Item Search

NameAudit NamePluginCategory
1.3 Set 'Enable Sender ID agent' to 'True'CIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

SYSTEM AND INFORMATION INTEGRITY

1.4 Set 'External send connector authentication: DNS Routing' to 'True'CIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.8 Set 'External send connector authentication: Ignore Start TLS' to 'False'CIS Microsoft Exchange Server 2013 Edge v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.9.4.2.2 Ensure 'Outlook Rich Text Options' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.9.6.1.3 Ensure 'Do not allow Outlook object model scripts to run for public folders' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.9.8.3.3 Ensure 'Read e-mail as plain text' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.9.8.4.3 Ensure 'Junk E-mail protection level: Select level:' is set to Enabled:HighCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND INFORMATION INTEGRITY

1.13 Set 'Message tracking logging - Transport' to 'True'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

AUDIT AND ACCOUNTABILITY

1.13.2.1.2 Ensure 'Missing CRLs' is set to Enabled:ErrorCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

IDENTIFICATION AND AUTHENTICATION

1.13.2.1.3 Ensure 'Missing Root Certificates' is set to Enabled:WarningCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

IDENTIFICATION AND AUTHENTICATION

1.13.2.1.4 Ensure 'Promote Level 2 errors as errors, not warnings' is set to DisabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND INFORMATION INTEGRITY

1.13.2.9 Ensure 'Signature Warning' is set to Enabled:Always warn about invalid signaturesCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.13.3.1.3 Ensure 'Do not prompt about Level 1 attachments when closing an item' is set to DisabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.13.3.1.4 Ensure 'Do not prompt about Level 1 attachments when sending an item' is set to DisabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

CONFIGURATION MANAGEMENT

1.13.3.1.5 Ensure 'Remove file extensions blocked as Level 1' is set to DisabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.13.4.2 Ensure 'Apply macro security settings to macros, add-ins and additional actions' is set to EnabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND INFORMATION INTEGRITY

1.14 Set 'Message tracking logging - Mailbox' to 'True'CIS Microsoft Exchange Server 2013 Mailbox v1.1.0Windows

AUDIT AND ACCOUNTABILITY

1.18 Set 'Maximum receive size - connector level' to '10240'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.86 PHTN-40-000223CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.89 PHTN-40-000226CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.90 PHTN-40-000227CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.91 PHTN-40-000228CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.92 PHTN-40-000229CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.12 Set 'Configure dial plan security' to 'Secured'CIS Microsoft Exchange Server 2013 UM v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.13 Set 'Allow access to voicemail without requiring a PIN' to 'False'CIS Microsoft Exchange Server 2013 UM v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

2.14 Set 'Retain deleted items for the specified number of days' to '14'CIS Microsoft Exchange Server 2013 Mailbox v1.1.0Windows

CONTINGENCY PLANNING

2.19 Set 'Require client MAPI encryption' to 'True'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.21 Set 'Require password' to 'True'CIS Microsoft Exchange Server 2013 CAS v1.1.0Windows

ACCESS CONTROL

3.8 Set 'Enable OOF messages to remote domains' to 'None'CIS Microsoft Exchange Server 2013 Hub v1.1.0Windows

CONFIGURATION MANAGEMENT

5.003 - Booting into alternate operating systems is permitted.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

5.017 - The user is allowed to launch Windows Messenger (MSN Messenger, .NET Messenger).DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

AIOS-13-013100 - Apple iOS/iPadOS must implement the management setting: disable paired Apple Watch.AirWatch - DISA Apple iOS/iPadOS 13 v2r1MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

FNFG-FW-000025 - The FortiGate firewall must generate traffic log entries containing information to establish when (date and time) the events occurred.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000050 - The FortiGate firewall must protect traffic log records from unauthorized access while in transit to the central audit server.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000075 - The FortiGate firewall implementation must manage excess bandwidth to limit the effects of packet flooding types of denial-of-service (DoS) attacks.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000090 - The FortiGate firewall must fail to a secure state if the firewall filtering functions fail unexpectedly.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000105 - If communication with the central audit server is lost, the FortiGate firewall must generate a real-time alert to, at a minimum, the SA and ISSO.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000110 - The FortiGate firewall must employ filters that prevent or limit the effects of all types of commonly known denial-of-service (DoS) attacks, including flooding, packet sweeps, and unauthorized port scanning.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000115 - The FortiGate firewall must apply ingress filters to traffic that is inbound to the network through any active external interface.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000120 - The FortiGate firewall must apply egress filters to traffic outbound from the network through any internal interface.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000130 - The FortiGate firewall must restrict traffic entering the VPN tunnels to the management network to only the authorized management packets based on destination address.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000145 - The FortiGate firewall must be configured to restrict it from accepting outbound packets that contain an illegitimate address in the source address field via an egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA Fortigate Firewall STIG v1r4FortiGate

CONFIGURATION MANAGEMENT

FNFG-FW-000150 - The FortiGate firewall must generate an alert that can be forwarded to, at a minimum, the Information System Security Officer (ISSO) and Information System Security Manager (ISSM) when denial-of-service (DoS) incidents are detected.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND INFORMATION INTEGRITY

FNFG-FW-000155 - The FortiGate firewall must allow authorized users to record a packet-capture-based IP, traffic type (TCP, UDP, or ICMP), or protocol.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000165 - The FortiGate firewall must generate traffic log records when attempts are made to send packets between security zones that are not authorized to communicate.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

PHTN-40-000223 - The Photon operating system must not forward IPv4 or IPv6 source-routed packets.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT

PHTN-40-000224 - The Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT

PHTN-40-000226 - The Photon operating system must prevent IPv4 Internet Control Message Protocol (ICMP) secure redirect messages from being accepted.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT

PHTN-40-000228 - The Photon operating system must log IPv4 packets with impossible addresses.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT

PHTN-40-000229 - The Photon operating system must use a reverse-path filter for IPv4 network traffic.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT