Item Search

NameAudit NamePluginCategory
1.1.22 Disable AutomountingCIS SUSE Linux Enterprise Workstation 11 L2 v2.1.1Unix

MEDIA PROTECTION

1.1.23 Disable AutomountingCIS Fedora 19 Family Linux Server L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.23 Disable AutomountingCIS SUSE Linux Enterprise 12 v3.2.1 L2 WorkstationUnix

MEDIA PROTECTION

1.1.23 Disable AutomountingCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.23 Disable USB Storage - lsmodCIS Debian Family Server L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.23 Disable USB Storage - lsmodCIS Red Hat 6 Server L1 v3.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.23 Disable USB Storage - modprobeCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.1.24 Disable USB Storage - lsmodCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.35 IIST-SI-000251CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.59 EX19-ED-000199CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED SERVICES\PrintSpoolerService'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.23 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BLWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.31 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' and (when the Web Server (IIS) Role with Web Services Role Service is installed) 'IIS_IUSRS' (MS only)CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

2.2.31 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only)CIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.31 Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only)CIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.32 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' (DC only)CIS Microsoft Windows Server 2016 v4.0.0 L1 DCWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.2.32 (L1) Ensure 'Impersonate a client after authentication' is set to 'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE' and (when the Web Server (IIS) Role with Web Services Role Service is installed) 'IIS_IUSRS' (MS only)CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

5.2 Ensure forwarding is enabled for all applications and file types in WildFire file blocking profilesCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.5 Ensure all WildFire session information settings are enabledCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.5 Ensure all WildFire session information settings are enabledCIS Palo Alto Firewall 7 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.6 Ensure alerts are enabled for malicious files detected by WildFireCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.5 Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in useCIS Palo Alto Firewall 7 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.5 Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in useCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.7 Ensure a Vulnerability Protection Profile is set to block attacks against critical/high, and set to default on medium, low, and infoCIS Palo Alto Firewall 7 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

6.8 Ensure a secure Vulnerability Protection Profile is applied to all security rules allowing trafficCIS Palo Alto Firewall 6 Benchmark L1 v1.0.0Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

7.2 Set Strong Password Creation Policies - DICTIONLIST = /usr/share/lib/dict/wordsCIS Solaris 11 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Strong Password Creation Policies - MINDIFF = 3CIS Solaris 11.1 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Strong Password Creation Policies - MINLOWER = 1CIS Solaris 11.1 L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Strong Password Creation Policies - MINLOWER = 1CIS Solaris 11.2 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

7.2 Set Strong Password Creation Policies - MINLOWER = 1CIS Solaris 11 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

7.4 Ensure TLS 1.0 is enabledCIS IIS 7 L1 v1.8.0Windows
8.5 (L1) VMware Tools must limit the automatic addition of featuresCIS VMware ESXi 8.0 v1.3.0 L1 VMwareVMware

CONFIGURATION MANAGEMENT

DISA_STIG_Apache_Site-2.4_Windows_v2r3.audit from DISA Apache Server 2.4 Windows Site v2r3 STIGDISA Apache Server 2.4 Windows Site STIG v2r3Windows
DISA_STIG_Microsoft_Exchange_2013_Edge_Transport_Server_v1r6.audit from DISA Microsoft Exchange 2013 Edge Transport Server v1r6 STIGDISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_Microsoft_Exchange_2016_Edge_Transport_Server_v2r6.audit from DISA Microsoft Exchange 2016 Edge Transport Server v2r6 STIGDISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_MSSQL_2014_Instance-OS_v2r4.audit from DISA MS SQL Server 2014 Instance v2r4 STIGDISA STIG SQL Server 2014 Instance OS Audit v2r4Windows
DISA_STIG_MSSQL_2016_Instance-OS_v3r6.audit from DISA MS SQL Server 2016 Instance v3r6 STIGDISA MS SQL Server 2016 Instance STIG v3r6 WindowsWindows
EX16-MB-000600 - Exchange services must be documented and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX19-MB-000198 - Exchange services must be documented, and unnecessary services must be removed or disabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

CONFIGURATION MANAGEMENT

IIST-SI-000221 - Anonymous IIS 10.0 website access accounts must be restricted.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000251 - The IIS 10.0 website must have a unique application pool.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000251 - The IIS 10.0 website must have a unique application pool.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

CONFIGURATION MANAGEMENT

IIST-SI-000252 - The maximum number of requests an application pool can process for each IIS 10.0 website must be explicitly set.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000258 - The application pools rapid fail protection for each IIS 10.0 website must be enabled.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000259 - The application pools rapid fail protection settings for each IIS 10.0 website must be managed.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000264 - The required DoD banner page must be displayed to authenticated users accessing a DoD private website.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000270 - HTTPAPI Server version must be removed from the HTTP Response Header information.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND INFORMATION INTEGRITY

SP13-00-000015 - SharePoint must utilize approved cryptography to protect the confidentiality of remote access sessions.DISA Microsoft SharePoint 2013 STIG v2r4Windows

ACCESS CONTROL

SP13-00-000120 - SharePoint must maintain the confidentiality of information during aggregation, packaging, and transformation in preparation for transmission. When transmitting data, applications need to leverage transmission protection mechanisms such as TLS, SSL VPNs, or IPSec.DISA Microsoft SharePoint 2013 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION