Item Search

NameAudit NamePluginCategory
AS24-U2-000660 - The Apache web server must set an inactive timeout for sessions.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000680 - The Apache web server must restrict inbound connections from nonsecure zones.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

ACCESS CONTROL

AS24-U2-000780 - The Apache web server application, libraries, and configuration files must only be accessible to privileged users.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

CONFIGURATION MANAGEMENT

AS24-U2-000890 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookies.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000030 - Exchange auto-forwarding email to remote domains must be disabled or restricted.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

ACCESS CONTROL

EX16-MB-000150 - Exchange must protect audit data against unauthorized deletion.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

AUDIT AND ACCOUNTABILITY

EX16-MB-000180 - The Exchange Internet Message Access Protocol 4 (IMAP4) service must be disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX16-MB-000200 - Exchange Mailbox databases must reside on a dedicated partition.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000220 - Exchange internal Receive connectors must require encryption.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000320 - Exchange Mail Quota settings must not restrict receiving mail.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000340 - Exchange Mailbox Stores must mount at startup.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000360 - Exchange Receive connectors must control the number of recipients per message.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000410 - Exchange Message size restrictions must be controlled on Send connectors.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000470 - Exchange Internal Receive connectors must not allow anonymous connections.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000480 - Exchange external/Internet-bound automated response messages must be disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000500 - Exchange must have anti-spam filtering enabled - SenderReputationConfigDISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000520 - Exchange must not send automated replies to remote domains.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000540 - The Exchange Global Recipient Count Limit must be set.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000550 - The Exchange Receive connector timeout must be limited.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

ACCESS CONTROL

EX16-MB-000570 - The Exchange application directory must be protected from unauthorized access.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX16-MB-000580 - An Exchange software baseline copy must exist.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX16-MB-000600 - Exchange services must be documented and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX16-MB-000620 - The Exchange Email application must not share a partition with another application.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000650 - The Exchange SMTP automated banner response must not reveal server details.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000660 - Exchange Internal Send connectors must use an authentication level.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-002930 - Exchange must have authenticated access set to Integrated Windows Authentication only.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

ACCESS CONTROL

JBOS-AS-000025 - Java permissions must be set for hosted applications.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

JBOS-AS-000110 - JBoss must be configured to produce log records containing information to establish what type of events occurred.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000170 - File permissions must be configured to protect log information from unauthorized modification.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000295 - The JBoss Password Vault must be used for storing passwords or other sensitive configuration information.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000305 - LDAP enabled security realm value allow-empty-passwords must be set to false.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000545 - Production JBoss servers must not allow automatic application deployment.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000690 - JBoss must be configured to generate log records when successful/unsuccessful attempts to modify privileges occur.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000720 - JBoss must be configured to generate log records for all account creations, modifications, disabling, and termination events.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000735 - JBoss servers must be configured to roll over and transfer logs on a minimum weekly basis.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-010000 - The SUSE operating system must be a vendor-supported release.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-15-010030 - The SUSE operating system must not have the vsftpd package installed if not required for operational support.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SLES-15-010060 - The SUSE operating system file /etc/gdm/banner must contain the Standard Mandatory DoD Notice and Consent banner text.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010120 - The SUSE operating system must initiate a session lock after a 15-minute period of inactivity for the graphical user interface (GUI).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010130 - The SUSE operating system must initiate a session lock after a 10-minute period of inactivity.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010230 - The SUSE operating system must not have duplicate User IDs (UIDs) for interactive users.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010280 - The SUSE operating system SSH daemon must be configured with a timeout interval.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010320 - The SUSE operating system, for all network connections associated with SSH traffic, must immediately terminate at the end of the session or after 10 minutes of inactivity.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010330 - All SUSE operating system persistent disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at-rest protection.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010340 - The SUSE operating system must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-15-010418 - The SUSE operating system must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-010430 - The SUSE operating system tool zypper must have gpgcheck enabled.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-010490 - If Network Security Services (NSS) is being used by the SUSE operating system it must prohibit the use of cached authentications after one day.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020260 - The SUSE operating system must employ passwords with a minimum of 15 characters.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020290 - The SUSE operating system must prevent the use of dictionary words for passwords.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT