Item Search

NameAudit NamePluginCategory
1.24 CISC-ND-000620CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

IDENTIFICATION AND AUTHENTICATION

1.27 SOL-11.1-010380CIS Solaris 11 SPARC STIG v1.0.0 CAT IUnix

AUDIT AND ACCOUNTABILITY

1.27 SOL-11.1-010380CIS Solaris 11 X86 STIG v1.0.0 CAT IUnix

AUDIT AND ACCOUNTABILITY

1.35 PHTN-40-000079CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IUnix

ACCESS CONTROL

1.101 PHTN-40-000239CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IUnix

ACCESS CONTROL

1.209 RHEL-09-255040CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IUnix

IDENTIFICATION AND AUTHENTICATION

AIOS-01-080006 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.MobileIron - DISA Apple iOS 10 v1r3MDM

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-003320 - The AlmaLinux 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-003540 - The AlmaLinux OS 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

APPL-11-002063 - The macOS system must enforce access restrictions.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002064 - The macOS system must have the security assessment policy subsystem enabled.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-12-002064 - The macOS system must have the security assessment policy subsystem enabled.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-13-002064 - The macOS system must have the security assessment policy subsystem enabled.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-15-002069 - The macOS system must require an administrator password to modify systemwide preferences.DISA Apple macOS 15 Sequoia STIG v1r7Unix

ACCESS CONTROL

APPL-26-002069 - The macOS system must require an administrator password to modify systemwide preferences.DISA Apple macOS 26 Tahoe STIG v1r2Unix

ACCESS CONTROL

ARST-RT-000450 - The Arista perimeter router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-000120 - Amazon Linux 2023 must check the GPG signature of software packages originating from external software repositories before installation.DISA Amazon Linux 2023 STIG v1r4Unix

CONFIGURATION MANAGEMENT

CASA-VN-000210 - The Cisco ASA must be configured to use a Diffie-Hellman (DH) Group of 16 or greater for Internet Key Exchange (IKE) Phase 1 - IKE Phase 1.DISA STIG Cisco ASA VPN v2r2Cisco

ACCESS CONTROL

CASA-VN-000640 - The Cisco VPN remote access server must be configured to use AES256 or greater encryption for the Internet Key Exchange (IKE) Phase 1 to protect confidentiality of remote access sessions - IKE Phase 1 to protect confidentiality of remote access sessions.DISA STIG Cisco ASA VPN v2r2Cisco

ACCESS CONTROL

CASA-VN-000650 - The Cisco ASA VPN remote access server must be configured to use AES256 or greater encryption for the IPsec security association to protect the confidentiality of remote access sessions - AES encryption for the IPsec security association to protect the confidentiality of remote access sessions.DISA STIG Cisco ASA VPN v2r2Cisco

ACCESS CONTROL

CD12-00-011700 - PostgreSQL must prevent non-privileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

ACCESS CONTROL

EPAS-00-003300 - The EDB Postgres Advanced Server software installation account must be restricted to authorized users.EnterpriseDB PostgreSQL Advanced Server DB v2r1PostgreSQLDB

CONFIGURATION MANAGEMENT

ESXI-70-000074 - The ESXi host must exclusively enable Transport Layer Security (TLS) 1.2 for all endpoints.DISA VMware vSphere 7.0 ESXi STIG v1r4 VMwareVMware

SYSTEM AND COMMUNICATIONS PROTECTION

FGFW-ND-000265 - The FortiGate device must implement cryptographic mechanisms using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions.DISA Fortigate Firewall NDM STIG v1r4FortiGate

MAINTENANCE

GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use.MobileIron - DISA Google Android 16 COBO STIG v1r1MDM

CONFIGURATION MANAGEMENT

GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use.MobileIron - DISA Google Android 16 COPE STIG v1r1MDM

CONFIGURATION MANAGEMENT

MD4X-00-002100 - MongoDB software installation account must be restricted to authorized users.DISA STIG MongoDB Enterprise Advanced 4.x v1r4 OSUnix

CONFIGURATION MANAGEMENT

MD8X-00-002500 - MongoDB software installation account must be restricted to authorized users.DISA MongoDB Enterprise Advanced 8.x STIG v1r1 UnixUnix

CONFIGURATION MANAGEMENT

MYS8-00-000100 - MySQL Database Server 8.0 must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

ACCESS CONTROL

MYS8-00-012000 - The MySQL Database Server 8.0 must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

MYS8-00-012100 - The MySQL Database Server 8.0 must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-000800 - Oracle Database must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

ACCESS CONTROL

O19C-00-000800 - Oracle Database must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

ACCESS CONTROL

O19C-00-017700 - Oracle Database must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures.DISA Oracle Database 19c STIG v1r5 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010185 - The OL 8 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL09-00-000254 - OL 9 SSH server must be configured to use only ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Oracle Linux 9 STIG v1r6Unix

ACCESS CONTROL

OL09-00-000262 - OL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Oracle Linux 9 STIG v1r6Unix

ACCESS CONTROL

RHEL-08-010280 - RHEL 8 IP tunnels must use FIPS 140-3-approved cryptographic algorithms.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-08-010290 - The RHEL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-09-255065 - The RHEL 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-10-300070 - RHEL 10 must use FIPS 140-3-approved cryptographic algorithms for IP tunnels.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700950 - RHEL 10 must disable the systemd Ctrl-Alt-Delete burst key sequence.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700960 - RHEL 10 must disable the x86 Ctrl-Alt-Delete key sequence.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

SHPT-00-000683 - SharePoint-specific malware (i.e., anti-virus) software must be integrated and configured - 'Scan Documents on Download is enabled'DISA STIG SharePoint 2010 v1r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SLEM-05-214015 - The SLEM 5 tool zypper must have gpgcheck enabled.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

CONFIGURATION MANAGEMENT

SLEM-05-255055 - SLEM 5 SSH server must be configured to use only FIPS 140-2/140-3 validated key exchange algorithms.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

ACCESS CONTROL

SQLD-22-000100 - SQL Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA Microsoft SQL Server 2022 Database STIG v1r3MS_SQLDB

ACCESS CONTROL

SQLI-22-006700 - SQL Server software installation account must be restricted to authorized users.DISA Microsoft SQL Server 2022 Instance STIG v1r4 MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT

SYMP-AG-000030 - Symantec ProxySG providing forward proxy intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52 - server.connection.negotiated_cipherDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

ACCESS CONTROL

WN11-00-000031 - Windows 11 systems must use a BitLocker PIN for pre-boot authentication.DISA Microsoft Windows 11 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION