Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
Item Search
Audits
Item Search
Add Filter
Description
Filename
Plugin
References
Control ID
Relevance
Description
Plugin
Filename
‹‹ Previous
Previous
Page 2 of 494
• 24672 Total
Next
Next ››
Name
Audit Name
Plugin
Category
DG0003-ORACLE11 - The latest security patches should be installed.
DISA STIG Oracle 11 Installation v9r1 Windows
Windows
DG0066-ORACLE11 - Procedures for establishing temporary passwords that meet DoD password requirements for new accounts should be defined, documented and implemented.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0092-ORACLE11 - Database data files containing sensitive information should be encrypted.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0106-ORACLE11 - Database data encryption controls should be configured in accordance with application requirements.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0107-ORACLE11 - Sensitive data is stored in the database and should be identified in the System Security Plan and AIS Functional Architecture documentation.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0158-ORACLE11 - DBMS remote administration should be audited.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DG0161-ORACLE11 - An automated tool that monitors audit data and immediately reports suspicious activity should be employed for the DBMS.
DISA STIG Oracle 11 Installation v9r1 Linux
Unix
DO6752-ORACLE11 - The Oracle SEC_PROTOCOL_ERROR_TRACE_ACTION parameter should not be set to NONE.
DISA STIG Oracle 11 Installation v9r1 Database
OracleDB
WA060 A22 - A public web server, if hosted on the NIPRNet, must be isolated in an accredited DoD DMZ Extension.
DISA STIG Apache Server 2.2 Unix v1r11
Unix
WA060 A22 - A public web server, if hosted on the NIPRNet, must be isolated in an accredited DoD DMZ Extension.
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA060 W22 - A public web server, if hosted on the NIPRNet, must be isolated in an accredited DoD DMZ Extension.
DISA STIG Apache Server 2.2 Windows v1r13
Windows
WA230 IIS6 - The site software used with the web server must have all applicable security patches applied and documented.
DISA STIG IIS 6.0 Server v6r16
Windows
WA230 W22 - The site software used with the web server must have all applicable security patches applied and documented.
DISA STIG Apache Server 2.2 Windows v1r13
Windows
WA00525 A22 - User specific directories must not be globally enabled.
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA00530 A22 - The process ID (PID) file must be properly secured
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA00530 A22 - The process ID (PID) file must be properly secured - permissions
DISA STIG Apache Server 2.2 Unix v1r11
Unix
WA00530 W22 - The process ID (PID) file must be properly secured.
DISA STIG Apache Server 2.2 Windows v1r13
Windows
WA00535 W22 - The ScoreBoard file must be properly secured.
DISA STIG Apache Server 2.2 Windows v1r13
Windows
WA00540 A22 - The web server must be configured to explicitly deny access to the OS root - Deny
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA00555 A22 - The web server must be configured to listen on a specific IP address and port - 0.0.0.0:80
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA00555 A22 - The web server must be configured to listen on a specific IP address and port - listen
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WA00565 A22 - HTTP request methods must be limited - Deny
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WG040 W22 - Public web server resources must not be shared with private assets.
DISA STIG Apache Server 2.2 Windows v1r13
Windows
WG050 A22 - The web server password(s) must be entrusted to the SA or Web Manager.
DISA STIG Apache Server 2.2 Unix v1r11
Unix
WG050 W22 - The web server service password(s) must be entrusted to the SA or Web Manager.
DISA STIG Apache Server 2.2 Windows v1r13
Windows
WG080 A22 - Installation of a compiler on production web server is prohibited.
DISA STIG Apache Server 2.2 Unix v1r11
Unix
WG080 W22 - Installation of a compiler on production web server must be prohibited.
DISA STIG Apache Server 2.2 Windows v1r13
Windows
WG220 A22 - Web administration tools must be restricted to the web manager and the web manager's designees - AccessConfig
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WG240 IIS6 - Logs of web server access and errors must be established and maintained.
DISA STIG IIS 6.0 Site Checklist v6r16
Windows
WG250 A22 - Log file access must be restricted to System Administrators, Web Administrators or Auditors.
DISA STIG Apache Site 2.2 Unix v1r11
Unix
WG260 IIS6 - Only fully reviewed and tested web sites must exist on a production web server.
DISA STIG IIS 6.0 Site Checklist v6r16
Windows
WG270 A22 - The web server's htpasswd files (if present) must reflect proper ownership and permissions
DISA STIG Apache Server 2.2 Unix v1r11
Unix
WG270 A22 - The web server's htpasswd files (if present) must reflect proper ownership and permissions
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WG280 - The access control files are owned by a privileged web server account - APP_Config_files
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WG280 - The access control files are owned by a privileged web server account - HTACCESS_DIR
DISA STIG Apache Server 2.2 Unix v1r11
Unix
WG280 - The access control files are owned by a privileged web server account - HTTPD_CONFIG_DIRECTORY/httpd.conf
DISA STIG Apache Server 2.2 Unix v1r11
Unix
WG350 IIS6 - A private web server must have a valid server certificate.
DISA STIG IIS 6.0 Site Checklist v6r16
Windows
WG350 W22 - A private web server must have a valid DoD server certificate.
DISA STIG Apache Site 2.2 Windows v1r13
Windows
WG355 A22 - A private web server's list of CAs in a trust hierarchy must lead to an authorized DoD PKI Root CA.
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WG355 W22 - A private web server's list of CAs in a trust hierarchy must lead to an authorized DoD PKI Root CA.
DISA STIG Apache Server 2.2 Windows v1r13
Windows
WG410 IIS6 - Interactive scripts must have proper access controls. - 'CGI Directory Permissions'
DISA STIG IIS 6.0 Site Checklist v6r16
Windows
WG410 IIS6 - Interactive scripts must have proper access controls. - 'Execute Permissions set 'Script only'
DISA STIG IIS 6.0 Site Checklist v6r16
Windows
WG410 W22 - Interactive scripts used on a web server must have proper access controls.
DISA STIG Apache Site 2.2 Windows v1r13
Windows
WG430 A22 - Anonymous FTP user access to interactive scripts is prohibited.
DISA STIG Apache Site 2.2 Unix v1r11 Middleware
Unix
WG430 IIS6 - Anonymous FTP users must not have access to interactive scripts.
DISA STIG IIS 6.0 Site Checklist v6r16
Windows
WG430 W22 - Anonymous FTP user access to interactive scripts must be prohibited.
DISA STIG Apache Site 2.2 Windows v1r13
Windows
WG440 A22 - Monitoring software must include CGI or equivalent programs in its scope.
DISA STIG Apache Server 2.2 Unix v1r11
Unix
WG440 A22 - Monitoring software must include CGI or equivalent programs in its scope.
DISA STIG Apache Server 2.2 Unix v1r11 Middleware
Unix
WG460 W22 - PERL scripts must use the TAINT option.
DISA STIG Apache Site 2.2 Windows v1r13
Windows
WG470 W22 - Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator. - 'Wscript.exe'
DISA STIG Apache Server 2.2 Windows v1r13
Windows
‹‹ Previous
Previous
Page 2 of 494
• 24672 Total
Next
Next ››