Item Search

NameAudit NamePluginCategory
OL08-00-020262 - The OL 8 lastlog command must have a mode of "0750" or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020270 - OL 8 must automatically expire temporary accounts within 72 hours.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-020290 - OL 8 must prohibit the use of cached authentications after one day.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-020300 - OL 8 must prevent the use of dictionary words for passwords.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-020332 - OL 8 must not allow blank or null passwords in the password-auth file.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030000 - The OL 8 audit system must be configured to audit the execution of privileged functions and prevent all software from executing at higher privilege levels than users executing the software.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-030010 - Cron logging must be implemented in OL 8.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030062 - OL 8 must label all offloaded audit logs before sending them to the central log server.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030120 - The OL 8 audit log directory must have a mode of 0700 or less permissive to prevent unauthorized read access.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030170 - OL 8 must generate audit records for all account creation events that affect "/etc/group".DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030171 - OL 8 must generate audit records for all account creations, modifications, disabling, and termination events that affect "/etc/sudoers".DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030190 - OL 8 must generate audit records for any use of the "su" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030260 - OL 8 must generate audit records for any uses of the "chcon" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030311 - OL 8 must generate audit records for any use of the "postdrop" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030320 - OL 8 must generate audit records for any use of the "ssh-keysign" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030400 - OL 8 must generate audit records for any use of the "crontab" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030420 - OL 8 must generate audit records for any use of the "truncate", "ftruncate", "creat", "open", "openat", and "open_by_handle_at" system calls.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030550 - OL 8 must generate audit records for any use of the "sudo" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030580 - OL 8 must generate audit records for any use of the "kmod" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030602 - OL 8 must allocate an "audit_backlog_limit" of sufficient size to capture processes that start prior to the audit daemon.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030630 - OL 8 audit tools must be owned by root.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030680 - OL 8 must have the packages required for encrypting offloaded audit logs installed.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030690 - The OL 8 audit records must be offloaded onto a different system or storage media from the system being audited.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030720 - OL 8 must authenticate the remote logging server for offloading audit logs.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-040002 - OL 8 must not have the sendmail package installed.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040021 - OL 8 must not have the asynchronous transfer mode (ATM) kernel module installed if not required for operational support.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040111 - OL 8 Bluetooth must be disabled.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-040124 - OL 8 must mount "/tmp" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040126 - OL 8 must mount "/var/log" with the "nodev" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040128 - OL 8 must mount "/var/log" with the "noexec" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040129 - OL 8 must mount "/var/log/audit" with the "nodev" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040133 - OL 8 must mount "/var/tmp" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040139 - OL 8 must have the USBGuard installed.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040161 - OL 8 must force a frequent session key renegotiation for SSH connections to the server.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-040190 - The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for OL 8 operational support.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040210 - OL 8 must prevent IPv6 Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040262 - OL 8 must not accept router advertisements on all IPv6 interfaces by default.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040282 - OL 8 must restrict the use of "ptrace" to descendant processes.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040360 - A File Transfer Protocol (FTP) server package must not be installed unless mission essential on OL 8.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040380 - OL 8 must not have the "iprutils" package installed if not required for operational support.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

WNDF-AV-000001 - Microsoft Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000019 - Microsoft Defender AV must be configured to monitor for file and program activity.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000028 - Microsoft Defender AV spyware definition age must not exceed 7 days.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000031 - Microsoft Defender AV must be configured for automatic remediation action to be taken for threat alert level Severe.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000038 - Microsoft Defender AV must be configured to block Win32 imports from macro code in Office.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000045 - Microsoft Defender AV must block untrusted and unsigned processes that run from USB.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000046 - Microsoft Defender AV must use advanced protection against ransomware.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000047 - Microsoft Defender AV must audit process creations originating from PSExec and WMI commands.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000049 - Microsoft Defender AV must audit executable files from running unless they meet a prevalence, age, or trusted list criterion.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000052 - Microsoft Defender AV must configure local administrator merge behavior for lists.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION