Item Search

NameAudit NamePluginCategory
2.005 - Systems must be at supported service packs (SP) or releases levels.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.018 - Anonymous shares are not restricted. - RestrictAnonymousSAMDISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.031 - The Send download LanMan compatible password option is not set to Send NTLMv2 response only\refuse LM.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.049 - The Recovery Console option is set to permit automatic logon to the system.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.108 - Unauthorized registry paths and sub-paths are remotely accessible.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.116 - Named Pipes and Shares can be accessed anonymously.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.017 - DOD information system access does not require the use of a password.DISA Windows Vista STIG v6r41Windows

IDENTIFICATION AND AUTHENTICATION

DG0129-ORACLE11 - Passwords should be encrypted when transmitted across the network.DISA STIG Oracle 11 Installation v9r1 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'No listeners are running'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'No listeners are running'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DTOO425-Outlook13 - The version of Outlook running on the system must be a supported version.DISA STIG Microsoft Outlook 2013 v1r14Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO999 - Access - The version of Microsoft Access running on the system must be a supported version.DISA STIG Office 2010 Access v1r11Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO999-Groove - The version of Groove running on the system must be a supported version.DISA STIG Microsoft Groove 2013 v1r4Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO999-Project13 - The version of Microsoft Project running on the system must be a supported version.DISA STIG Microsoft Project 2013 v1r5Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO999-Visio13 - The version of Visio running on the system must be a supported version.DISA STIG Microsoft Visio 2013 v1r5Windows

SYSTEM AND INFORMATION INTEGRITY

GEN000100 - The operating system must be a supported release.DISA STIG AIX 5.3 v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - '.rhosts'DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - 'shosts.equiv'DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN002220 - All shell files must have mode 0755 or less permissive.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN004600 - The SMTP service must be an up-to-date version.DISA STIG AIX 5.3 v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN005080 - The TFTP daemon must operate in 'secure mode' which provides access only to a single directory on the host - Not ApplicableDISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN005200 - X displays must not be exported to the world.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN008600 - The system must be configured to only boot from the system boot device.DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN008640 - The system must not use removable media as the boot loader - 'prevboot'DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.bat mappings'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.cmd mappings'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.HTR scripting Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Allowed Web Service Extensions'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Index Server Web Interface Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Internet Data Connector Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Server Side Includes Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Script Source permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Write permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI110 IIS6 - The command shell options must be disabled.DISA STIG IIS 6.0 Server v6r16Windows

ACCESS CONTROL

WA000-WI6040 IIS6 - A unique non-privileged account must be used to run Worker Process Identities. - 'AppPoolIdentityType = 3 - WAMUserName'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI6040 IIS6 - A unique non-privileged account must be used to run Worker Process Identities. - 'AppPoolIdentityType Check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - -+IncludesNOEXEC|-IncludesDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - +IncludesDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA054 W22 - Server side includes (SSIs) must run with execution capability disabled.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG195 IIS6 - Anonymous access accounts must be restricted.DISA STIG IIS 6.0 Server v6r16Windows

ACCESS CONTROL

WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

ACCESS CONTROL

WG230 W22 - Web server administration must be performed over a secure path or at the local console.DISA STIG Apache Site 2.2 Windows v1r13Windows

ACCESS CONTROL

WG290 A22 - Web client access to the content directories must be restricted to read and execute - script aliasDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG290 A22 - Web client access to the content directories must be restricted to read and execute - script alias matchDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG360 A22 - Symbolic links must not be used in the web content directory tree - findDISA STIG Apache Site 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG385 A22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG385 IIS6 - All web server documentation, sample code, example applications, and tutorials must be removed. - 'Inetpub\AdminScripts'DISA STIG IIS 6.0 Server v6r16Windows

CONFIGURATION MANAGEMENT

WG385 W22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. - 'httpd-manual'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG385 W22 - All web server documentation, sample code, example applications, and tutorials must be removed from a production web server. - 'printenv'DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT