Item Search

NameAudit NamePluginCategory
1.48 ESXI-80-000221CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT I VMwareVMware

CONFIGURATION MANAGEMENT

1.85 O19C-00-017700CIS Oracle Database 19c STIG v1.1.0 CAT I UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-040390 - AlmaLinux OS 9 must enable the Pluggable Authentication Module (PAM) interface for SSHD.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

MAINTENANCE

APPL-15-002060 - The macOS system must apply gatekeeper settings to block applications from unidentified developers.DISA Apple macOS 15 Sequoia STIG v1r7Unix

CONFIGURATION MANAGEMENT

APPL-15-002064 - The macOS system must enable gatekeeper.DISA Apple macOS 15 Sequoia STIG v1r7Unix

CONFIGURATION MANAGEMENT

CASA-FW-000010 - The Cisco ASA must be configured to filter outbound traffic, allowing only authorized ports and services - ACL AppliedDISA STIG Cisco ASA FW v2r1Cisco

ACCESS CONTROL

CASA-FW-000220 - The Cisco ASA must be configured to implement scanning threat detection.DISA STIG Cisco ASA FW v2r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CASA-ND-000430 - The Cisco ASA must be configured to prohibit the use of all unnecessary and/or non-secure functions, ports, protocols, and/or services.DISA STIG Cisco ASA NDM v2r5Cisco

CONFIGURATION MANAGEMENT

CASA-VN-000240 - The Cisco ASA must be configured to use FIPS-validated SHA-2 or higher for Internet Key Exchange (IKE) Phase 2.DISA STIG Cisco ASA VPN v2r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CD16-00-008300 - PostgreSQL must use NSA-approved cryptography to protect classified information in accordance with the data owner's requirements.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

CNTR-R2-000130 - The Kubernetes Kubelet must have the read-only port flag disabled.DISA Rancher Government Solutions RKE2 STIG v2r7Unix

ACCESS CONTROL

JUEX-NM-000510 - The Juniper EX switches must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.DISA Juniper EX Series Network Device Management v2r4Juniper

MAINTENANCE

JUEX-NM-000930 - The Juniper EX switch must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.DISA Juniper EX Series Network Device Management v2r4Juniper

ACCESS CONTROL

MD8X-00-000200 - MongoDB must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA MongoDB Enterprise Advanced 8.x STIG v1r1 UnixUnix

ACCESS CONTROL

Mitigating an attack using TCP profilesTenable F5 BIG-IP Best Practice AuditF5

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-008000 - The Oracle Database software installation account must be restricted to authorized users.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

OL08-00-010180 - OL 8 must have the crypto-policies package installed.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010181 - OL 8 must implement a FIPS 140-3-compliant systemwide cryptographic policy.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010470 - There must be no ".shosts" files on the OL 8 operating system.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020332 - OL 8 must not allow blank or null passwords in the password-auth file.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040190 - The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for OL 8 operational support.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040360 - A File Transfer Protocol (FTP) server package must not be installed unless mission essential on OL 8.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

PHTN-40-000182 - The Photon operating system must implement NIST FIPS-validated cryptography for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-010121 - The RHEL 8 operating system must not have accounts configured with blank or null passwords.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-010460 - There must be no shosts.equiv files on the RHEL 8 operating system.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040170 - The x86 Ctrl-Alt-Delete key sequence must be disabled on RHEL 8.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040172 - The systemd Ctrl-Alt-Delete burst key sequence in RHEL 8 must be disabled.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-09-211010 - RHEL 9 must be a vendor-supported release.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-271040 - RHEL 9 must not allow unattended or automatic logon via the graphical user interface.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-611025 - RHEL 9 must not allow blank or null passwords.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-10-001000 - RHEL 10 must be a vendor-supported release.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND SERVICES ACQUISITION

SLES-15-010510 - FIPS 140-2 mode must be enabled on the SUSE operating system.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-020100 - The SUSE operating system root account must be the only account with unrestricted access to the system.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SLES-15-040430 - The SUSE operating system must not allow unattended or automatic logon via the graphical user interface (GUI).DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SYMP-AG-000330 - Symantec ProxySG must be configured with a pre-established trust relationship and mechanisms with appropriate authorities that validate user account access authorizations and privileges - Domain joinedDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000340 - Symantec ProxySG providing user authentication intermediary services must restrict user authentication traffic to specific authentication servers - Domain existsDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-NM-000030 - Symantec ProxySG must configure Web Management Console access restrictions to authorized IP address/ranges.DISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

ACCESS CONTROL

SYMP-NM-000310 - Symantec ProxySG must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirements - cli timeoutDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-18-999999 - The Ubuntu operating system must be a vendor supported release.DISA STIG Ubuntu 18.04 LTS v2r15Unix

CONFIGURATION MANAGEMENT

UBTU-24-100040 - Ubuntu 24.04 LTS must not have the rsh-server package installed.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

CONFIGURATION MANAGEMENT

UBTU-24-100050 - Ubuntu 24.04 LTS must not have the nfs-kernel-server package installed.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

CONFIGURATION MANAGEMENT

VCLD-67-000034 - VAMI must implement TLS1.2 exclusively - tlsv11DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCTR-67-000999 - The version of vCenter running on the system must be a supported version.DISA STIG VMware vSphere 6.7 vCenter v1r4VMware

SYSTEM AND INFORMATION INTEGRITY

VCUI-67-000999 - The version of UI Tomcat running on the system must be a supported version.DISA STIG VMware vSphere 6.7 UI Tomcat v1r3Unix

SYSTEM AND INFORMATION INTEGRITY

VMCH-65-000999 - The version of VMM running on the server must be a supported version.DISA STIG VMware vSphere Virtual Machine 6.5 v2r2VMware

CONFIGURATION MANAGEMENT

WN11-00-000040 - Windows 11 systems must be maintained at a supported servicing level.DISA Microsoft Windows 11 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN11-00-000100 - Internet Information System (IIS) or its subcomponents must not be installed on a workstation.DISA Microsoft Windows 11 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN11-00-000150 - Structured Exception Handling Overwrite Protection (SEHOP) must be enabled.DISA Microsoft Windows 11 STIG v2r8Windows

SYSTEM AND INFORMATION INTEGRITY

WN11-CC-000155 - Solicited Remote Assistance must not be allowed.DISA Microsoft Windows 11 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

ZEBR-10-999999 - All Zebra Android 10 installations must be removed.AirWatch - DISA Zebra Android 10 COPE v1r2MDM

CONFIGURATION MANAGEMENT