Item Search

NameAudit NamePluginCategory
1.1.11 Ensure separate partition exists for /var/logCIS SUSE Linux Enterprise Server 11 L2 v2.1.1Unix

AUDIT AND ACCOUNTABILITY

1.1.11 Ensure separate partition exists for /var/logCIS SUSE Linux Enterprise Workstation 11 L2 v2.1.1Unix

AUDIT AND ACCOUNTABILITY

1.1.11 Ensure separate partition exists for /var/logCIS Ubuntu Linux 18.04 LXD Host L2 Workstation v1.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.12 Ensure separate partition exists for /homeCIS Debian 8 Server L2 v2.0.2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.1.13 Ensure separate partition exists for /homeCIS CentOS 6 Server L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

1.1.13 Ensure separate partition exists for /homeCIS Red Hat 6 Server L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

1.1.15 Ensure separate partition exists for /var/logCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

AUDIT AND ACCOUNTABILITY

1.1.17 Ensure separate partition exists for /homeCIS Ubuntu Linux 16.04 LTS Workstation L2 v2.0.0Unix

CONFIGURATION MANAGEMENT

2.9.1 Ensure External Intelligence Extensions Is DisabledMobileIron - CIS Apple iPadOS 26 v1.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.9.1 Ensure External Intelligence Extensions Is DisabledAirWatch - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.9.1 Ensure External Intelligence Extensions Is DisabledAirWatch - CIS Apple iOS 26 Benchmark v1.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

2.9.1 Ensure External Intelligence Extensions Is DisabledAirWatch - CIS Apple iPadOS 26 v1.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.82 (L1) Ensure 'List of types that should be excluded from synchronization' is set to 'Enabled: passwords'CIS Google Chrome Group Policy v1.0.0 L1Windows

CONFIGURATION MANAGEMENT

3.10.1 Ensure External Intelligence Extensions Is DisabledMobileIron - CIS Apple iPadOS 18 v2.0.0 L1 Institution OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.2.2.12 Ensure the device code sign-in flow is blockedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

5.4 Ensure all WildFire session information settings are enabledCIS Palo Alto Firewall 10 v1.3.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

5.4 Ensure all WildFire session information settings are enabledCIS Palo Alto Firewall 11 v1.2.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

18.5.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2008 R2 Domain Controller Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.5.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2008 Domain Controller Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.5.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Windows 7 Workstation Level 2 v3.2.0Windows

CONFIGURATION MANAGEMENT

18.6.10.2 (L1) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Windows Server 2012 MS L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.6.10.2 (L2) Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L2Windows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.6.10.2 Ensure 'Turn off Microsoft Peer-to-Peer Networking Services' is set to 'Enabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

ALMA-09-001340 - AlmaLinux OS 9 must prevent a user from overriding the session idle-delay setting for the graphical user interface.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-001450 - AlmaLinux OS 9 must initiate a session lock for graphical user interfaces when the screensaver is activated.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-002880 - All AlmaLinux OS 9 remote access methods must be monitored.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-003320 - The AlmaLinux 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-003540 - The AlmaLinux OS 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-005410 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-005960 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-046660 - AlmaLinux OS 9 must audit all uses of the delete_module, init_module and finit_module system calls.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-046880 - AlmaLinux OS 9 must produce audit records containing information to establish the identity of any individual or process associated with the event.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-047760 - AlmaLinux OS 9 must generate audit records for any use of the "umount" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-047980 - AlmaLinux OS 9 must enable auditing of processes that start prior to the audit daemon.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-048090 - AlmaLinux OS 9 must audit all uses of the truncate, ftruncate, creat, open, openat, and open_by_handle_at system calls.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-048200 - AlmaLinux OS 9 must generate audit records for any use of the "chacl" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-048640 - AlmaLinux OS 9 must audit all uses of the chown, fchown, fchownat, and lchown system calls.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-048750 - AlmaLinux OS 9 must generate audit records for any use of the "chsh" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-050180 - AlmaLinux OS 9 must generate audit records for any use of the "setfacl" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-050730 - AlmaLinux OS 9 must generate audit records for any use of the "sudoedit" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

ALMA-09-051940 - AlmaLinux OS 9 must use a separate file system for the system audit data path.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-052820 - AlmaLinux OS 9 must encrypt, via the gtls driver, the transfer of audit records offloaded onto a different system or media from the system being audited via rsyslog.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-053590 - AlmaLinux OS 9 must notify the system administrator (SA) and information system security officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent usage.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054030 - AlmaLinux OS 9 audit system must take appropriate action when an error writing to the audit storage volume occurs.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-056010 - AlmaLinux OS 9 audit logs must be owned by root to prevent unauthorized read access.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

AUDIT AND ACCOUNTABILITY

GOOG-14-006700 - Google Android 14 allowlist must be configured to not include applications with the following characteristics:MobileIron - DISA Google Android 14 COBO STIG v2r5MDM

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

GOOG-14-006700 - Google Android 14 allowlist must be configured to not include applications with the following characteristics:MobileIron - DISA Google Android 14 COPE STIG v2r5MDM

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION