Item Search

NameAudit NamePluginCategory
DISA_IIS_8.5_Web_Server_v2r7.audit from DISA Microsoft IIS 8.5 Server v2r7 STIGDISA IIS 8.5 Server v2r7Windows
DISA_IIS_8.5_Web_Site_v2r9.audit from DISA Microsoft IIS 8.5 Site v2r9 STIGDISA IIS 8.5 Site v2r9Windows
DISA_STIG_IIS_10.0_Web_Site_v2r14.audit from DISA Microsoft IIS 10.0 Site v2r14 STIGDISA IIS 10.0 Site v2r14Windows
DISA_STIG_Microsoft_Office_365_ProPlus_v3r5.audit from DISA Microsoft Office 365 ProPlus STIG v3r5DISA Microsoft Office 365 ProPlus STIG v3r5Windows
DISA_STIG_Oracle_Database_12c_v3r5_Database.audit from DISA Oracle Database 12c v3r5 STIGDISA Oracle Database 12c STIG v3r5 OracleDBOracleDB
DISA_STIG_Oracle_Database_12c_v3r5_OS_Linux.audit from DISA Oracle Database 12c v3r5 STIGDISA Oracle Database 12c STIG v3r5 UnixUnix
DISA_STIG_Oracle_Database_12c_v3r5_OS_Windows.audit from DISA Oracle Database 12c v3r5 STIGDISA Oracle Database 12c STIG v3r5 WindowsWindows
DISA_STIG_Oracle_Linux_7_v3r5.audit from DISA Oracle Linux 7 v3r5 STIGDISA Oracle Linux 7 STIG v3r5Unix
IIST-SI-000202 - The IIS 10.0 website session state cookie settings must be configured to Use Cookies mode.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000208 - An IIS 10.0 website behind a load balancer or proxy server must produce log records containing the source client IP, and destination information.DISA IIS 10.0 Site v2r14Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000209 - The IIS 10.0 website must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 website events.DISA IIS 10.0 Site v2r14Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000219 - Each IIS 10.0 website must be assigned a default host header.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000227 - The IIS 10.0 websites Maximum Query String limit must be configured.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 website, patches, loaded modules, and directory paths.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SI-000235 - The Idle Time-out monitor for each IIS 10.0 website must be enabled.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000236 - The IIS 10.0 websites connectionTimeout setting must be explicitly configured to disconnect an idle session.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000241 - The IIS 10.0 website must only accept client certificates issued by DOD PKI or DOD-approved PKI Certification Authorities (CAs).DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000242 - The IIS 10.0 private website must employ cryptographic mechanisms (TLS) and require client certificates.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000244 - IIS 10.0 website session IDs must be sent to the client using TLS.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000246 - Cookies exchanged between the IIS 10.0 website and the client must have cookie properties set to prohibit client-side scripts from reading the cookie data.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000251 - The IIS 10.0 website must have a unique application pool.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000261 - Interactive scripts on the IIS 10.0 web server must be located in unique and designated folders.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000262 - Interactive scripts on the IIS 10.0 web server must have restrictive access controls.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SV-000109 - An IIS 10.0 web server behind a load balancer or proxy server must produce log records containing the source client IP and destination information.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000110 - The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server eventsDISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000110 - The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server events.DISA IIS 10.0 Server v3r6Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000111 - The IIS 10.0 web server must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.DISA IIS 10.0 Server v3r6Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000111 - The IIS 10.0 web server must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000115 - The log information from the IIS 10.0 web server must be protected from unauthorized modification or deletion.DISA IIS 10.0 Server v3r6Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000115 - The log information from the IIS 10.0 web server must be protected from unauthorized modification or deletion.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000116 - The log data and records from the IIS 10.0 web server must be backed up onto a different system or media.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000116 - The log data and records from the IIS 10.0 web server must be backed up onto a different system or media.DISA IIS 10.0 Server v3r6Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000119 - The IIS 10.0 web server must not be both a website server and a proxy server.DISA IIS 10.0 Server v3r6Windows

CONFIGURATION MANAGEMENT

IIST-SV-000119 - The IIS 10.0 web server must not be both a website server and a proxy server.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000120 - All IIS 10.0 web server sample code, example applications, and tutorials must be removed from a production IIS 10.0 server.DISA IIS 10.0 Server v3r6Windows

CONFIGURATION MANAGEMENT

IIST-SV-000120 - All IIS 10.0 web server sample code, example applications, and tutorials must be removed from a production IIS 10.0 server.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabledDISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA IIS 10.0 Server v3r6Windows

CONFIGURATION MANAGEMENT

IIST-SV-000132 - The IIS 10.0 web server must separate the hosted applications from hosted web server management functionality.DISA IIS 10.0 Server v3r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000132 - The IIS 10.0 web server must separate the hosted applications from hosted web server management functionality.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000136 - The IIS 10.0 web server must augment re-creation to a stable and known baseline.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000136 - The IIS 10.0 web server must augment re-creation to a stable and known baseline.DISA IIS 10.0 Server v3r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.DISA IIS 10.0 Server v3r6Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000145 - The IIS 10.0 web server must use a logging mechanism configured to allocate log record storage capacity large enough to accommodate the logging requirements of the IIS 10.0 web server.DISA IIS 10.0 Server v3r6Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000145 - The IIS 10.0 web server must use a logging mechanism configured to allocate log record storage capacity large enough to accommodate the logging requirements of the IIS 10.0 web server.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 10.0 Server v3r6Windows

CONFIGURATION MANAGEMENT

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.DISA IIS 10.0 Server v3r6Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND INFORMATION INTEGRITY