Item Search

NameAudit NamePluginCategory
1.113 WN19-CC-000200CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

ADBP-XI-000990 - Adobe Acrobat Pro XI periodic downloading of Adobe European certificates must be disabled.DISA Adobe Acrobat Pro XI STIG v1r2Windows

CONFIGURATION MANAGEMENT

ADBP-XI-001295 - Adobe Acrobat Pro XI Adobe Repair Installation must be disabled.DISA Adobe Acrobat Pro XI STIG v1r2Windows

CONFIGURATION MANAGEMENT

ADBP-XI-001300 - Adobe Acrobat Pro XI third-party web connectors must be disabled.DISA Adobe Acrobat Pro XI STIG v1r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-01-080005 - Apple iOS must not allow more than 10 consecutive failed authentication attempts.AirWatch - DISA Apple iOS 10 v1r3MDM

ACCESS CONTROL

AIOS-02-080007 - Apple iOS must disable automatic transfer of diagnostic data to an external device other than an enrolled MDM service.AirWatch - DISA Apple iOS 10 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-02-080008 - Apple iOS must implement the management setting: limit Ad Tracking.MobileIron - DISA Apple iOS 10 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-02-080101 - Apple iOS must not allow backup to remote systems (enterprise books).AirWatch - DISA Apple iOS 10 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-14-009300 - Apple iOS/iPadOS must implement the management setting: require the user to enter a password when connecting to an AirPlay-enabled device for the first time.MobileIron - DISA Apple iOS/iPadOS 14 v1r3MDM

ACCESS CONTROL

AIOS-14-010200 - Apple iOS/iPadOS must implement the management setting: force Apple Watch wrist detection.AirWatch - DISA Apple iOS/iPadOS 14 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-15-010500 - Apple iOS/iPadOS 15 must implement the management setting: limit Ad Tracking.AirWatch - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-010500 - Apple iOS/iPadOS 15 must implement the management setting: limit Ad Tracking.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-012300 - Apple iOS/iPadOS 15 must not allow managed apps to write contacts to unmanaged contacts accounts.AirWatch - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-15-012400 - Apple iOS/iPadOS 15 must not allow unmanaged apps to read contacts from managed contacts accounts.MobileIron - DISA Apple iOS/iPadOS 15 STIG v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-16-008400 - Apple iOS/iPadOS 16 must be configured to display the DoD advisory warning message at startup or each time the user unlocks the device.MobileIron - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

ACCESS CONTROL

AIOS-16-011800 - Apple iOS/iPadOS 16 must implement the management setting: Force Apple Watch wrist detection.AirWatch - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-010950 - Apple iOS/iPadOS 17 must implement the management setting: require passcode for incoming Airplay connection requests.MobileIron - DISA Apple iOS/iPadOS 17 v2r2MDM

ACCESS CONTROL

AIOS-17-011800 - Apple iOS/iPadOS 17 must implement the management setting: force Apple Watch wrist detection.MobileIron - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-708400 - Apple iOS/iPadOS 17 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device.MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2MDM

ACCESS CONTROL

AIOS-17-710900 - Apple iOS/iPadOS 17 must implement the management setting: require the user to enter a password when connecting to an AirPlay-enabled device.AirWatch - DISA Apple iOS/iPadOS 17 BYOAD v1r2MDM

ACCESS CONTROL

AIOS-17-710950 - Apple iOS/iPadOS 17 must implement the management setting: require passcode for incoming Airplay connection requests.MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2MDM

ACCESS CONTROL

AIOS-17-712400 - Apple iOS/iPadOS 17 must not allow unmanaged apps to read contacts from managed contacts accounts.AirWatch - DISA Apple iOS/iPadOS 17 BYOAD v1r2MDM

CONFIGURATION MANAGEMENT

APPL-11-002009 - The macOS system must be configured to disable AirDrop.DISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002009 - The macOS system must be configured to disable AirDrop.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002062 - The macOS system must be configured with Bluetooth turned off unless approved by the organization - DisableBluetoothDISA STIG Apple macOS 11 v1r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-005055 - The macOS system must be configured to disable prompts to configure ScreenTime.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

ARST-L2-000230 - The Arista MLS layer 2 switch must not have any switch ports assigned to the native VLAN.DISA Arista MLS EOS 4.X L2S STIG v2r3Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000180 - The Arista perimeter router must be configured to not redistribute static routes to an alternate gateway service provider into BGP or an IGP peering with the NIPRNet or to other autonomous systems.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

ACCESS CONTROL

ARST-RT-000210 - The multicast Rendezvous Point (RP) Arista router must be configured to filter Protocol Independent Multicast (PIM) Register and Join messages received from the Designated Router (DR) for any undesirable multicast groups and sources.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

ACCESS CONTROL

ARST-RT-000520 - The Arista router must be configured to have IP directed broadcast disabled on all interfaces.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000580 - The multicast Rendezvous Point (RP) Arista router must be configured to limit the multicast forwarding cache so that its resources are not saturated by managing an overwhelming number of Protocol Independent Multicast (PIM) and Multicast Source Discovery Protocol (MSDP) source-active entries.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000770 - The Arista Multicast Source Discovery Protocol (MSDP) router must be configured to use its loopback address as the source address when originating MSDP traffic.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

CONTINGENCY PLANNING

ARST-RT-000780 - The Arista router must be configured to advertise a hop limit of at least 32 in Router Advertisement messages for IPv6 stateless auto-configuration deployments.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

CONFIGURATION MANAGEMENT

ARST-RT-000780 - The Arista router must be configured to advertise a hop limit of at least 32 in Router Advertisement messages for IPv6 stateless auto-configuration deployments.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

CONFIGURATION MANAGEMENT

GEN001780 - Global initialization files must contain the mesg -n or mesg n commands. - '/etc/profile'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002717 - System audit tool executables must have mode 0750 or less permissive - '/usr/sbin/audit' - suidDISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002717 - System audit tool executables must have mode 0750 or less permissive - '/usr/sbin/auditbin'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002717 - System audit tool executables must have mode 0750 or less permissive - '/usr/sbin/auditselect'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002717 - System audit tool executables must have mode 0750 or less permissive - '/usr/sbin/auditstream'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN005760 - The NFS export configuration file must have mode 0644 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

JUEX-L2-000250 - The Juniper EX switch must not have any access interfaces assigned to a VLAN configured as native for any trunked interface.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-RT-000160 - The Juniper router must be configured to have all inactive interfaces disabled.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

JUEX-RT-000190 - The Juniper perimeter router must not be configured to redistribute static routes to an alternate gateway service provider into BGP or an IGP peering with the NIPRNet or to other autonomous systems.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

JUEX-RT-000230 - The Juniper multicast Rendezvous Point (RP) router must be configured to filter Protocol Independent Multicast (PIM) Join messages received from the Designated Router (DR) for any undesirable multicast groups.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

RHEL-09-231195 - RHEL 9 must disable mounting of cramfs.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-651035 - RHEL 9 must be configured so that the file integrity tool verifies extended attributes.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-20-010400 - The Ubuntu operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

ACCESS CONTROL

WN25-CC-000030 - Windows Server 2025 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT

WN25-CC-000060 - Windows Server 2025 must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Microsoft Windows Server 2025 STIG v1r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-CC-000200 - Windows Server 2025 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT