Item Search

NameAudit NamePluginCategory
AS24-U2-000300 - The Apache web server must have Multipurpose Internet Mail Extensions (MIME) that invoke operating system shell programs disabled.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

CONFIGURATION MANAGEMENT

AS24-U2-000320 - The Apache web server must have resource mappings set to disable the serving of certain file types.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

CONFIGURATION MANAGEMENT

AS24-U2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

IDENTIFICATION AND AUTHENTICATION

AS24-U2-000470 - Cookies exchanged between the Apache web server and client, such as session cookies, must have security settings that disallow cookie access outside the originating Apache web server and hosted application.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000050 - The Exchange Email Diagnostic log level must be set to the lowest level.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

AUDIT AND ACCOUNTABILITY

EX16-MB-000060 - Exchange Audit record parameters must be set.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

AUDIT AND ACCOUNTABILITY

EX16-MB-000070 - Exchange Circular Logging must be disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

AUDIT AND ACCOUNTABILITY

EX16-MB-000160 - Exchange Audit data must be on separate partitions.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

AUDIT AND ACCOUNTABILITY

EX16-MB-000490 - Exchange must have anti-spam filtering installed.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000500 - Exchange must have anti-spam filtering enabled - SenderFilterConfigDISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000530 - Exchange servers must have an approved DoD email-aware virus protection software installed.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-000590 - Exchange software must be monitored for unauthorized changes.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX16-MB-002870 - The application must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

CONFIGURATION MANAGEMENT

EX16-MB-002910 - Exchange must use encryption for Outlook Web App (OWA) access.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

ACCESS CONTROL

EX16-MB-002920 - Exchange must have forms-based authentication disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

ACCESS CONTROL

JBOS-AS-000015 - HTTPS must be enabled for JBoss web interfaces.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

JBOS-AS-000035 - The JBoss server must be configured with Role Based Access Controls.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

JBOS-AS-000050 - Silent Authentication must be removed from the Default Management Security Realm.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

JBOS-AS-000225 - Google Analytics must be disabled in EAP Console.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000230 - JBoss process owner execution permissions must be limited.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000250 - Any unapproved applications must be removed - Any unapproved applications must be removed.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000260 - The JBoss Server must be configured to utilize a centralized authentication mechanism such as AD or LDAP.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000355 - The JBoss server must separate hosted application functionality from application server management functionality.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

JBOS-AS-000680 - Production JBoss servers must be supported by the vendor.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

JBOS-AS-000685 - The JRE installed on the JBoss server must be kept up to date.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

JBOS-AS-000710 - JBoss must be configured to generate log records that show starting and ending times for access to the application server management interface.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-010090 - The SUSE operating system must display the approved Standard Mandatory DoD Notice before granting local or remote access to the system via a graphical user logon.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010150 - The SUSE operating system must log SSH connection attempts and failures to the server.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-010180 - The SUSE operating system must not have the telnet-server package installed.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SLES-15-010220 - The SUSE operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

SLES-15-010240 - The SUSE operating system must disable the file system automounter.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010351 - The SUSE operating system library files must have mode 0755 or less permissive.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-010354 - The SUSE operating system library directories must be owned by root.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-010355 - The SUSE operating system library files must be group-owned by root.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-010357 - The SUSE operating system must have system commands set to a mode of 0755 or less permissive.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-010361 - The SUSE operating system must have system commands group-owned by root or a system account.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-030000 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-15-030020 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-15-030060 - The SUSE operating system must generate audit records for all uses of the ssh-keysign command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030190 - The SUSE operating system must generate audit records for all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030450 - The SUSE operating system must generate audit records for all uses of the chcon command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030560 - The SUSE operating system must generate audit records for all uses of the sudo command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-040050 - The SUSE operating system file integrity tool must be configured to verify extended attributes.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040130 - All SUSE operating system local initialization files must not execute world-writable programs.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040220 - The SUSE operating system must be configured to not overwrite Pluggable Authentication Modules (PAM) configuration on package changes.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040340 - The SUSE operating system must not allow interfaces to accept Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040380 - The SUSE operating system must not be performing Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040430 - The SUSE operating system must not allow unattended or automatic logon via the graphical user interface (GUI).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040440 - The SUSE operating system must not allow unattended or automatic logon via SSH.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT