Item Search

NameAudit NamePluginCategory
1.1.10 Ensure separate partition exists for /var/logCIS Debian 8 Workstation L2 v2.0.2Unix

AUDIT AND ACCOUNTABILITY

1.1.11 Ensure separate partition exists for /var/logCIS CentOS 6 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.11 Ensure separate partition exists for /var/logCIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.11 Ensure separate partition exists for /var/logCIS Oracle Linux 6 Workstation L2 v2.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.11 Ensure separate partition exists for /var/logCIS Red Hat 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.13 Ensure separate partition exists for /homeCIS Debian Family Workstation L2 v1.0.0Unix

CONFIGURATION MANAGEMENT

5.5 Ensure all WildFire session information settings are enabledCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

18.5.10.1 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

CONFIGURATION MANAGEMENT

18.5.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT

18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Windows Server 2012 R2 DC L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Windows Server 2012 R2 MS L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L2 BL NGWindows

CONFIGURATION MANAGEMENT

18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L2 NGWindows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

ALMA-09-032030 - AlmaLinux OS 9 must require users to provide a password for privilege escalation.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-032140 - AlmaLinux OS 9 must not be configured to bypass password requirements for privilege escalation.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-032250 - AlmaLinux OS 9 must require reauthentication when using the "sudo" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-033460 - The pcscd socket on AlmaLinux OS 9 must be active.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-033680 - AlmaLinux OS 9 must implement certificate status checking for multifactor authentication.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-035000 - AlmaLinux OS 9 must prevent a user from overriding the disabling of the graphical user interface automount function.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-035660 - AlmaLinux OS 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-036760 - AlmaLinux OS 9 must require the change of at least four character classes when passwords are changed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037090 - AlmaLinux OS 9 must require the change of at least eight characters when passwords are changed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037200 - AlmaLinux OS 9 PAM must be configured to use a sufficient number of password hashing rounds.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037970 - Passwords for existing users must have a 60-day maximum password lifetime restriction in /etc/shadow.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-038960 - AlmaLinux OS 9 must map the authenticated identity to the user or group account for PKI-based authentication.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-039290 - AlmaLinux 9 cryptographic policy must not be overridden.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-041600 - AlmaLinux OS 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042370 - AlmaLinux OS 9 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-043030 - AlmaLinux OS 9 must not allow users to override SSH environment variables.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-043250 - AlmaLinux OS 9 wireless network adapters must be disabled.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-043910 - AlmaLinux OS 9 /var/log directory must be group-owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-044130 - AlmaLinux OS 9 /var/log/messages file must be owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-044900 - AlmaLinux OS 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-045450 - AlmaLinux OS 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

ALMA-09-046770 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-048420 - AlmaLinux OS 9 must generate audit records for any use of the "chcon" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-050620 - AlmaLinux OS 9 must generate audit records for any use of the "ssh-keysign" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-050950 - AlmaLinux OS 9 must generate audit records for any use of the "unix_chkpwd" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-052380 - AlmaLinux OS 9 must take appropriate action when the internal event queue is full.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-053040 - AlmaLinux OS 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-053150 - The rsyslog service on AlmaLinux OS 9 must be active.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-053480 - AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054140 - AlmaLinux OS 9 audit system must take appropriate action when the audit storage volume is full.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054360 - AlmaLinux OS 9 audit system must make full use of the audit storage space.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054470 - AlmaLinux OS 9 audit system must take appropriate action when the audit files have reached maximum size.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054690 - AlmaLinux OS 9 must periodically flush audit records to disk to prevent the loss of audit records.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-055130 - The chronyd service must be enabled.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-056120 - AlmaLinux OS 9 audit logs must have 0600 permissions to prevent unauthorized read access.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-056340 - AlmaLinux OS 9 audit tools must be owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY