Item Search

NameAudit NamePluginCategory
1.34 SQLI-22-009500CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDBMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

1.35 O19C-00-009900CIS Oracle Database 19c STIG v1.1.0 CAT I UnixUnix

CONFIGURATION MANAGEMENT

1.44 ESXI-80-000217CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT I VMwareVMware

CONFIGURATION MANAGEMENT

1.66 EX19-ED-000236CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.75 O19C-00-015500CIS Oracle Database 19c STIG v1.1.0 CAT I UnixUnix

IDENTIFICATION AND AUTHENTICATION

1.140 WN22-CC-000470CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IWindows

MAINTENANCE

1.204 WN22-MS-000140CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IWindows

CONFIGURATION MANAGEMENT

1.207 WN16-SO-000020CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IWindows

CONFIGURATION MANAGEMENT

1.228 WN22-SO-000210CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IWindows

CONFIGURATION MANAGEMENT

1.230 WN16-SO-000300CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.230 WN22-SO-000230CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.236 WN16-SO-000380CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IWindows

CONFIGURATION MANAGEMENT

1.314 RHEL-09-611025CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

ALMA-09-015420 - AlmaLinux OS 9 must not allow unattended or automatic logon via the graphical user interface.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

ALMA-09-042700 - All AlmaLinux OS 9 networked systems must have the OpenSSH client package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CASA-VN-000150 - The Cisco ASA must be configured to use Internet Key Exchange (IKE) for all IPsec security associations.DISA STIG Cisco ASA VPN v2r2Cisco

CONFIGURATION MANAGEMENT

CASA-VN-000340 - The Cisco ASA VPN gateway must use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.DISA STIG Cisco ASA VPN v2r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CD16-00-004400 - PostgreSQL must use NIST FIPS 140-2/140-3 validated cryptographic modules for cryptographic operations.DISA Crunchy Data Postgres 16 STIG v1r3 UnixUnix

IDENTIFICATION AND AUTHENTICATION

CD16-00-005200 - PostgreSQL must protect the confidentiality and integrity of all information at rest.DISA Crunchy Data Postgres 16 STIG v1r3 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-80-000217 - The ESXi host must configure virtual switch security policies to reject Media Access Control (MAC) address changes.DISA VMware vSphere 8.0 ESXi STIG v2r4 VMwareVMware

CONFIGURATION MANAGEMENT

ESXI-80-000221 - The ESXi host must have all security patches and updates installed.DISA VMware vSphere 8.0 ESXi STIG v2r4 VMwareVMware

CONFIGURATION MANAGEMENT

JUEX-NM-000680 - The Juniper EX switch must be configured with an operating system release that is currently supported by the vendor.DISA Juniper EX Series Network Device Management v2r4Juniper

CONFIGURATION MANAGEMENT

JUEX-RT-000180 - The Juniper perimeter router must not be configured to be a Border Gateway Protocol (BGP) peer to an alternate gateway service provider.DISA Juniper EX Series Router v2r1Juniper

ACCESS CONTROL

MD7X-00-008300 - MongoDB must use NSA-approved cryptography to protect classified information in accordance with the data owner's requirements.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 MongoDBMongoDB

SYSTEM AND COMMUNICATIONS PROTECTION

MD8X-00-000300 - MongoDB must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.DISA MongoDB Enterprise Advanced 8.x STIG v1r1 MongoDBMongoDB

ACCESS CONTROL

O19C-00-011800 - Database administrator (DBA) OS accounts must be granted only those host system privileges necessary for the administration of the Oracle Database.DISA Oracle Database 19c STIG v1r5 UnixUnix

CONFIGURATION MANAGEMENT

PHTN-40-000207 - The Photon operating system must configure Secure Shell (SSH) to disallow authentication with an empty password.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-08-010150 - RHEL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-08-010270 - RHEL 8 cryptographic policy must not be overridden.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-010275 - RHEL 8 must implement DOD-approved encryption in the bind package.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-215060 - The Trivial File Transfer Protocol (TFTP) server must not be installed unless it is required, and if required, the RHEL 9 TFTP daemon must be configured to operate in secure mode.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

SLEM-05-212015 - SLEM 5 with Unified Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

ACCESS CONTROL

SLEM-05-411065 - SLEM 5 root account must be the only account with unrestricted access to the system.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

CONFIGURATION MANAGEMENT

SLEM-05-671010 - FIPS 140-2/140-3 mode must be enabled on SLEM 5.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010045 - The SUSE operating system must implement a FIPS 140-3-compliant systemwide cryptographic policy.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010046 - SUSE operating system cryptographic policy must not be overridden.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010190 - SUSE operating systems with a basic input/output system (BIOS) must require authentication upon booting into single-user and maintenance modes.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

ACCESS CONTROL

SLES-15-010200 - SUSE operating systems with Unified Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

ACCESS CONTROL

SLES-15-040061 - The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence for Graphical User Interfaces.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SLES-15-040062 - The SUSE operating system must disable the systemd Ctrl-Alt-Delete burst key sequence.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SQLD-22-000300 - SQL Server must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.DISA Microsoft SQL Server 2022 Database STIG v1r3MS_SQLDB

ACCESS CONTROL

SQLI-22-018100 - When using command-line tools such as SQLCMD in a mixed-mode authentication environment, users must use a logon method that does not expose the password.DISA Microsoft SQL Server 2022 Instance STIG v1r4 MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

UBTU-22-271030 - Ubuntu 22.04 LTS must disable the x86 Ctrl-Alt-Delete key sequence if a graphical user interface is installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-611060 - Ubuntu 22.04 LTS must not allow accounts configured with blank or null passwords.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-24-300028 - Ubuntu 24.04 LTS must not allow accounts configured in Pluggable Authentication Modules (PAM) with blank or null passwords.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

CONFIGURATION MANAGEMENT

UBTU-24-600130 - Ubuntu 24.04 LTS must ensure only users who need access to security functions are part of sudo group.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-CC-000330 - The Windows Remote Management (WinRM) client must not use Basic authentication.DISA Microsoft Windows 11 STIG v2r8Windows

MAINTENANCE

WN11-SO-000140 - Anonymous SID/Name translation must not be allowed.DISA Microsoft Windows 11 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN11-SO-000150 - Anonymous enumeration of shares must be restricted.DISA Microsoft Windows 11 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

ZEBR-11-010800 - Zebra Android 11 devices must have the latest available Zebra Android 11 operating system installed.MobileIron - DISA Zebra Android 11 COBO STIG v1r4MDM

CONFIGURATION MANAGEMENT