL 8 operating systems booted with United Extensible Firmware Interface (UEFI) must have a unique name for the grub superusers account when booting into single-user mode and maintenance.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010149 - OL 8 operating systems booted with a BIOS must have a unique name for the grub superusers account when booting into single-user and maintenance modes.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010152 - OL 8 operating systems must require authentication upon booting into emergency mode.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010160 - The OL 8 "pam_unix.so" module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010163 - The krb5-server package must not be installed on OL 8.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010182 - OL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010187 - OL 8 must implement DOD-approved encryption in the bind package.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010220 - The OL 8 "/var/log/messages" file must be owned by root.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010240 - The OL 8 "/var/log" directory must have mode 0755 or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010290 - The OL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, MAINTENANCE

OL08-00-010300 - OL 8 system commands must have mode 755 or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010320 - OL 8 system commands must be group-owned by root or a system account.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010340 - OL 8 library files must be owned by root.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010358 - OL 8 must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010360 - The OL 8 file integrity tool must notify the system administrator (SA) when changes to the baseline configuration or anomalies in the operation of any security functions are discovered within an organizationally defined frequency.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

OL08-00-010420 - OL 8 must implement non-executable data to protect its memory from unauthorized code execution.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010422 - OL 8 must disable virtual syscalls.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010473 - OL 8 must enable the hardware random number generator entropy gatherer service.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010521 - The OL 8 SSH daemon must not allow Kerberos authentication, except to fulfill documented and validated mission requirements.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010542 - OL 8 must use a separate file system for the system audit data path.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010543 - OL 8 must use a separate file system for "/tmp".DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010572 - OL 8 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010740 - All OL 8 local interactive user home directories must be group-owned by the home directory owner's primary group.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020011 - OL 8 systems, versions 8.2 and above, must automatically lock an account when three unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020027 - OL 8 systems, versions 8.2 and above, must configure SELinux context type to allow the use of a non-default faillock tally directory.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020028 - OL 8 systems below version 8.2 must configure SELinux context type to allow the use of a non-default faillock tally directory.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020030 - OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for graphical user sessions.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020043 - OL 8 must enable a user session lock until that user reestablishes access using established identification and authentication procedures for command line sessions.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020060 - OL 8 must automatically lock graphical user sessions after 10 minutes of inactivity.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020081 - OL 8 must prevent a user from overriding the session idle-delay setting for the graphical user interface.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020200 - OL 8 user account passwords must have a 60-day maximum password lifetime restriction.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000030 - Audit policy using subcategories must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-SO-000040 - Outgoing secure channel traffic must be encrypted.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000050 - The computer account password must not be prevented from being reset.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000060 - The system must be configured to require a strong session key.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000080 - The Windows message title for the legal notice must be configured.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-SO-000085 - Caching of logon credentials must be limited.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000110 - Unencrypted passwords must not be sent to third-party SMB Servers.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000160 - The system must be configured to prevent anonymous users from having the same rights as the Everyone group.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000245 - User Account Control approval mode for the built-in Administrator must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000251 - Windows 11 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000270 - User Account Control must run all administrators in Admin Approval Mode, enabling UAC.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-UR-000065 - The 'Debug programs' user right must only be assigned to the Administrators group.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000110 - The 'Impersonate a client after authentication' user right must only be assigned to Administrators, Service, Local Service, and Network Service.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000140 - The 'Modify firmware environment values' user right must only be assigned to the Administrators group.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL