Item Search

NameAudit NamePluginCategory
1.3.1 Pre-authentication BannerCIS Cisco NX-OS v1.2.0 L1Cisco

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.2.1 Ensure DLP policies are enabledCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000020 - The Apache web server must perform server-side session management.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

ACCESS CONTROL

AS24-U2-000030 - The Apache web server must use encryption strength in accordance with the categorization of data hosted by the Apache web server when remote connections are provided.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000240 - The Apache web server must not perform user management for hosted applications.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

CONFIGURATION MANAGEMENT

AS24-U2-000350 - Users and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

CONFIGURATION MANAGEMENT

AS24-U2-000540 - The Apache web server must augment re-creation to a stable and known baseline.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000580 - The Apache web server document directory must be in a separate partition from the Apache web servers system files.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000620 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

AS24-U2-000650 - The Apache web server must set an absolute timeout for sessions.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000700 - Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

ACCESS CONTROL

JBOS-AS-000085 - JBoss must be configured to allow only the ISSM (or individuals or roles appointed by the ISSM) to select which loggable events are to be logged.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

JUEX-NM-000490 - The Juniper EX switch must use an an NTP service that is hosted by a trusted source or a DOD-compliant enterprise or local NTP server.DISA Juniper EX Series Network Device Management v2r4Juniper

IDENTIFICATION AND AUTHENTICATION

SLES-15-010419 - The SUSE operating system must use a file integrity tool to verify correct operation of all security functions.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-15-010560 - The SUSE operating system must remove all outdated software components after updated versions have been installed.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-15-020010 - The SUSE operating system must lock an account after three consecutive invalid access attempts.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-020050 - The SUSE operating system must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity after password expiration.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020060 - The SUSE operating system must never automatically remove or disable emergency administrator accounts.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-020090 - The SUSE operating system must not have unnecessary accounts.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-020104 - The SUSE operating system must not be configured to bypass password requirements for privilege escalation.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020120 - The SUSE operating system must display the date and time of the last successful account logon upon an SSH logon.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL

SLES-15-020160 - The SUSE operating system must require the change of at least eight of the total number of characters when passwords are changed.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020190 - The SUSE operating system must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-030010 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-15-030330 - The SUSE operating system must generate audit records for all uses of the sudoedit command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030480 - The SUSE operating system must generate audit records for all modifications to the lastlog file.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030570 - The Information System Security Officer (ISSO) and System Administrator (SA), at a minimum, must be alerted of a SUSE operating system audit processing failure event.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030660 - The SUSE operating system must allocate audit record storage capacity to store at least one week of audit records when audit records are not immediately sent to a central audit record storage facility.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030770 - The SUSE operating system must generate audit records for the /var/log/wtmp file.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030780 - The SUSE operating system must generate audit records for the /var/log/btmp file.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030790 - The SUSE operating system must off-load audit records onto a different system or media from the system being audited.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-030800 - Audispd must take appropriate action when the SUSE operating system audit storage is full.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

SLES-15-040040 - The SUSE operating system file integrity tool must be configured to verify Access Control Lists (ACLs).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040062 - The SUSE operating system must disable the systemd Ctrl-Alt-Delete burst key sequence.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040070 - All SUSE operating system local interactive users must have a home directory assigned in the /etc/passwd file.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040080 - All SUSE operating system local interactive user home directories defined in the /etc/passwd file must exist.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040110 - All SUSE operating system local initialization files must have mode 0740 or less permissive.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040140 - SUSE operating system file systems that contain user home directories must be mounted to prevent files with the setuid and setgid bit set from being executed.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040170 - SUSE operating system file systems that are being imported via Network File System (NFS) must be mounted to prevent binary files from being executed.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040200 - A separate file system must be used for SUSE operating system user home directories (such as /home or an equivalent).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040210 - The SUSE operating system must use a separate file system for /var.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040230 - The SUSE operating system SSH daemon must be configured to not allow authentication using known hosts authentication.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040240 - The SUSE operating system SSH daemon public host key files must have mode 0644 or less permissive.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040250 - The SUSE operating system SSH daemon private host key files must have mode 0640 or less permissive.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040260 - The SUSE operating system SSH daemon must perform strict mode checking of home directory configuration files.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040300 - The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040321 - The SUSE operating system must not forward Internet Protocol version 6 (IPv6) source-routed packets by default.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040330 - The SUSE operating system must prevent Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040360 - The SUSE operating system must not allow interfaces to send Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040450 - The SUSE operating system SSH server must be configured to use only FIPS-validated key exchange algorithms.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL