Item Search

NameAudit NamePluginCategory
1.2.1.5 Ensure DNF is configured to perform a signature check on local packagesCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.5 O365-CO-000002CIS Microsoft Office 365 ProPlus STIG v1.1.0 CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.8.14 Ensure unrestricted logon is not allowedCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

1.11 Ensure anti-virus is installed and runningCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

SYSTEM AND INFORMATION INTEGRITY

1.68 UBTU-24-300025CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.99 UBTU-22-611060CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.105 UBTU-24-600130CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IUnix

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.20 Ensure the rsh package has been removedCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

2.2.23 Ensure default SNMP community strings don't existCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

AIOS-17-706950 - Apple iOS/iPadOS 17 must be configured to enforce a passcode reuse prohibition of at least two generations.AirWatch - DISA Apple iOS/iPadOS 17 BYOAD v1r2MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-17-706950 - Apple iOS/iPadOS 17 must be configured to enforce a passcode reuse prohibition of at least two generations.MobileIron - DISA Apple iOS/iPadOS BYOAD 17 v1r2MDM

IDENTIFICATION AND AUTHENTICATION

ALMA-09-002990 - AlmaLinux OS 9 SSH client must be configured to use only encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-003870 - AlmaLinux OS 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL

ALMA-09-009590 - AlmaLinux OS 9 must check the GPG signature of software packages originating from external software repositories before installation.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

APPL-11-002031 - The macOS system must be configured to disable the system preference pane for Apple ID.DISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002038 - Apple macOS must be configured to disable the tftp service.DISA STIG Apple macOS 11 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

ARBA-VN-002430 - AOS, when used as a VPN Gateway, must not accept certificates that have been revoked when using PKI for authentication.DISA HPE Aruba Networking AOS VPN STIG v1r1ArubaOS

IDENTIFICATION AND AUTHENTICATION

ARST-RT-000450 - The Arista perimeter router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-001205 - Amazon Linux 2023 server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-2/140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL

CD12-00-000800 - If passwords are used for authentication, PostgreSQL must transmit only encrypted representations of passwords.DISA STIG Crunchy Data PostgreSQL OS v3r1Unix

IDENTIFICATION AND AUTHENTICATION

CD16-00-000200 - PostgreSQL must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

ACCESS CONTROL

CD16-00-008500 - PostgreSQL must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest (to include, at a minimum, PII and classified information) on organization-defined information system components.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-80-000014 - The ESXi host Secure Shell (SSH) daemon must use FIPS 140-2 validated cryptographic modules to protect the confidentiality of remote access sessions.DISA VMware vSphere 8.0 ESXi STIG v2r4 UnixUnix

ACCESS CONTROL

F5BI-FW-300020 - The F5 BIG-IP appliance must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).DISA F5 BIG-IP TMOS Firewall STIG v1r1F5

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-VN-300006 - The F5 BIG-IP appliance IPsec VPN must use AES256 or greater encryption for the IPsec proposal.DISA F5 BIG-IP TMOS VPN STIG v1r1F5

ACCESS CONTROL

FGFW-ND-000245 - The FortiGate device must use LDAPS for the LDAP connection.DISA Fortigate Firewall NDM STIG v1r4FortiGate

IDENTIFICATION AND AUTHENTICATION

GEN000000-AIX00080 - The SYSTEM attribute must not be set to NONE for any account.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN002220 - All shell files must have mode 0755 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005100 - The TFTP daemon must have mode 0755 or less permissive.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN008640 - The system must not use removable media as the boot loader - 'prevboot'DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN008640 - The system must not use removable media as the boot loader - 'service'DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GOOG-16-012500 - Google Android 16 must be configured to disable 'Private Space' use - Private Space use.AirWatch - DISA Google Android 16 COBO STIG v1r1MDM

CONFIGURATION MANAGEMENT

MADB-10-003900 - If passwords are used for authentication, MariaDB must transmit only encrypted representations of passwords.DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDBMySQLDB

IDENTIFICATION AND AUTHENTICATION

MD7X-00-002700 - MongoDB software installation account must be restricted to authorized users.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 UnixUnix

CONFIGURATION MANAGEMENT

MD8X-00-003600 - MongoDB must, for password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.DISA MongoDB Enterprise Advanced 8.x STIG v1r1 MongoDBMongoDB

IDENTIFICATION AND AUTHENTICATION

RHEL-08-010291 - The RHEL 8 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

ACCESS CONTROL

RHEL-09-211045 - The systemd Ctrl-Alt-Delete burst key sequence in RHEL 9 must be disabled.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-255070 - The RHEL 9 SSH client must be configured to use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-09-255075 - The RHEL 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL

RHEL-10-001050 - RHEL 10 must have GNU Privacy Guard (GPG) signature verification enabled for all software repositories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200631 - RHEL 10 must use cryptographic mechanisms to protect the integrity of audit tools.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-701050 - RHEL 10 must prevent the loading of a new kernel for later execution.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

SHPT-00-000683 - SharePoint-specific malware (i.e., anti-virus) software must be integrated and configured - 'Scan Documents on Upload is enabled'DISA STIG SharePoint 2010 v1r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SQL2-00-015700 - Vendor-supported software and patches must be evaluated and patched against newly found vulnerabilities.DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

CONFIGURATION MANAGEMENT

SYMP-AG-000030 - Symantec ProxySG providing forward proxy intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52 - client.connection.negotiated_cipherDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

ACCESS CONTROL

SYMP-AG-000030 - Symantec ProxySG providing forward proxy intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52 - client.connection.negotiated_ssl_versionDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

ACCESS CONTROL

SYMP-NM-000290 - The Symantec ProxySG Web Management Console and SSH sessions must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.DISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

MAINTENANCE

WN11-CC-000180 - Autoplay must be turned off for non-volume devices.DISA Microsoft Windows 11 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN11-UR-000045 - The 'Create a token object' user right must not be assigned to any groups or accounts.DISA Microsoft Windows 11 STIG v2r8Windows

ACCESS CONTROL

WN22-DC-000290 - Windows Server 2022 domain controller PKI certificates must be issued by the DOD PKI or an approved External Certificate Authority (ECA).DISA Microsoft Windows Server 2022 STIG v2r8Windows

IDENTIFICATION AND AUTHENTICATION