Item Search

NameAudit NamePluginCategory
DISA_STIG_Microsoft_OneDrive_v2r4.audit from DISA Microsoft OneDrive v2r4 STIGDISA STIG Microsoft OneDrive v2r4Windows
DISA_STIG_Oracle_Database_11.2g_v2r5_OS_Windows.audit from DISA Oracle Database 11.2g v2r5 STIGDISA STIG Oracle 11.2g v2r5 WindowsWindows
DISA_STIG_Oracle_Database_12c_v3r5_OS_Windows.audit from DISA Oracle Database 12c v3r5 STIGDISA Oracle Database 12c STIG v3r5 WindowsWindows
SLES-12-010030 - The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access via local console.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010060 - The SUSE operating system must be able to lock the graphical user interface (GUI).DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010109 - The SUSE operating system must specify the default 'include' directory for the /etc/sudoers file - include directory for the /etc/sudoers file.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010180 - The SUSE operating system must enforce passwords that contain at least one special character.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010210 - The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (login.defs).DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010230 - The SUSE operating system must configure the Linux Pluggable Authentication Modules (PAM) to only store encrypted representations of passwords.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010340 - The SUSE operating system must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity after password expiration.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010370 - The SUSE operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010420 - FIPS 140-2 mode must be enabled on the SUSE operating system.DISA SLES 12 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-010530 - The SUSE operating system file integrity tool must be configured to verify extended attributes.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010720 - All SUSE operating system local interactive user accounts, upon creation, must be assigned a home directory.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010840 - SUSE operating system kernel core dumps must be disabled unless needed.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010850 - A separate file system must be used for SUSE operating system user home directories (such as /home or an equivalent).DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010871 - The SUSE operating system library files must have mode 0755 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010881 - The SUSE operating system must have directories that contain system commands owned by root.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010883 - The SUSE operating system must have directories that contain system commands group-owned by root.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010890 - The SUSE operating system must prevent unauthorized users from accessing system error messages.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-12-020040 - The Information System Security Officer (ISSO) and System Administrator (SA), at a minimum, must be alerted of a SUSE operating system audit processing failure event.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-020050 - The Information System Security Officer (ISSO) and System Administrator (SA), at a minimum, must have mail aliases to be notified of a SUSE operating system audit processing failure.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-020070 - The audit-audispd-plugins must be installed on the SUSE operating system.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-020080 - The SUSE operating system audit event multiplexor must be configured to use Kerberos.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-020100 - The audit system must take appropriate action when the network cannot be used to off-load audit records.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-020200 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-12-020230 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-12-020290 - The SUSE operating system must generate audit records for all uses of the mount command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020320 - The SUSE operating system must generate audit records for all uses of the ssh-keysign command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020370 - The SUSE operating system must generate audit records for all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr syscalls.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020460 - The SUSE operating system must generate audit records for all uses of the chmod, fchmod, and fchmodat system calls.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020550 - The SUSE operating system must generate audit records for all uses of the passwd command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020560 - The SUSE operating system must generate audit records for all uses of the gpasswd command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020570 - The SUSE operating system must generate audit records for all uses of the newgrp command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020650 - The SUSE operating system must generate audit records for all modifications to the tallylog file must generate an audit record.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020660 - The SUSE operating system must generate audit records for all modifications to the lastlog file.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020670 - The SUSE operating system must generate audit records for all uses of the passmass command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020730 - The SUSE operating system must generate audit records for all uses of the delete_module command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020760 - The SUSE operating system must generate audit records for all modifications to the faillog file.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-030170 - The SUSE operating system must implement DoD-approved encryption to protect the confidentiality of SSH remote connections.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

SLES-12-030191 - The SUSE operating system for all network connections associated with SSH traffic must immediately terminate at the end of the session or after 10 minutes of inactivity.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-030210 - The SUSE operating system SSH daemon public host key files must have mode 0644 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030230 - The SUSE operating system SSH daemon must perform strict mode checking of home directory configuration files.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030260 - The SUSE operating system SSH daemon must disable forwarded remote X connections for interactive users, unless to fulfill documented and validated mission requirements.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030363 - The SUSE operating system must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030380 - The SUSE operating system must not respond to Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030430 - The SUSE operating system must not be performing Internet Protocol version 4 (IPv4) packet forwarding unless the system is a router.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030440 - The SUSE operating system must not have network interfaces in promiscuous mode unless approved and documented.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030500 - The SUSE operating system must have the packages required for multifactor authentication to be installed.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-030510 - The SUSE operating system must implement certificate status checking for multifactor authentication.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION