Item Search

NameAudit NamePluginCategory
1.2.1.5 Ensure DNF is configured to perform a signature check on local packagesCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.006 - Users with Administrative privilege are not documented or do not have separate accounts for administrative duties.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

2.005 - Systems must be at supported service packs (SP) or releases levels.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.062 - Anonymous SID/Name translation is allowed.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

5.007 - An approved, up-to-date, DoD antivirus program must be installed and used.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

DG0067-ORACLE11 - Database account passwords should be stored in encoded or encrypted format whether stored in database objects, external host files, environment variables or any other storage locations.DISA STIG Oracle 11 Installation v9r1 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'No listeners are running'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'No listeners are running'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DTOO999 - InfoPath - The version of InfoPath running on the system must be a supported version.DISA STIG Office 2010 InfoPath v1r12Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO999 - OneNote - The version of OneNote running on the system must be a supported version.DISA Microsoft OneNote 2010 STIG v1r10Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO999 - PowerPoint - The version of PowerPoint running on the system must be a supported version.DISA STIG Office 2010 PowerPoint v1r11Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO999 - Project - The version of Microsoft Project running on the system must be a supported version.DISA STIG Office 2010 Project v1r10Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO999-Groove - The version of Groove running on the system must be a supported version.DISA STIG Microsoft Groove 2013 v1r4Windows

SYSTEM AND INFORMATION INTEGRITY

DTOSkype999 - The version of Skype running on the system must be a supported version.DISA STIG Microsoft Skype for Business 2016 v2r1Windows

SYSTEM AND INFORMATION INTEGRITY

GEN001640 - Run control scripts must not execute world-writable programs or scripts.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004400 - Files executed through a mail aliases file must be owned by root.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004640 - The SMTP service must not have a uudecode alias active - '/etc/aliases decode alias does not exist'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN005080 - The TFTP daemon must operate in 'secure mode' which provides access only to a single directory on the host file system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN005200 - X displays must not be exported to the world.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.bat mappings'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.cmd mappings'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.HTR scripting Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Allowed Web Service Extensions'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Index Server Web Interface Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Internet Data Connector Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Server Side Includes Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Script Source permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Write permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI110 IIS6 - The command shell options must be disabled.DISA STIG IIS 6.0 Server v6r16Windows

ACCESS CONTROL

WA000-WI6040 IIS6 - A unique non-privileged account must be used to run Worker Process Identities. - 'AppPoolIdentityType = 3 - WAMUserName'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI6040 IIS6 - A unique non-privileged account must be used to run Worker Process Identities. - 'AppPoolIdentityType Check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - -+IncludesNOEXEC|-IncludesDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - +IncludesDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA054 W22 - Server side includes (SSIs) must run with execution capability disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG190 IIS6 - The web server must use a vendor-supported version of the web server software.DISA STIG IIS 6.0 Server v6r16Windows

SYSTEM AND INFORMATION INTEGRITY

WG190 W22 - The web server must use a vendor-supported version of the web server software.DISA STIG Apache Server 2.2 Windows v1r13Windows

SYSTEM AND INFORMATION INTEGRITY

WG195 IIS6 - Anonymous access accounts must be restricted.DISA STIG IIS 6.0 Server v6r16Windows

ACCESS CONTROL

WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

ACCESS CONTROL

WG230 A22 - Web server administration must be performed over a secure path or at the local console.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG230 W22 - Web server administration must be performed over a secure path or at the local console.DISA STIG Apache Site 2.2 Windows v1r13Windows

ACCESS CONTROL

WG290 A22 - Web client access to the content directories must be restricted to read and execute - aliasDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG290 A22 - Web client access to the content directories must be restricted to read and execute - script aliasDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG290 A22 - Web client access to the content directories must be restricted to read and execute - script alias matchDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG360 A22 - Symbolic links must not be used in the web content directory tree - confDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG360 A22 - Symbolic links must not be used in the web content directory tree - findDISA STIG Apache Site 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG360 A22 - Symbolic links must not be used in the web content directory tree - findDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG385 A22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG385 W22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. - 'extra'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG385 W22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. - 'printenv'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT