Item Search

NameAudit NamePluginCategory
AS24-U2-000090 - The Apache web server must produce log records containing sufficient information to establish what type of events occurred.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

AUDIT AND ACCOUNTABILITY

AS24-U2-000310 - The Apache web server must allow mappings to unused and vulnerable scripts to be removed.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

CONFIGURATION MANAGEMENT

AS24-U2-000590 - The Apache web server must be tuned to handle the operational requirements of the hosted application.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000450 - The Exchange Outbound Connection Limit per Domain Count must be controlled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010010 - Vendor-packaged SUSE operating system security patches and updates must be installed and up to date.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-15-010020 - The SUSE operating system must display the Standard Mandatory DOD Notice and Consent Banner before granting access via local console.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010100 - The SUSE operating system must be able to lock the graphical user interface (GUI).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010260 - The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (login.defs).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010300 - The sticky bit must be set on all SUSE operating system world-writable directories.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010360 - The SUSE operating system must have directories that contain system commands owned by root.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-010410 - The SUSE operating system must be configured to use Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-010450 - The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010480 - The SUSE operating system must disable the USB mass storage kernel module.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010530 - All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010580 - The SUSE operating system must off-load rsyslog messages for networked systems in real time and off-load standalone systems at least weekly.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-020020 - The SUSE operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-020040 - The SUSE operating system must deny direct logons to the root account using remote access via SSH.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020130 - The SUSE operating system must enforce passwords that contain at least one uppercase character.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020140 - The SUSE operating system must enforce passwords that contain at least one lowercase character.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020150 - The SUSE operating system must enforce passwords that contain at least one numeric character.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020200 - The SUSE operating system must be configured to create or update passwords with a minimum lifetime of 24 hours (one day).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020210 - The SUSE operating system must employ user passwords with a minimum lifetime of 24 hours (one day).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020300 - The SUSE operating system must not be configured to allow blank or null passwords.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-030030 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/security/opasswd.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-15-030050 - SUSE operating system audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030090 - The SUSE operating system must generate audit records for all uses of the newgrp command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030130 - The SUSE operating system must generate audit records for all uses of the crontab command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030140 - The SUSE operating system must audit all uses of the sudoers file and all files in the /etc/sudoers.d/ directory.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030150 - The SUSE operating system must generate audit records for all uses of the creat, open, openat, open_by_handle_at, truncate, and ftruncate system calls.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030360 - The SUSE operating system must generate audit records for all uses of the umount system call.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030410 - The SUSE operating system must generate audit records for all uses of the kmod command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030420 - The SUSE operating system must generate audit records for all uses of the chmod command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030470 - The SUSE operating system must generate audit records for all modifications to the tallylog file must generate an audit record.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030490 - The SUSE operating system must generate audit records for all uses of the passmass command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030520 - The SUSE operating system must generate audit records for all uses of the delete_module system call.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030530 - The SUSE operating system must generate audit records for all uses of the init_module and finit_module system calls.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030600 - The SUSE operating system must protect audit rules from unauthorized modification.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030640 - The SUSE operating system must generate audit records for all uses of the privileged functions.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

SLES-15-030670 - The audit-audispd-plugins must be installed on the SUSE operating system.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030740 - The SUSE operating system must generate audit records for all uses of the unlink, unlinkat, rename, renameat, and rmdir system calls.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030810 - The SUSE operating system must use a separate file system for the system audit data path.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040030 - There must be no shosts.equiv files on the SUSE operating system.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040060 - The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040120 - All SUSE operating system local interactive user initialization files executable search paths must contain only paths that resolve to the users home directory.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040150 - SUSE operating system file systems that are used with removable media must be mounted to prevent files with the setuid and setgid bit set from being executed.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040160 - SUSE operating system file systems that are being imported via Network File System (NFS) must be mounted to prevent files with the setuid and setgid bit set from being executed.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040320 - The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets by default.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040341 - The SUSE operating system must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040410 - All SUSE operating system files and directories must have a valid group owner.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000004 - Microsoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY