Item Search

NameAudit NamePluginCategory
OL08-00-010010 - OL 8 vendor-packaged system security patches and updates must be installed and up to date.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010050 - OL 8 must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010121 - The OL 8 operating system must not have accounts configured with blank or null passwords.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010150 - OL 8 operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010151 - OL 8 operating systems must require authentication upon booting into rescue mode.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010161 - OL 8 must prevent system daemons from using Kerberos for authentication.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010185 - The OL 8 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-010200 - OL 8 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010250 - The OL 8 "/var/log" directory must be owned by root.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

OL08-00-010331 - OL 8 library directories must have mode 755 or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010372 - OL 8 must prevent the loading of a new kernel for later execution.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010382 - OL 8 must restrict privilege elevation to authorized personnel.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010400 - OL 8 must implement certificate status checking for multifactor authentication.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010423 - OL 8 must clear memory when it is freed to prevent use-after-free attacks.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010472 - OL 8 must have the packages required to use the hardware random number generator entropy gatherer service.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010480 - The OL 8 SSH public host key files must have mode "0644" or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010490 - The OL 8 SSH private host key files must have mode "0600" or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010541 - OL 8 must use a separate file system for "/var/log".DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010650 - OL 8 must prevent files with the setuid and setgid bit set from being executed on file systems that are imported via Network File System (NFS).DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010670 - OL 8 must disable kernel dumps unless needed.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010671 - OL 8 must disable the "kernel.core_pattern".DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010710 - All OL 8 world-writable directories must be group-owned by root, sys, bin, or an application group.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010730 - All OL 8 local interactive user home directories must have mode "0750" or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010750 - All OL 8 local interactive user home directories defined in the "/etc/passwd" file must exist.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010760 - All OL 8 local interactive user accounts must be assigned a home directory upon creation.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-010830 - OL 8 must not allow users to override SSH environment variables.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020010 - OL 8 systems below version 8.2 must automatically lock an account when three unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020013 - OL 8 systems, versions 8.2 and above, must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020014 - OL 8 systems below version 8.2 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020015 - OL 8 systems, versions 8.2 and above, must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020018 - OL 8 systems below version 8.2 must prevent system messages from being presented when three unsuccessful logon attempts occur.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020023 - OL 8 systems, versions 8.2 and above, must include root when automatically locking an account until the locked account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020025 - OL 8 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020050 - OL 8 must be able to initiate directly a session lock for all connection types using smartcard when the smartcard is removed.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020090 - OL 8 must map the authenticated identity to the user or group account for PKI-based authentication.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020100 - OL 8 must ensure the password complexity module is enabled in the password-auth file.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020130 - OL 8 must enforce password complexity by requiring that at least one numeric character be used.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020280 - All OL 8 passwords must contain at least one special character.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020331 - OL 8 must not allow blank or null passwords in the system-auth file.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020353 - OL 8 must define default permissions for logon and non-logon shells.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030030 - The OL 8 Information System Security Officer (ISSO) and System Administrator (SA) (at a minimum) must have mail aliases to be notified of an audit processing failure.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030060 - The OL 8 audit system must take appropriate action when the audit storage volume is full.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030061 - The OL 8 audit system must audit local events.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030070 - OL 8 audit logs must have a mode of "0600" or less permissive to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030301 - OL 8 must generate audit records for any use of the "umount" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

WN11-UR-000075 - The 'Deny log on as a batch job' user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000085 - The 'Deny log on locally' user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000100 - The 'Force shutdown from a remote system' user right must only be assigned to the Administrators group.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL

WN11-UR-000130 - The 'Manage auditing and security log' user right must only be assigned to the Administrators group.DISA Microsoft Windows 11 STIG v2r9Windows

AUDIT AND ACCOUNTABILITY

WN11-UR-000165 - The 'Take ownership of files or other objects' user right must only be assigned to the Administrators group.DISA Microsoft Windows 11 STIG v2r9Windows

ACCESS CONTROL