Item Search

NameAudit NamePluginCategory
1.7 IIST-SI-000209CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

AUDIT AND ACCOUNTABILITY

1.34 IIST-SI-000246CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

4.2 Ensure 'maxURL request filter' is configured - ApplicationsCIS IIS 7 L2 v1.8.0Windows

SYSTEM AND INFORMATION INTEGRITY

ESXI-06-000002 - The system must verify the DCUI.Access list.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000005 - The system must enforce the limit of three consecutive invalid logon attempts by a user.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000006 - The system must enforce the unlock timeout of 15 minutes after a user account is locked out.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000008 - The SSH daemon must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000030 - The system must produce audit records containing information to establish what type of events occurred.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-000031 - The VMM must enforce password complexity by requiring that at least one upper-case character be used.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-000035 - The VMM must be configured to disable non-essential capabilities by disabling SSH.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000036 - The system must disable ESXi Shell unless needed for diagnostics or troubleshooting.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000037 - The system must use Active Directory for local user authentication.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-000038 - The system must use the vSphere Authentication Proxy to protect passwords when adding ESXi hosts to Active Directory.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-000039 - Active Directory ESX Admin group membership must not be used.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-000040 - The system must use multifactor authentication for local access to privileged accounts.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-000043 - The system must logout of the console UI after a predetermined period.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000045 - The system must enable a persistent log location for all locally stored logs.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-000048 - The system must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000049 - The system must protect the confidentiality and integrity of transmitted information by protecting ESXi management traffic.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000051 - The system must protect the confidentiality and integrity of transmitted information.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000054 - The system must enable bidirectional CHAP authentication for iSCSI traffic.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000055 - The system must disable Inter-VM transparent page sharing.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND INFORMATION INTEGRITY

ESXI-06-000057 - The system must configure the firewall to block network traffic by default - OutgoingDISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000058 - The system must enable BPDU filter on the host to prevent being locked out of physical switch ports with Portfast and BPDU Guard enabled.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000060 - The virtual switch MAC Address Change policy must be set to reject.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000061 - The virtual switch Promiscuous Mode policy must be set to reject.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000062 - The system must prevent unintended use of the dvFilter network APIs.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000063 - All port groups must be configured to a value other than that of the native VLAN.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000065 - All port groups must not be configured to VLAN values reserved by upstream physical switches.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000067 - All physical switch ports must be configured with spanning tree disabled.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000072 - The system must have all security patches and updates installed.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000073 - The system must protect the confidentiality and integrity of transmitted information by isolating IP-based storage traffic.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-100007 - The VMM must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-100030 - The VMM must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-100037 - The VMM must require individuals to be authenticated with an individual authenticator prior to using a group authenticator by using Active Directory for local user authentication.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-100038 - The VMM must require individuals to be authenticated with an individual authenticator prior to using a group authenticator by using the vSphere Authentication Proxy.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-200035 - The VMM must provide the capability to immediately disconnect or disable remote access to the information system by disabling SSH.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-200037 - The VMM must implement replay-resistant authentication mechanisms for network access to privileged accounts by using Active Directory for local user authentication.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-200039 - The VMM must implement replay-resistant authentication mechanisms for network access to privileged accounts by restricting use of Active Directory ESX Admin group membership.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-300039 - The VMM must implement replay-resistant authentication mechanisms for network access to non-privileged accounts by restricting use of Active Directory ESX Admin group membership.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-300040 - The VMM must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-500004 - The VMM must, at a minimum, off-load interconnected systems in real time and off-load standalone systems weekly by configuring remote logging.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SI-000235 - The Idle Time-out monitor for each IIS 8.5 website must be enabled.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SV-000156 - All accounts installed with the IIS 8.5 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 8.5 Server v2r7Windows

CONFIGURATION MANAGEMENT

SP13-00-000060 - SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds - ConnectionTimeoutDISA Microsoft SharePoint 2013 STIG v2r4Windows

CONFIGURATION MANAGEMENT

SP13-00-000060 - SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds - maxBandwidthDISA Microsoft SharePoint 2013 STIG v2r4Windows

CONFIGURATION MANAGEMENT