Item Search

NameAudit NamePluginCategory
1.5.9 Ensure kernel page-table isolation is enabledCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.10 Ensure the system has the packages required to enable the hardware random number generator entropy gatherer serviceCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

1.18 WN16-00-000200CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

ACCESS CONTROL

1.18 WN19-00-000180CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIIWindows

ACCESS CONTROL

1.44 WN16-00-000450CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

AUDIT AND ACCOUNTABILITY

1.44 WN16-00-000450CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IIIWindows

AUDIT AND ACCOUNTABILITY

1.46 WN16-00-000470CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IIIWindows

CONFIGURATION MANAGEMENT

1.46 WN19-00-000460CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.47 WN16-00-000480CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.97 WN16-CC-000040CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IIIWindows

CONFIGURATION MANAGEMENT

1.98 WN19-CC-000040CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.99 WN16-CC-000060CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IIIWindows

CONFIGURATION MANAGEMENT

1.99 WN16-CC-000060CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.100 WN16-CC-000070CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.100 WN19-CC-000060CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.125 WN19-CC-000320CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

1.162 WN19-DC-000160CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.244 WN19-SO-000370CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIIWindows

CONFIGURATION MANAGEMENT

2.1.33 Ensure the operating system has enabled the hardware random number generator entropy gatherer serviceCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

3.048 - The Recovery Console SET command must be disabled.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.097 - The system is configured for a greater keep-alive time than recommended.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.119 - The system is configured to allow the display of the last user name on the logon screen.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

4.006 - Users must be forcibly disconnected when their logon hours expire.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

5.3.3.5.1 Ensure the date and time of the last successful account logon upon logon is displayedCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

5.4.3.14 Ensure the number of concurrent sessions is configuredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

DG0019-ORACLE11 - Application software should be owned by a Software Application account.DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

DG0091-ORACLE11 - Custom and GOTS application source code stored in the database should be protected with encryption or encoding.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

DG0104-ORACLE11 - DBMS service identification should be unique and clearly identifies the service - 'All Oracle services use the proper naming'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DO0145-ORACLE11 - OS DBA group membership should be restricted to authorized accounts.DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

DO0157-ORACLE11 - Database application user accounts should be denied storage usage for object creation within the database.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

SYSTEM AND COMMUNICATIONS PROTECTION

DO0221-ORACLE11 - The Oracle SID should not be the default SID - 'No default instance names exist'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

CONFIGURATION MANAGEMENT

DO0430-ORACLE11 - The Oracle Management Agent should be uninstalled if not required and authorized or is installed on a database accessible from the Internet.DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DO6746-ORACLE11 - The Oracle listener.ora file should specify IP addresses rather than host names to identify hosts - '$ORACLE_HOME/network/admin/listener.ora HOST entroes do not use hostnames'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

CONFIGURATION MANAGEMENT

GEN002260 - The system must be checked for extraneous device files at least weekly.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002752 - The audit system must be configured to audit account disabling - '/etc/security/audit/config USER_Change exists'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN003523 - The kernel core dump data directory must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003602 - The system must not process ICMP timestamp requests.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN004440 - Sendmail logging must not be set to less than nine in the sendmail.cf file.DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN004700 - The Sendmail service must not have the wizard backdoor active.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN004980 - The FTP daemon must be configured for logging or verbose mode - '/etc/syslog.conf contains daemon.info or *.info'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN005533 - The SSH daemon must limit connections to a single session.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN008420 - The system must use available memory address randomization techniques.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN008460 - The system must have USB disabled unless needed - 'lsdev'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

WA000-WWA030 A22 - The httpd.conf MaxSpareServers directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WG420 IIS6 - Backup interactive scripts must be removed from the web site.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WG420 W22 - Backup interactive scripts on the production web server must be prohibited.DISA STIG Apache Server 2.2 Windows v1r13Windows

CONFIGURATION MANAGEMENT

WG490 A22 - Java software on production web servers must be limited to class files and the JAVA virtual machine - cgi-binDISA STIG Apache Site 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG490 A22 - Java software on production web servers must be limited to class files and the JAVA virtual machine - htmlDISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG520 A22 - Web server and/or operating system information must be protected.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION