Item Search

NameAudit NamePluginCategory
1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS SUSE Linux Enterprise 16 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS Amazon Linux 2 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS Debian Linux 13 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS Debian Linux 12 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS Debian Linux 13 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

1.1.2.1.1 Ensure /tmp is tmpfs or a separate partitionCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

1.5.3 Ensure kernel.yama.ptrace_scope is configuredCIS Debian Linux 13 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

1.5.3 Ensure kernel.yama.ptrace_scope is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

1.7.2 Ensure GDM disable-user-list is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.6 Ensure net.ipv4.icmp_ignore_bogus_error_responses is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.6 Ensure net.ipv4.icmp_ignore_bogus_error_responses is configuredCIS Debian Linux 13 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.13 Ensure net.ipv4.conf.default.rp_filter is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.13 Ensure net.ipv4.conf.default.rp_filter is configuredCIS Amazon Linux 2 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.13 Ensure net.ipv4.conf.default.rp_filter is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.13 Ensure net.ipv4.conf.default.rp_filter is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.13 Ensure net.ipv4.conf.default.rp_filter is configuredCIS Debian Linux 13 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

GEN000560 - The system must not have accounts configured with blank or null passwords.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001160 - All files and directories must have a valid owner.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001610 - Run control scripts' lists of preloaded libraries must contain only absolute paths.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/.login'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/bashrc'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/csh.cshrc'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/environment'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/security/environ'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001845 - Global initialization files' library search paths must contain only absolute paths - '/etc/bashrc'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001845 - Global initialization files' library search paths must contain only absolute paths - '/etc/environment'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001845 - Global initialization files' library search paths must contain only absolute paths - '/etc/security/.login'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001850 - Global initialization files' lists of preloaded libraries must contain only absolute paths - '/etc/environment'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001850 - Global initialization files' lists of preloaded libraries must contain only absolute paths - '/etc/security/environ'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001900 - All local initialization files' executable search paths must contain only absolute paths.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001901 - Local initialization files' library search paths must contain only absolute paths - 'LD_LIBRARY_PATH'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002430 - Removable media, remote file systems and any file system not containing approved device files must be mounted with nodevDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003510 - Kernel core dumps must be disabled unless needed - 'secondary dump device'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004560 - The SMTP service's SMTP greeting must not provide version information.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN005480 - The syslog daemon must not accept remote messages unless it is a syslog server documented using site-defined procedures.DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN005526 - The SSH daemon must not permit Kerberos authentication unless needed.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN005540 - The SSH daemon must be configured for IP filtering - '/etc/hosts.allow'DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN005540 - The SSH daemon must be configured for IP filtering - '/etc/hosts.deny'DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN006230 - Samba must be configured to use encrypted passwords.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN006620 - The system's access control program must be configured to grant or deny system access to specific hosts - 'hosts.deny ALL:ALL'DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN007950 - The system must not respond to ICMPv6 echo requests sent to a broadcast address.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN008600 - The system must be configured to only boot from the system boot device.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN008640 - The system must not use removable media as the boot loader - 'both'DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN008640 - The system must not use removable media as the boot loader - 'service'DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

WINCC-000029 - Group Policies must be refreshed in the background if the user is logged on.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

WINER-000009 - The system must be configured to send error reports on TCP port 1232.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

WINFW-000001 - A host-based firewall must be installed and enabled on the system.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

WINGE-000100 - EMET v5.5 or later must be installed on the system.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT