Item Search

NameAudit NamePluginCategory
1.2 Password Security Policy - c) Configure 'strong-password dictionary' and 'same-consecutive' to avoid weak password - same-consecutiveTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.2 Password Security Policy - d) Display password in cipher textTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.2 Password Security Policy - e) Check for strong-password username-related-chk inverseTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.3 Verify no unauthorized kernel modules are loaded on the hostCIS VMware ESXi 5.1 v1.0.1 Level 1VMware
1.6 Support Web Access Security - b) ssl-context fieldTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - a) Disable encryption noneTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - j) Disable diffie-hellman group1-sha1Tenable ZTE ROSNG Best PracticesZTE_ROSNG
1.9 SSL Strong Algorithm - d) renegotiateTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.14 ESXI-80-000094CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT II UnixUnix

AUDIT AND ACCOUNTABILITY

1.49 EX19-ED-000139CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

2.1 Configure NTP time synchronizationCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

AUDIT AND ACCOUNTABILITY

2.2 Ensure that authorization is enabled for Cassandra databasesCIS Apache Cassandra 3.11 L1 Unix Audit v1.0.0Unix

ACCESS CONTROL

2.2 Ensure that authorization is enabled for Cassandra databasesCIS Apache Cassandra 3.11 L2 Unix Audit v1.0.0Unix

ACCESS CONTROL

2.3 Disable the Proxy ARP Function - c) No proxy localTenable ZTE ROSNG Best PracticesZTE_ROSNG
2.5 Product Default BannerTenable ZTE ROSNG Best PracticesZTE_ROSNG
3.3 Authentication and Verification of BGP Routing ProtocolsTenable ZTE ROSNG Best PracticesZTE_ROSNG
3.8 Ensure 'INACTIVE_ACCOUNT_TIME' Is Less than or Equal to '120'CIS Oracle Database 23ai v1.1.0 L1 RDBMSOracleDB

ACCESS CONTROL

3.8 Ensure 'INACTIVE_ACCOUNT_TIME' Is Less than or Equal to '120'CIS Oracle Database 26ai v1.0.0 L1 RDBMSOracleDB

ACCESS CONTROL

3.8 Ensure 'INACTIVE_ACCOUNT_TIME' Is Less than or Equal to '120'CIS Oracle Database 26ai v1.0.0 L1 RDBMS On Linux Host OS OracleDBOracleDB

ACCESS CONTROL

3.8 Ensure 'INACTIVE_ACCOUNT_TIME' Is Less Than Or Equal To '120'CIS Oracle Database 19c v2.0.0 L1 RDBMSOracleDB

ACCESS CONTROL

3.8 Ensure 'INACTIVE_ACCOUNT_TIME' Is Less than or Equal to '120'CIS Oracle Database 26ai v1.0.0 L1 RDBMS On Windows Server Host OS OracleDBOracleDB

ACCESS CONTROL

5.2.2.3 Enable Conditional Access policies to block legacy authenticationCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

7.23 (L1) Virtual machines must restrict sharing of memory pages with other VMsCIS VMware ESXi 8.0 v1.3.0 L1 VMwareVMware

CONFIGURATION MANAGEMENT

12.22 Developer access to production databases - 'Disallow'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows
12.22 Developer access to production databases - 'Disallow'CIS v1.1.0 Oracle 11g OS L1Unix
ACLs: Filter for RFC 1918 addresses (10.0.0.0/8)TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

SYSTEM AND COMMUNICATIONS PROTECTION

ACLs: Filter for RFC 3330 addresses (0.0.0.0/8)TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

SYSTEM AND COMMUNICATIONS PROTECTION

ACLs: Filter for RFC 3330 addresses (169.254.0.0/16)TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

SYSTEM AND COMMUNICATIONS PROTECTION

ACLs: Filter for RFC 3330 addresses (224.0.0.0/4)TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

SYSTEM AND COMMUNICATIONS PROTECTION

Authentication: enable remote authenticationTNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

IDENTIFICATION AND AUTHENTICATION

Authentication: local authentication is available as a last resortTNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

IDENTIFICATION AND AUTHENTICATION

BGP: Authenticate peersTNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

ACCESS CONTROL

CIS_VMware_vSphere_8.0_vCenter_Appliance_Secure_Token_Service_STS_STIG_v1.0.0_CAT_II.audit from CIS VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v1.0.0CIS VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v1.0.0 CAT IIUnix
DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_Management_Interface_VAMI_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance Management Interface VAMI STIG v2r2DISA VMware vSphere 8.0 vCenter Appliance Management Interface VAMI STIG v2r2Unix
DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_Photon_OS_4.0_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix
DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_User_Interface_UI_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v2r2DISA VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v2r2Unix
ESXI-67-000078 - The ESXi host must use DoD-approved certificates.DISA STIG VMware vSphere 6.7 ESXi OS v1r3Unix

CONFIGURATION MANAGEMENT

GEN002430-ESXI5 - Removable media, remote file systems, and any file system that does not contain approved device files must be mounted with the nodev option.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

CONFIGURATION MANAGEMENT

GEN005900-ESXI5-00891 - The nosuid option must be enabled on all NFS client mounts.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

CONFIGURATION MANAGEMENT

Login: FTP is disabledTNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

CONFIGURATION MANAGEMENT

SRG-OS-000077-ESXI5 - The system must prohibit the reuse of passwords within five iterations.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

IDENTIFICATION AND AUTHENTICATION

SRG-OS-99999-ESXI5-000137 - The system must disable the Managed Object Browser (MOB) - MOBDISA VMWare ESXi 5.0 Server STIG v2r1VMware

CONFIGURATION MANAGEMENT

SRG-OS-99999-ESXI5-000152 - Keys from SSH authorized_keys file must be removed.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

CONFIGURATION MANAGEMENT

VCFL-67-000005 - vSphere Client must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

VCRP-70-000008 - Envoy log files must be shipped via syslog to a central log serverDISA STIG VMware vSphere 7.0 RhttpProxy v1r1Unix

AUDIT AND ACCOUNTABILITY

VCSA-70-000248 - The vCenter Server must disable the Customer Experience Improvement Program (CEIP).DISA STIG VMware vSphere 7.0 vCenter v1r3VMware

CONFIGURATION MANAGEMENT

VCTR-67-000067 - The vCenter Server must disable the Customer Experience Improvement Program (CEIP).DISA STIG VMware vSphere 6.7 vCenter v1r4VMware

CONFIGURATION MANAGEMENT

VCUI-70-000012 - vSphere UI must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled.DISA STIG VMware vSphere 7.0 vCA UI v1r2Unix

CONFIGURATION MANAGEMENT

VCUI-70-000013 - vSphere UI must have mappings set for Java servlet pages.DISA STIG VMware vSphere 7.0 vCA UI v1r2Unix

CONFIGURATION MANAGEMENT

VM Tools: guest-8.tools-enable-loggingVMware vSphere Security Configuration and Hardening GuideVMware

CONFIGURATION MANAGEMENT