Item Search

NameAudit NamePluginCategory
1.29 UBTU-24-100900CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.103 UBTU-22-612015CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

20.13 (L1) Ensure 'Web browser is supported and secured'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-18-015500 - Apple iOS/iPadOS 18 must disable the download of iOS/iPadOS beta updates.AirWatch - DISA Apple iOS/iPadOS 18 v2r3MDM

CONFIGURATION MANAGEMENT

AIOS-18-015500 - Apple iOS/iPadOS 18 must disable the download of iOS/iPadOS beta updates.MobileIron - DISA Apple iOS/iPadOS 18 v2r3MDM

CONFIGURATION MANAGEMENT

ALMA-09-034010 - AlmaLinux OS 9 must have the openssl-pkcs11 package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

DB2X-00-008000 - DB2 must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged statusDISA STIG IBM DB2 v10.5 LUW v2r1 DatabaseIBM_DB2DB

CONFIGURATION MANAGEMENT

GOOG-12-006300 - Google Android 12 must be configured to lock the display after 15 minutes (or less) of inactivity.MobileIron - DISA Google Android 12 COBO v1r2MDM

ACCESS CONTROL

GOOG-12-007700 - Google Android 12 must be configured to display the DoD advisory warning message at startup or each time the user unlocks the device.MobileIron - DISA Google Android 12 COPE v1r2MDM

ACCESS CONTROL

GOOG-12-007700 - Google Android 12 must be configured to display the DoD advisory warning message at startup or each time the user unlocks the device.AirWatch - DISA Google Android 12 COBO v1r2MDM

ACCESS CONTROL

GOOG-12-007700 - Google Android 12 must be configured to display the DoD advisory warning message at startup or each time the user unlocks the device.MobileIron - DISA Google Android 12 COBO v1r2MDM

ACCESS CONTROL

GOOG-12-009000 - Google Android 12 must be configured to disable multiuser modes.AirWatch - DISA Google Android 12 COBO v1r2MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

GOOG-12-009000 - Google Android 12 must be configured to disable multiuser modes.MobileIron - DISA Google Android 12 COBO v1r2MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

GOOG-12-009000 - Google Android 12 must be configured to disable multiuser modes.MobileIron - DISA Google Android 12 COPE v1r2MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

GOOG-12-009400 - Google Android 12 must be configured to disable Bluetooth or configured via User Based Enforcement (UBE) to allow Bluetooth for only Headset Profile (HSP), Hands-Free Profile (HFP), and Serial Port Profile (SPP).AirWatch - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-009400 - Google Android 12 must be configured to disable Bluetooth or configured via User Based Enforcement (UBE) to allow Bluetooth for only Headset Profile (HSP), Hands-Free Profile (HFP), and Serial Port Profile (SPP).MobileIron - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-012100 - Google Android 12 must allow only the administrator (EMM) to install/remove DoD root and intermediate PKI certificates.MobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-012200 - Google Android 12 must be configured to disable all data signaling over [assignment: list of externally accessible hardware ports (for example, USB)].AirWatch - DISA Google Android 12 COBO v1r2MDM

ACCESS CONTROL

OL08-00-030301 - OL 8 must generate audit records for any use of the "umount" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030310 - OL 8 must generate audit records for any use of the "unix_update" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030312 - OL 8 must generate audit records for any use of the "postqueue" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030330 - OL 8 must generate audit records for any use of the "setfacl" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030340 - OL 8 must generate audit records for any use of the "pam_timestamp_check" command.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030590 - OL 8 must generate audit records for any attempted modifications to the "faillock" log file.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030601 - OL 8 must enable auditing of processes that start prior to the audit daemon.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL08-00-030610 - OL 8 must allow only the Information System Security Manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030620 - OL 8 audit tools must have a mode of "0755" or less permissive.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

OL08-00-030741 - OL 8 must disable the chrony daemon from acting as a server.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-030742 - OL 8 must disable network management of the chrony daemon.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040010 - OL 8 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040020 - OL 8 must cover or disable the built-in or attached camera when not in use.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040080 - OL 8 must be configured to disable the ability to use USB mass storage devices.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040100 - A firewall must be installed on OL 8.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-040101 - A firewall must be active on OL 8.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

OL08-00-040125 - OL 8 must mount "/tmp" with the "noexec" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040127 - OL 8 must mount "/var/log" with the "nosuid" option.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040135 - The OL 8 "fapolicy" module must be installed.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040141 - OL 8 must enable the USBGuard.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL08-00-040159 - All OL 8 networked systems must have SSH installed.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-040250 - OL 8 must not forward IPv6 source-routed packets by default.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040259 - OL 8 must not enable IPv4 packet forwarding unless the system is a router.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040279 - OL 8 must ignore IPv4 Internet Control Message Protocol (ICMP) redirect messages.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040285 - OL 8 must use reverse path filtering on all IPv4 interfaces.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040286 - OL 8 must enable hardening for the Berkeley Packet Filter Just-in-time compiler.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040290 - OL 8 must be configured to prevent unrestricted mail relaying.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040320 - The graphical display manager must not be installed on OL 8 unless approved.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040350 - If the Trivial File Transfer Protocol (TFTP) server is required, the OL 8 TFTP daemon must be configured to operate in secure mode.DISA Oracle Linux 8 STIG v2r9Unix

CONFIGURATION MANAGEMENT

OL08-00-040400 - OL 8 must prevent nonprivileged users from executing privileged functions, including disabling, circumventing, or altering implemented security safeguards/countermeasures.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL

RHEL-10-200620 - RHEL 10 must have the "opensc" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010320 - The SUSE operating system, for all network connections associated with SSH traffic, must immediately terminate at the end of the session or after 10 minutes of inactivity.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION