Item Search

NameAudit NamePluginCategory
OL08-00-010000 - OL 8 must be a vendor-supported release.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010020 - OL 8 must implement NIST FIPS-validated cryptography for the following: To provision digital signatures, to generate cryptographic hashes, and to protect data requiring data-at-rest protections in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010030 - All OL 8 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at-rest protection.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010070 - All OL 8 remote access methods must be monitored.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010120 - OL 8 must employ FIPS 140-3-approved cryptographic hashing algorithms for all stored passwords.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010159 - The OL 8 "pam_unix.so" module must be configured in the system-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010162 - The krb5-workstation package must not be installed on OL 8.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010170 - OL 8 must use a Linux Security Module configured to enforce limits on system services.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010184 - The OL 8 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010201 - OL 8 must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010260 - The OL 8 "/var/log" directory must be group-owned by root.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010310 - OL 8 system commands must be owned by root.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010375 - OL 8 must restrict access to the kernel message buffer.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010384 - OL 8 must require reauthentication when using the "sudo" command.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010421 - OL 8 must clear the page allocator to prevent use-after-free attacks.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010440 - YUM must remove all software components after updated versions have been installed on OL 8.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

WN11-AU-000010 - The system must be configured to audit Account Logon - Credential Validation successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000054 - The system must be configured to audit Logon/Logoff - Account Lockout failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000070 - The system must be configured to audit Logon/Logoff - Logon failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000085 - The system must be configured to audit Object Access - Removable Storage failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000110 - The system must be configured to audit Privilege Use - Sensitive Privilege Use failures.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-AU-000115 - The system must be configured to audit Privilege Use - Sensitive Privilege Use successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000130 - The system must be configured to audit System - Other System Events successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000135 - The system must be configured to audit System - Other System Events failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000155 - The system must be configured to audit System - System Integrity failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000583 - Windows 11 must be configured to audit handle manipulation failures.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000586 - Windows 11 must be configured to audit registry successes.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-CC-000039 - Run as different user must be removed from context menus.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000060 - Connections to non-domain networks when connected to a domain authenticated network must be blocked.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000185 - The default autorun behavior must be configured to prevent autorun commands.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000190 - Autoplay must be disabled for all drives.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000204 - Enhanced diagnostic data must be limited to the minimum required to support Windows Analytics.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000215 - Explorer Data Execution Prevention must be enabled.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WN11-CC-000220 - File Explorer heap termination on corruption must be disabled.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-CC-000225 - File Explorer shell protocol must run in protected mode.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000270 - Passwords must not be saved in the Remote Desktop Client.DISA Microsoft Windows 11 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

WN11-CC-000310 - Users must be prevented from changing installation options.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000095 - The Smart Card removal option must be configured to Force Logoff or Lock Workstation.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000100 - The Windows SMB client must be configured to always perform SMB packet signing.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000140 - Anonymous SID/Name translation must not be allowed.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000150 - Anonymous enumeration of shares must be restricted.DISA Microsoft Windows 11 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000205 - The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000210 - The system must be configured to the required LDAP client signing level.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-UR-000015 - The 'Act as part of the operating system' user right must not be assigned to any groups or accounts.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000040 - The 'Create a pagefile' user right must only be assigned to the Administrators group.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000045 - The 'Create a token object' user right must not be assigned to any groups or accounts.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000070 - The 'Deny access to this computer from the network' user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000125 - The 'Lock pages in memory' user right must not be assigned to any groups or accounts.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000145 - The 'Perform volume maintenance tasks' user right must only be assigned to the Administrators group.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000160 - The 'Restore files and directories' user right must only be assigned to the Administrators group.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL