Item Search

NameAudit NamePluginCategory
1.126 WN11-CC-000070CIS Microsoft Windows 11 STIG v1.2.0 CAT IIWindows

CONFIGURATION MANAGEMENT

ALMA-09-051940 - AlmaLinux OS 9 must use a separate file system for the system audit data path.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ARST-L2-000050 - The Arista MLS switch must have Root Guard enabled on all switch ports connecting to access layer switches and hosts.DISA Arista MLS EOS 4.X L2S STIG v2r3Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-L2-000130 - The Arista MLS layer 2 switch must have IGMP or MLD Snooping configured on all VLANs.DISA Arista MLS EOS 4.X L2S STIG v2r3Arista

CONFIGURATION MANAGEMENT

ARST-RT-000140 - The Arista multicast edge router must be configured to establish boundaries for administratively scoped multicast traffic.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

ACCESS CONTROL

ARST-RT-000180 - The Arista perimeter router must be configured to not redistribute static routes to an alternate gateway service provider into BGP or an IGP peering with the NIPRNet or to other autonomous systems.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

ACCESS CONTROL

ARST-RT-000600 - The Arista BGP router must be configured to enable the Generalized TTL Security Mechanism (GTSM).DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

CASA-VN-000010 - The Cisco ASA must be configured to generate log records containing information to establish what type of VPN events occurred.DISA STIG Cisco ASA VPN v2r2Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000236 - The Cisco router must be configured to advertise a hop limit of at least 32 in Router Advertisement messages for IPv6 stateless auto-configuration deployments.DISA Cisco IOS Router RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

ESXI-80-000207 - The ESXi host Secure Shell (SSH) daemon must be configured to not allow gateway ports.DISA VMware vSphere 8.0 ESXi STIG v2r4 UnixUnix

CONFIGURATION MANAGEMENT

EX19-MB-000042 - Exchange circular logging must be disabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

AUDIT AND ACCOUNTABILITY

F5BI-AP-000239 - The F5 BIG-IP appliance must be configured to set the 'Max In Progress Sessions per Client IP' value to 10 or less - Max In Progress Sessions per Client IP value to 10 or less.DISA F5 BIG-IP Access Policy Manager STIG v2r4F5

ACCESS CONTROL

F5BI-AP-300164 - The F5 BIG-IP appliance must be configured to set the "Max In Progress Sessions per Client IP" value to 10 or an organizational-defined number.DISA F5 BIG-IP TMOS ALG STIG v1r3F5

ACCESS CONTROL

FFOX-00-000021 - Firefox autoplay must be disabled.DISA Mozilla Firefox STIG v6r8 LinuxUnix

CONFIGURATION MANAGEMENT

GEN001280 - Manual page files must have mode 0644 or less permissive - '/usr/share/infopage/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001440 - All interactive users must be assigned a home directory in the /etc/passwd file.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001780 - Global initialization files must contain the mesg -n or mesg n commands. - '/etc/bashrc'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001780 - Global initialization files must contain the mesg -n or mesg n commands. - '/etc/environment'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001780 - Global initialization files must contain the mesg -n or mesg n commands. - '/etc/security/environ'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002715 - System audit tool executables must be owned by root - '/usr/sbin/auditconv'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002715 - System audit tool executables must be owned by root - '/usr/sbin/auditselect'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002715 - System audit tool executables must be owned by root - '/usr/sbin/auditstream'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002716 - System audit tool executables must be group-owned by bin, sys, or system - '/usr/sbin/auditcat'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002716 - System audit tool executables must be group-owned by bin, sys, or system - '/usr/sbin/auditconv'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

JUEX-RT-000080 - The Juniper router configured for Multicast Source Discovery Protocol (MSDP) must filter source-active multicast advertisements to external MSDP peers to avoid global visibility of local-only multicast sources and groups.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

JUEX-RT-000090 - The Juniper router configured for MSDP must limit the amount of source-active messages it accepts on per-peer basis.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

JUEX-RT-000150 - The Juniper multicast edge router must be configured to establish boundaries for administratively scoped multicast traffic.DISA Juniper EX Series Switches Router STIG v2r1Juniper

ACCESS CONTROL

JUEX-RT-000260 - The Juniper router must be configured to log all packets that have been dropped.DISA Juniper EX Series Switches Router STIG v2r1Juniper

AUDIT AND ACCOUNTABILITY

JUEX-RT-000270 - The Juniper router must be configured to have all nonessential capabilities disabled.DISA Juniper EX Series Switches Router STIG v2r1Juniper

CONFIGURATION MANAGEMENT

JUEX-RT-000980 - The Juniper Multicast Source Discovery Protocol (MSDP) router must be configured to use its loopback address as the source address when originating MSDP traffic.DISA Juniper EX Series Switches Router STIG v2r1Juniper

CONFIGURATION MANAGEMENT

OL08-00-010540 - OL 8 must use a separate file system for "/var".DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040026 - OL 8 must disable IEEE 1394 (FireWire) Support.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040310 - The OL 8 file integrity tool must be configured to verify Access Control Lists (ACLs).DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-08-010376 - RHEL 8 must prevent kernel profiling by unprivileged users.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-08-040004 - RHEL 8 must enable mitigations against processor-based vulnerabilities.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040021 - RHEL 8 must disable the asynchronous transfer mode (ATM) protocol.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-08-040023 - RHEL 8 must disable the stream control transmission protocol (SCTP).DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

CONFIGURATION MANAGEMENT

RHEL-09-231025 - RHEL 9 must use a separate file system for /var/log.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

SLES-15-040050 - The SUSE operating system file integrity tool must be configured to verify extended attributes.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SLES-15-040210 - The SUSE operating system must use a separate file system for /var.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

UBTU-22-653035 - Ubuntu 22.04 LTS must allocate audit record storage capacity to store at least one weeks' worth of audit records, when audit records are not immediately sent to a central audit record storage facility.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-24-100700 - Ubuntu 24.04 LTS must have the "chrony" package installed.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

CONFIGURATION MANAGEMENT

UBTU-24-600140 - Ubuntu 24.04 LTS must restrict access to the kernel message buffer.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-24-900980 - Ubuntu 24.04 LTS must alert the system administrator (SA) and information system security officer (ISSO) (at a minimum) in the event of an audit processing failure.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

WN11-CC-000030 - The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-CC-000206 - Windows Update must not obtain updates from other PCs on the internet.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN11-SO-000240 - The default permissions of global system objects must be increased.DISA Microsoft Windows 11 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN22-CC-000030 - Windows Server 2022 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing.DISA Microsoft Windows Server 2022 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN25-CC-000040 - Windows Server 2025 source routing must be configured to the highest protection level to prevent Internet Protocol (IP) source routing.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT

WN25-CC-000050 - Windows Server 2025 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT