Item Search

NameAudit NamePluginCategory
1.74 OL08-00-010410CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.105 UBTU-22-612025CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020352 - OL 8 must set the umask value to 077 for all local interactive user accounts.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030063 - OL 8 must resolve audit information before writing to disk.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030100 - The OL 8 audit log directory must be owned by root to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030121 - The OL 8 audit system must protect auditing rules from unauthorized change.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030150 - OL 8 must generate audit records for all account creation events that affect "/etc/passwd".DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030172 - OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers.d/".DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030180 - The OL 8 audit package must be installed.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

OL08-00-030300 - OL 8 must generate audit records for any use of the "mount" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030302 - OL 8 must generate audit records for any use of the "mount" syscall.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030315 - OL 8 must generate audit records for any use of the "userhelper" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030360 - OL 8 must generate audit records for any use of the "init_module" and "finit_module" system calls.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030390 - OL 8 must generate audit records for any use of the delete_module syscall.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030570 - OL 8 must generate audit records for any use of the "chacl" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030640 - OL 8 audit tools must be group-owned by root.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030660 - OL 8 must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-040004 - OL 8 must enable mitigations against processor-based vulnerabilities.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040024 - OL 8 must disable the transparent inter-process communication (TIPC) protocol.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040025 - OL 8 must disable mounting of cramfs.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040030 - OL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040120 - OL 8 must mount "/dev/shm" with the "nodev" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040121 - OL 8 must mount "/dev/shm" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040131 - OL 8 must mount "/var/log/audit" with the "noexec" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040132 - OL 8 must mount "/var/tmp" with the "nodev" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040137 - The OL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040140 - OL 8 must block unauthorized peripherals before establishing a connection.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040170 - The x86 Ctrl-Alt-Delete key sequence must be disabled on OL 8.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040171 - The x86 Ctrl-Alt-Delete key sequence in OL 8 must be disabled if a graphical user interface is installed.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040180 - OL 8 must disable the debug-shell systemd service.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040209 - OL 8 must prevent IPv4 Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040239 - OL 8 must not forward IPv4 source-routed packets.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040260 - OL 8 must not enable IPv6 packet forwarding unless the system is a router.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040300 - The OL 8 file integrity tool must be configured to verify extended attributes.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040321 - The graphical display manager must not be the default target on OL 8 unless approved.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040330 - OL 8 network interfaces must not be in promiscuous mode.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040340 - OL 8 remote X connections for interactive users must be disabled unless to fulfill documented and validated mission requirements.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

WBSP-AS-001300 - The WebSphere Application Server must accept Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WBSP-AS-001300 - The WebSphere Application Server must accept Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.DISA IBM WebSphere Traditional 9 Windows STIG v2r1Windows

IDENTIFICATION AND AUTHENTICATION

WNDF-AV-000004 - Microsoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000005 - Microsoft Defender AV must be configured to not exclude files for scanning.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000006 - Microsoft Defender AV must be configured to not exclude files opened by specified processes.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000008 - Microsoft Defender AV must be configured to disable local setting override for reporting to Microsoft MAPS.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000012 - Microsoft Defender AV must be configured for protocol recognition for network protection.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000013 - Microsoft Defender AV must be configured to not allow local override of monitoring for file and program activity.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000018 - Microsoft Defender AV must monitor for incoming and outgoing files.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000022 - Microsoft Defender AV must be configured to enable behavior monitoring.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000025 - Microsoft Defender AV must be configured to scan removable drives.DISA Microsoft Defender Antivirus STIG v2r9Windows

MAINTENANCE

WNDF-AV-000026 - Microsoft Defender AV must be configured to perform a weekly scheduled scan.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000041 - Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Medium.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION