Item Search

NameAudit NamePluginCategory
1.1.1 Ensure 'Enforce password history' is set to '24 or more password(s)'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

IDENTIFICATION AND AUTHENTICATION

1.1.4 Ensure 'Minimum password length' is set to '14 or more character(s)'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

IDENTIFICATION AND AUTHENTICATION

1.2.1 (L1) Ensure 'Account lockout duration' is set to '15 or more minute(s)'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.2.1 Ensure 'Account lockout duration' is set to '15 or more minute(s)'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.56 SLES-15-010460CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.57 SLES-15-010470CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.73 OL08-00-010400CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

2.1.6 Ensure rsh server is not enabled - rloginCIS Distribution Independent Linux Server L1 v2.0.0Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.1.6 Ensure rsh server is not enabled - rshCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.1.8 Ensure telnet server is not enabledCIS Distribution Independent Linux Workstation L1 v2.0.0Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.7.1 Ensure 'Interactive logon: Do not display last user name' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.7.2 Ensure 'Interactive logon: Do not require CTRL+ALT+DEL' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.7.3 (BL) Ensure 'Interactive logon: Machine account lockout threshold' is set to '10 or fewer invalid logon attempts, but not 0'CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.3.7.3 (BL) Ensure 'Interactive logon: Machine account lockout threshold' is set to '10 or fewer invalid logon attempts, but not 0'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

2.3.7.5 Configure 'Interactive logon: Message text for users attempting to log on'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.7.6 Configure 'Interactive logon: Message title for users attempting to log on'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.7.8 Ensure 'Interactive logon: Prompt user to change password before expiration' is set to 'between 5 and 14 days'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.10.11 (L1) Ensure 'Network access: Sharing and security model for local accounts' is set to 'Classic - local users authenticate as themselves'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.10.11 Ensure 'Network access: Sharing and security model for local accounts' is set to 'Classic - local users authenticate as themselves'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.11.1 (L1) Ensure 'Network security: Allow Local System to use computer identity for NTLM' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

2.3.11.1 Ensure 'Network security: Allow Local System to use computer identity for NTLM' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

AIOS-16-014800 - Apple iOS/iPadOS 16 must be configured to disable Auto Unlock of the iPhone by an Apple Watch.MobileIron - DISA Apple iOS-iPadOS 16 STIG v2r2MDM

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

AIOS-17-014800 - Apple iOS/iPadOS 17 must be configured to disable 'Auto Unlock' of the iPhone by an Apple Watch - Auto Unlock of the iPhone by an Apple Watch.MobileIron - DISA Apple iOS/iPadOS 17 v2r2MDM

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

AIX7-00-001012 - AIX must use the SSH server to implement replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

ARBA-VN-000490 - The VPN Gateway must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).DISA HPE Aruba Networking AOS VPN STIG v1r1ArubaOS

IDENTIFICATION AND AUTHENTICATION

Big Sur - Disable Root Login for SSHNIST macOS Big Sur v1.4.0 - All ProfilesUnix

IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Guest Access to Shared Apple File Protocol FoldersNIST macOS Catalina v1.5.0 - All ProfilesUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Guest Access to Shared Apple File Protocol FoldersNIST macOS Catalina v1.5.0 - 800-53r4 HighUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Guest Access to Shared Apple File Protocol FoldersNIST macOS Catalina v1.5.0 - 800-53r5 LowUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Guest Access to Shared SMB FoldersNIST macOS Catalina v1.5.0 - 800-53r4 HighUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Root Login for SSHNIST macOS Catalina v1.5.0 - All ProfilesUnix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010400 - OL 8 must implement certificate status checking for multifactor authentication.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL09-00-000270 - OL 9 must have the openssl-pkcs11 package installed.DISA Oracle Linux 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

OL09-00-000285 - OL 9 must have the SSSD package installed.DISA Oracle Linux 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

OL09-00-000286 - OL 9 must use the SSSD package for multifactor authentication services.DISA Oracle Linux 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611165 - RHEL 9 must enable certificate based smart card authentication.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

SLEM-05-255010 - SLEM 5 must have SSH installed to protect the confidentiality and integrity of transmitted information.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010460 - The SUSE operating system must have the packages required for multifactor authentication to be installed.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010470 - The SUSE operating system must implement certificate status checking for multifactor authentication.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-20-010018 - Ubuntu 20.04 LTS must have the "SSSD" package installed.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-20-010019 - Ubuntu 20.04 LTS must use the "SSSD" package for multifactor authentication services.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-254010 - Ubuntu 22.04 LTS must have the "SSSD" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-254015 - Ubuntu 22.04 LTS must use the "SSSD" package for multifactor authentication services.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-24-100650 - Ubuntu 24.04 LTS must have the "SSSD" package installed.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-24-100660 - Ubuntu 24.04 LTS must use the "SSSD" package for multifactor authentication services.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

WN16-DC-000030 - The Kerberos service ticket maximum lifetime must be limited to 600 minutes or less.DISA Microsoft Windows Server 2016 STIG v2r10Windows

IDENTIFICATION AND AUTHENTICATION

WN16-DC-000050 - The Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less.DISA Microsoft Windows Server 2016 STIG v2r10Windows

IDENTIFICATION AND AUTHENTICATION

WN19-DC-000050 - Windows Server 2019 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less.DISA Microsoft Windows Server 2019 STIG v3r8Windows

IDENTIFICATION AND AUTHENTICATION

WN19-DC-000060 - Windows Server 2019 computer clock synchronization tolerance must be limited to five minutes or less.DISA Microsoft Windows Server 2019 STIG v3r8Windows

IDENTIFICATION AND AUTHENTICATION

WPAW-00-001600 - The Windows PAW must be configured to enforce two-factor authentication and use Active Directory for authentication management.DISA Microsoft Windows PAW STIG v3r2Windows

IDENTIFICATION AND AUTHENTICATION