Item Search

NameAudit NamePluginCategory
1.11 O19C-00-005600CIS Oracle Database 19c STIG v1.1.0 CAT II OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

1.96 O19C-00-020600CIS Oracle Database 19c STIG v1.1.0 CAT II OracleDBOracleDB

CONFIGURATION MANAGEMENT

1.114 WN10-CC-000063CIS Microsoft Windows 10 STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

4.2 Ensure No Custom 'ORACLE_MAINTAINED' Users ExistCIS Oracle Database 26ai v1.0.0 L1 RDBMS On Windows Server Host OS OracleDBOracleDB

ACCESS CONTROL

4.2 Ensure No Custom 'ORACLE_MAINTAINED' Users ExistCIS Oracle Database 26ai v1.0.0 L1 RDBMS On Linux Host OS OracleDBOracleDB

ACCESS CONTROL

4.2 Ensure No Custom 'ORACLE_MAINTAINED' Users ExistCIS Oracle Database 23ai v1.1.0 L1 RDBMSOracleDB

ACCESS CONTROL

4.2 Ensure No Custom 'ORACLE_MAINTAINED' Users ExistCIS Oracle Database 26ai v1.0.0 L1 RDBMSOracleDB

ACCESS CONTROL

4.2 Ensure No Custom 'ORACLE_MAINTAINED' Users ExistCIS Oracle Database 19c v2.0.0 L1 RDBMSOracleDB

ACCESS CONTROL

AZLX-23-002370 - Amazon Linux 2023 must require the change of at least 50 percent of the total number of characters when passwords are changed.DISA Amazon Linux 2023 STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

DG0019-ORACLE11 - Application software should be owned by a Software Application account - 'Oracle base directory file permissions are correct'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0019-ORACLE11 - Application software should be owned by a Software Application account - 'Oracle home directory file permissions are correct'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0019-ORACLE11 - Application software should be owned by a Software Application account.DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0104-ORACLE11 - DBMS service identification should be unique and clearly identifies the service - 'All Oracle services use the proper naming'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0104-ORACLE11 - DBMS service identification should be unique and clearly identifies the service.DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG7002-ORACLE11 - A minimum of two Oracle control files must be defined and configured to be stored on separate, archived disks (physical or virtual) or archived partitions on a RAID device.DISA STIG Oracle 11 Installation v9r1 DatabaseOracleDB
DO0220-ORACLE11 - Oracle instance names should not contain Oracle version numbers.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO3696-ORACLE11 - The Oracle RESOURCE_LIMIT parameter should be set to TRUE - 'resource_limit = true'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DO6753-ORACLE11 - Oracle Application Express or Oracle HTML DB should not be installed on a production database.DISA STIG Oracle 11 Installation v9r1 DatabaseOracleDB

CONFIGURATION MANAGEMENT

F5BI-DM-300046 - The F5 BIG-IP appliance must be configured to use multifactor authentication (MFA) for interactive logins.DISA F5 BIG-IP TMOS NDM STIG v1r2F5

AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

O19C-00-000200 - Oracle Database must protect against or limit the effects of organization-defined types of denial-of-service (DoS) attacks.DISA Oracle Database 19c STIG v1r3 WindowsWindows

ACCESS CONTROL

O19C-00-000500 - Oracle Database must associate organization-defined types of security labels having organization-defined security label values with information in storage.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

ACCESS CONTROL

O19C-00-008600 - Oracle instance names must not contain Oracle version numbers.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-020500 - A minimum of three Oracle Control Files must be created and each stored on a separate physical and logical device.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O19C-00-020500 - A minimum of three Oracle Control Files must be created and each stored on a separate physical and logical device.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O112-BP-021300 - Oracle instance names must not contain Oracle version numbers.DISA STIG Oracle 11.2g v2r5 DatabaseOracleDB

CONFIGURATION MANAGEMENT

O112-P3-006200 - The DBMS must protect against an individual using a group account from falsely denying having performed a particular action.DISA STIG Oracle 11.2g v2r5 DatabaseOracleDB

AUDIT AND ACCOUNTABILITY

O121-BP-021300 - Oracle instance names must not contain Oracle version numbers.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-BP-025101 - The directory assigned to the AUDIT_FILE_DEST parameter must be protected from unauthorized access and must be stored in a dedicated directory or disk partition separate from software or other application files.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-007500 - The DBMS must produce audit records containing sufficient information to establish when (date and time) the events occurred.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

O121-C2-008000 - The DBMS must include organization-defined additional, more detailed information in the audit records for audit events identified by type, location, or subject.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

AUDIT AND ACCOUNTABILITY

OL07-00-010019 - The Oracle Linux operating system must ensure cryptographic verification of vendor software packages.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-010483 - Oracle Linux operating systems version 7.2 or newer booted with a BIOS must have a unique name for the grub superusers account when booting into single-user and maintenance modes.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL07-00-020220 - The Oracle Linux operating system must enable the SELinux targeted policy.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

OL07-00-032000 - The Oracle Linux operating system must use a virus scan program.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040201 - The Oracle Linux operating system must implement virtual address space randomization.DISA Oracle Linux 7 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

VCENTER-000021 - The use of Linux-based clients must be restricted.DISA STIG VMWare ESXi vCenter 5 STIG v2r1VMware

CONFIGURATION MANAGEMENT

WBLC-01-000010 - Oracle WebLogic must use cryptography to protect the integrity of the remote access session - Unsecure Listen PortOracle WebLogic Server 12c Linux v2r2Unix

ACCESS CONTROL

WBLC-01-000030 - Oracle WebLogic must provide access logging that ensures users who are granted a privileged role (or roles) have their privileged activity logged.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-01-000033 - Oracle WebLogic must enforce the organization-defined time period during which the limit of consecutive invalid access attempts by a user is counted.Oracle WebLogic Server 12c Linux v2r2Unix

CONFIGURATION MANAGEMENT

WBLC-02-000065 - Oracle WebLogic must compile audit records from multiple components within the system into a system-wide (logical or physical) audit trail that is time-correlated to within an organization-defined level of tolerance.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000073 - Oracle WebLogic must produce process events and severity levels to establish what type of HTTPD-related events and severity levels occurred.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000076 - Oracle WebLogic must produce audit records containing sufficient information to establish when (date and time) the events occurred.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000077 - Oracle WebLogic must produce audit records containing sufficient information to establish where the events occurred.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000078 - Oracle WebLogic must produce audit records containing sufficient information to establish the sources of the events.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000099 - Oracle WebLogic must protect audit tools from unauthorized modification.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-08-000211 - Oracle WebLogic must establish a trusted communications path between the user and organization-defined security functions within the information system - SSL Listen PortOracle WebLogic Server 12c Linux v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-08-000231 - Oracle WebLogic must protect the confidentiality of applications and leverage transmission protection mechanisms, such as TLS and SSL VPN, when deploying applications - AdminServer SSL Listen PortOracle WebLogic Server 12c Linux v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-09-000252 - Oracle WebLogic must identify potentially security-relevant error conditions.Oracle WebLogic Server 12c Windows v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

WBLC-09-000252 - Oracle WebLogic must identify potentially security-relevant error conditions.Oracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

WBLC-10-000999 - The version of Oracle WebLogic running on the system must be a supported version.Oracle WebLogic Server 12c Linux v2r2Unix

SYSTEM AND INFORMATION INTEGRITY