Item Search

NameAudit NamePluginCategory
1.4 DTOO188CIS Microsoft Office System 2016 STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.6.11 Ensure the operating system implements certificate status checking for multifactor authenticationCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

1.17 DTOO410CIS Microsoft Office System 2016 STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.18 DTOO412CIS Microsoft Office System 2016 STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.19 DTOO416CIS Microsoft Office System 2016 STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.20 DTOO601CIS Microsoft Office System 2016 STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

2.6.1 Ensure fapolicyd is installedCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

DTOO224 - Outlook - Recipients of sent email must be unable to be added to the safe sender's list.DISA Microsoft Outlook 2010 STIG v1r14Windows

CONFIGURATION MANAGEMENT

DTOO225 - Outlook - Outlook Dial-up options to Warn user before allowing switch in dial-up access must be configured.DISA Microsoft Outlook 2010 STIG v1r14Windows

IDENTIFICATION AND AUTHENTICATION

DTOO226 - Outlook - Dial-up and Hang up Options for Outlook must be configured.DISA Microsoft Outlook 2010 STIG v1r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO227 - Outlook - Digital signatures must be allowed.DISA Microsoft Outlook 2010 STIG v1r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO229 - Outlook - Outlook must be enforced as the default email, calendar, and contacts program.DISA Microsoft Outlook 2010 STIG v1r14Windows

CONFIGURATION MANAGEMENT

DTOO278 - Outlook - Automatically configure user profile based on Active Directory primary SMTP address must be enforced.DISA Microsoft Outlook 2010 STIG v1r14Windows

CONFIGURATION MANAGEMENT

DTOO281 - Outlook - RSS feed synchronization with Common Feed List must be disallowed.DISA Microsoft Outlook 2010 STIG v1r14Windows

CONFIGURATION MANAGEMENT

DTOO290 - PowerPoint - Hidden markup options must be visible.DISA STIG Office 2010 PowerPoint v1r11Windows

CONFIGURATION MANAGEMENT

DTOO304 - Warning Bar settings for VBA macros must be configured.DISA STIG Microsoft Project 2016 v1r1Windows

CONFIGURATION MANAGEMENT

DTOO314 - Outlook - Default message format must be set to use Plain Text.DISA Microsoft Outlook 2010 STIG v1r14Windows

CONFIGURATION MANAGEMENT

DTOO320 - Outlook - Check e-mail addresses against addresses of certificates being used must be disallowed.DISA Microsoft Outlook 2010 STIG v1r14Windows

CONFIGURATION MANAGEMENT

GEN000242 - The system must use at least two time sources for clock synchronization - 'at least 2 servers are configured'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000290 - The system must not have unnecessary accounts - 'ftp does not exsit'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000410 - The FTPS/FTP service on the system must be configured with the DoD login banner - '/etc/ftpaccess.ctl contains herald'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000500 - Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000595 - Password hashes must have been generated using a FIPS 140-2 hashing algorithm - 'Verify no password hashes in /etc/passwd'DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000920 - The root account's home directory (other than /) must have mode 0700 - Not ApplicableDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001373 - The /etc/nsswitch.conf file must have mode 0644 or less permissive - Not ApplicableDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001700 - System start-up files must only execute programs owned by a privileged UID or an application.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001980 - The /etc/group file must not contain a plus (+) without defining entries for NIS+ netgroups - '/etc/group'DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001980 - The /etc/passwd file must not contain a plus (+) without defining entries for NIS+ netgroups - '/etc/passwd'DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001980 - The shosts.equiv file must not contain a plus (+) without defining entries for NIS+ netgroups - '~/shosts.equiv'DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN002400 - The system must be checked weekly for unauthorized setuid files, and unauthorized modification to authorized setuid files.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002660 - Auditing must be implemented.DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002720 - System must be configured to audit failed attempts to access files/programs - '/etc/security/audit/events FILE_Open exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002740 - The audit system must be configured to audit file deletions - '/etc/security/audit/config FILE_Unlink exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config DEV_Change exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config FILE_Fchpriv exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config FILE_Owner exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config FS_Mount exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/config PROC_Adjtime exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events FILE_Mknod exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events RESTORE_Import exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002760 - System must be configured to audit all admin/privileged/security actions - '/etc/security/audit/events USER_Remove exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002800 - System must be configured to audit login, logout, and session initiation - '/etc/security/audit/events INIT_Start exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002800 - System must be configured to audit login, logout, and session initiation - '/etc/security/audit/events USER_Login exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002800 - System must be configured to audit login, logout, and session initiation - 'User audit class assignments should be reviewed'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN002860 - Audit logs must be rotated daily.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003660 - The system must log authentication informational data - 'auth.*'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN003900 - The hosts.lpd file (or equivalent) must not contain a '+' character.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN004820 - Anonymous FTP must not be active on the system unless authorized.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN005120 - The TFTP daemon must be configured to vendor specs including a home directory owned by the TFTP userDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN005505 - The SSH daemon must be configured to only use FIPS 140-2 approved ciphers.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION