Item Search

NameAudit NamePluginCategory
1.2.6 - AirWatch - Disable 'plug-ins'AirWatch - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

1.2.6 - MobileIron - Disable 'plug-ins' - 'Samsung SAFE'MobileIron - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

1.412 RHEL-10-800110CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.2 Ensure time set is within appropriate limitsCIS Apple OSX 10.9 L1 v1.3.0Unix

CONFIGURATION MANAGEMENT

3.3 Ensure that MongoDB is run using a non-privileged, dedicated service accountCIS MongoDB 8 v1.0.0 L1 WindowsWindows

ACCESS CONTROL

3.3 Ensure that MongoDB is run using a non-privileged, dedicated service accountCIS MongoDB 5 v1.2.0 L1 UnixUnix

ACCESS CONTROL

5.7 Do not enable the "root" accountCIS Apple OSX 10.9 L1 v1.3.0Unix

ACCESS CONTROL

5.18 Install an approved tokend for smartcard authenticationCIS Apple OSX 10.9 L2 v1.3.0Unix

IDENTIFICATION AND AUTHENTICATION

CIS_Red_Hat_EL7_STIG_v2.0.0_L1_Server.audit from CIS Red Hat Enterprise Linux 7 STIG v2.0.0CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix
CIS_Red_Hat_EL7_STIG_v2.0.0_L2_Server.audit from CIS Red Hat Enterprise Linux 7 STIG v2.0.0CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 ServerUnix
CIS_Red_Hat_Enterprise_Linux_8_STIG_v2.0.0_L1_Workstation.audit from CIS Red Hat Enterprise Linux 8 STIG v2.0.0CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 WorkstationUnix
CIS_Red_Hat_Enterprise_Linux_8_STIG_v2.0.0_L2_Server.audit from CIS Red Hat Enterprise Linux 8 STIG v2.0.0CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 ServerUnix
CIS_Red_Hat_Enterprise_Linux_8_STIG_v2.0.0_L2_Workstation.audit from CIS Red Hat Enterprise Linux 8 STIG v2.0.0CIS Red Hat Enterprise Linux 8 STIG v2.0.0 L2 WorkstationUnix
CIS_Red_Hat_Enterprise_Linux_8_STIG_v2.0.0_STIG.audit from CIS Red Hat Enterprise Linux 8 STIG v2.0.0CIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix
CIS_Red_Hat_Enterprise_Linux_9_STIG_v1.0.0_CAT_I.audit from CIS Red Hat Enterprise Linux 9 STIG v1.0.0CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IUnix
CIS_Red_Hat_Enterprise_Linux_9_STIG_v1.0.0_CAT_II.audit from CIS Red Hat Enterprise Linux 9 STIG v1.0.0CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IIUnix
CIS_Red_Hat_Enterprise_Linux_9_STIG_v1.0.0_CAT_III.audit from CIS Red Hat Enterprise Linux 9 STIG v1.0.0CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IIIUnix
CIS_Red_Hat_Enterprise_Linux_10_STIG_v1.0.0_CAT_I.audit from CIS Red Hat Enterprise Linux 10 STIG v1.0.0CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IUnix
CIS_Red_Hat_Enterprise_Linux_10_STIG_v1.0.0_CAT_II.audit from CIS Red Hat Enterprise Linux 10 STIG v1.0.0CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix
CIS_Red_Hat_Enterprise_Linux_10_STIG_v1.0.0_CAT_III.audit from CIS Red Hat Enterprise Linux 10 STIG v1.0.0CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIIUnix
CIS_SUSE_Linux_Enterprise_Server_15_STIG_v1.0.0_CAT_I.audit from CIS SUSE Linux Enterprise Server 15 STIG v1.0.0CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IUnix
CIS_SUSE_Linux_Enterprise_Server_15_STIG_v1.0.0_CAT_II.audit from CIS SUSE Linux Enterprise Server 15 STIG v1.0.0CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IIUnix
CIS_SUSE_Linux_Enterprise_Server_15_STIG_v1.0.0_CAT_III.audit from CIS SUSE Linux Enterprise Server 15 STIG v1.0.0CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IIIUnix
DISA_STIG_McAfee_VSEL_1.9.x_2.0.x_Managed_Client_v1r5.audit from DISA McAfee VSEL 1.9/2.0 Managed Client v1r5 STIGMcAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5Unix
DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_User_Interface_UI_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v2r2DISA VMware vSphere 8.0 vCenter Appliance User Interface UI STIG v2r2Unix
DTAVSEL-017 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to deny access to the file if scanning fails.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-018 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Access scanner must be configured to allow access to files if scanning times out.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-100 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x must be configured to run a scheduled On-Demand scan at least once a week.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Local Client v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

DTAVSEL-113 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Demand scanner must be configured to include all local drives and their sub-directories.McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

EPAS-00-000800 - The EDB Postgres Advanced Server must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

ACCESS CONTROL

EPAS-00-002400 - The EDB Postgres Advanced Server must be configurable to overwrite audit log records, oldest first (First-In-First-Out [FIFO]), in the event of unavailability of space for more audit log records.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

AUDIT AND ACCOUNTABILITY

EPAS-00-002700 - The audit information produced by the EDB Postgres Advanced Server must be protected from unauthorized modification.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

AUDIT AND ACCOUNTABILITY

EPAS-00-004200 - The EDB Postgres Advanced Server must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

IDENTIFICATION AND AUTHENTICATION

EPAS-00-006100 - Access to database files must be limited to relevant processes and to authorized, administrative users.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

EPAS-00-007400 - The EDB Postgres Advanced Server must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

ACCESS CONTROL

O121-C2-012900 - The DBMS must use multifactor authentication for access to user accounts.DISA Oracle Database 12c STIG v3r5 UnixUnix

IDENTIFICATION AND AUTHENTICATION

O121-C2-012900 - The DBMS must use multifactor authentication for access to user accounts.DISA Oracle Database 12c STIG v3r5 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

PHTN-67-000012 - The Photon operating system must be configured to audit the execution of privileged functions - uid 64DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020240 - The SUSE operating system must generate audit records for all uses of the privileged functions.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

SPLK-CL-000060 - Splunk Enterprise must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix

ACCESS CONTROL

SPLK-CL-000100 - Splunk Enterprise installation directories must be secured.DISA STIG Splunk Enterprise 7.x for Windows v3r2 OSWindows

AUDIT AND ACCOUNTABILITY

SPLK-CL-000120 - The System Administrator (SA) and Information System Security Manager (ISSM) must configure the retention of the log records based on the defined security plan.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix

AUDIT AND ACCOUNTABILITY

SPLK-CL-000175 - Splunk Enterprise forwarders must be configured with Indexer Acknowledgement enabled.DISA STIG Splunk Enterprise 7.x for Windows v3r2 OSWindows

CONFIGURATION MANAGEMENT

SPLK-CL-000190 - Splunk Enterprise installation directories must be secured.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix

AUDIT AND ACCOUNTABILITY

SPLK-CL-000340 - Splunk Enterprise must be configured to enforce password complexity by requiring that at least one uppercase character be used.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000360 - Splunk Enterprise must be configured to enforce password complexity by requiring that at least one numeric character be used.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000400 - Splunk Enterprise must be configured to enforce a 60-day maximum password lifetime restriction.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000500 - Splunk Enterprise must use a version supported by the vendor.DISA STIG Splunk Enterprise 7.x for Windows v3r2 OSWindows

SYSTEM AND INFORMATION INTEGRITY

SPLK-CL-000510 - Splunk Enterprise must use a version supported by the vendor.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG OSUnix

SYSTEM AND INFORMATION INTEGRITY

WN10-UR-000090 - The Deny log on through Remote Desktop Services user right on Windows 10 workstations must at a minimum be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.DISA Microsoft Windows 10 STIG v3r6Windows

ACCESS CONTROL