Item Search

NameAudit NamePluginCategory
1.1.3 Ensure 'Minimum password age' is set to '1 or more day(s)'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.1.6 (L1) Ensure 'Store passwords using reversible encryption' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

IDENTIFICATION AND AUTHENTICATION

1.1.6 Ensure 'Store passwords using reversible encryption' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

IDENTIFICATION AND AUTHENTICATION

1.23 APPL-15-000090CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.23 APPL-26-000090CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.41 AZLX-23-001115CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.45 RHEL-10-200611CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.46 RHEL-10-200612CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.58 EX19-MB-000203CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIWindows

IDENTIFICATION AND AUTHENTICATION

1.186 AZLX-23-002595CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-033570 - AlmaLinux OS 9 must have the pcsc-lite package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

AOSX-14-000040 - The macOS system must use replay-resistant authentication mechanisms and implement cryptographic mechanisms to protect the integrity of and verify remote disconnection at the termination of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions - OpenSSH VersionDISA STIG Apple Mac OSX 10.14 v2r6Unix

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

AOSX-14-000040 - The macOS system must use replay-resistant authentication mechanisms and implement cryptographic mechanisms to protect the integrity of and verify remote disconnection at the termination of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions - SSHD currently runningDISA STIG Apple Mac OSX 10.14 v2r6Unix

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

AOSX-14-000040 - The macOS system must use replay-resistant authentication mechanisms and implement cryptographic mechanisms to protect the integrity of and verify remote disconnection at the termination of nonlocal maintenance and diagnostic communications, when used for nonlocal maintenance sessions - SSHD service disabledDISA STIG Apple Mac OSX 10.14 v2r6Unix

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-11-001100 - The macOS system must require individuals to be authenticated with an individual authenticator prior to using a group authenticator.DISA STIG Apple macOS 11 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

APPL-13-001100 - The macOS system must require individuals to be authenticated with an individual authenticator prior to using a group authenticator.DISA STIG Apple macOS 13 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

AZLX-23-002595 - Amazon Linux 2023 must ensure the pcscd socket is active.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

CD16-00-003600 - PostgreSQL must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).DISA Crunchy Data Postgres 16 STIG v1r3 UnixUnix

IDENTIFICATION AND AUTHENTICATION

ESXI-70-000038 - ESXi hosts using Host Profiles and/or Auto Deploy must use the vSphere Authentication Proxy to protect passwords when adding themselves to Active Directory.DISA VMware vSphere 7.0 ESXi STIG v1r4 VMwareVMware

IDENTIFICATION AND AUTHENTICATION

GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.AirWatch - DISA Google Android 12 COPE v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.AirWatch - DISA Google Android 12 COBO v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-13-707200 - Google Android 13 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MobileIron - DISA Google Android 13 BYOAD v1r3MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-15-007200 - Google Android 15 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MobileIron - DISA Google Android 15 COBO STIG v1r5MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-16-007200 - Google Android 16 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.AirWatch - DISA Google Android 16 COBO STIG v1r3MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-16-007200 - Google Android 16 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.AirWatch - DISA Google Android 16 COPE STIG v1r3MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-16-007200 - Google Android 16 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MobileIron - DISA Google Android 16 COPE STIG v1r3MDM

IDENTIFICATION AND AUTHENTICATION

HONW-13-007200 - Honeywell Android 13 must be configured to disable trust agents.MobileIron - DISA Honeywell Android 13 COPE STIG v1r1MDM

IDENTIFICATION AND AUTHENTICATION

HONW-13-007200 - Honeywell Android 13 must be configured to disable trust agents.MobileIron - DISA Honeywell Android 13 COBO STIG v1r1MDM

IDENTIFICATION AND AUTHENTICATION

MD8X-00-012800 - MongoDB must require users to be individually authenticated before granting access to the shared accounts or resources.DISA MongoDB Enterprise Advanced 8.x STIG v1r1 UnixUnix

IDENTIFICATION AND AUTHENTICATION

OL08-00-010410 - OL 8 must accept Personal Identity Verification (PIV) credentials.DISA Oracle Linux 8 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

OL09-00-002343 - OL 9 SSHD must not allow blank passwords.DISA Oracle Linux 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

PHTN-67-000034 - The Photon operating system must not have Duplicate User IDs (UIDs).DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-255040 - RHEL 9 SSHD must not allow blank passwords.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200612 - RHEL 10 must have the "pcsc-lite-ccid" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600150 - RHEL 10 must assign a primary group to all interactive users.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600470 - RHEL 10 must have a unique group ID (GID) for each group in "/etc/group".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

SHPT-00-000530 - The Central Administration Web Application must use Kerberos as the authentication provider.DISA STIG SharePoint 2010 v1r9Windows

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000320 - Splunk Enterprise must use organization-level authentication to uniquely identify and authenticate users.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000330 - Splunk Enterprise must use HTTPS/SSL for access to the user interface.DISA STIG Splunk Enterprise 8.x for Linux v2r3 STIG REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000320 - Symantec ProxySG must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users) - Domain JoinedDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000330 - Symantec ProxySG must be configured with a pre-established trust relationship and mechanisms with appropriate authorities that validate user account access authorizations and privileges - Domain ExistsDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000350 - Symantec ProxySG providing user authentication intermediary services must implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000360 - Symantec ProxySG providing user authentication intermediary services must implement multifactor authentication for remote access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000370 - Symantec ProxySG providing user authentication intermediary services must use multifactor authentication for network access to nonprivileged accounts.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-NM-000230 - Symantec ProxySG must implement HTTPS-console to provide replay-resistant authentication mechanisms for network access to privileged accounts. - HTTP-ConsoleDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-NM-000230 - Symantec ProxySG must implement HTTPS-console to provide replay-resistant authentication mechanisms for network access to privileged accounts. - HTTPS-ConsoleDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

IDENTIFICATION AND AUTHENTICATION

UBTU-20-010065 - The Ubuntu operating system must electronically verify Personal Identity Verification (PIV) credentials.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-612025 - Ubuntu 22.04 LTS must electronically verify personal identity verification (PIV) credentials.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

WN25-DC-000030 - Windows Server 2025 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less.DISA Microsoft Windows Server 2025 STIG v1r1Windows

IDENTIFICATION AND AUTHENTICATION

ZEBR-14-007200 - Zebra Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MobileIron - DISA Zebra Android 14 COBO STIG v1r2MDM

IDENTIFICATION AND AUTHENTICATION