Item Search

NameAudit NamePluginCategory
1.4 VCLD-80-000010CIS VMware vSphere 8.0 vCenter Appliance Management Interface VAMI STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.8 PHTN-40-000016CIS VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

1.108 SLES-15-030050CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

AIX7-00-002004 - AIX must produce audit records containing information to establish the source and the identity of any individual or process associated with an event.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

APPL-11-001003 - The macOS system must initiate session audits at system startup, using internal clocks with time stamps for audit records that meet a minimum granularity of one second and can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT), to generate audit records containing information to establish what type of events occurred, the identity of any individual or process associated with the event, including individual identities of group account users, establish where the events occurred, source of the event, and outcome of the events including all account enabling actions, full-text recording of privileged commands, and information about the use of encryption for access wireless access to and from the system.DISA STIG Apple macOS 11 v1r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

APPL-11-001003 - The macOS system must initiate session audits at system startup, using internal clocks with time stamps for audit records that meet a minimum granularity of one second and can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT), to generate audit records containing information to establish what type of events occurred, the identity of any individual or process associated with the event, including individual identities of group account users, establish where the events occurred, source of the event, and outcome of the events including all account enabling actions, full-text recording of privileged commands, and information about the use of encryption for access wireless access to and from the system.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

APPL-12-001003 - The macOS system must initiate session audits at system startup, using internal clocks with time stamps for audit records that meet a minimum granularity of one second and can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT), in order to generate audit records containing information to establish what type of events occurred, the identity of any individual or process associated with the event, including individual identities of group account users, establish where the events occurred, source of the event, and outcome of the events including all account enabling actions, full-text recording of privileged commands, and information about the use of encryption for access wireless access to and from the system.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

APPL-13-001003 - The macOS system must produce audit records containing information to establish when, where, what type, the source, and the outcome for all DOD-defined auditable events and actions.DISA STIG Apple macOS 13 v1r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

ARST-ND-000790 - The Arista network device must be configured to capture all DOD auditable events.DISA Arista MLS EOS 4.X NDM STIG v2r2Arista

AUDIT AND ACCOUNTABILITY

ARST-ND-000790 - The Arista network device must be configured to capture all DOD auditable events.DISA STIG Arista MLS EOS 4.2x NDM v2r1Arista

AUDIT AND ACCOUNTABILITY

AS24-U1-000070 - The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication eventsDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

AS24-U1-000070 - The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

AUDIT AND ACCOUNTABILITY

AS24-U1-000130 - An Apache web server, behind a load balancer or proxy server, must produce log records containing the client IP information as the source and destination and not the load balancer or proxy IP information with each event.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

AS24-W1-000090 - The Apache web server must produce log records containing sufficient information to establish what type of events occurred.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000090 - The Apache web server must produce log records containing sufficient information to establish what type of events occurred.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000130 - An Apache web server, behind a load balancer or proxy server, must produce log records containing the client IP information as the source and destination and not the load balancer or proxy IP information with each event.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

BIND-9X-001110 - A BIND 9.x server implementation must be configured to allow DNS administrators to audit all DNS server components based on selectable event criteria and produce audit records within all DNS server components that contain information for failed security verification tests, information to establish the outcome and source of the events, any information necessary to determine cause of failure, and any information necessary to return to operations with least disruption to mission processes.DISA BIND 9.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

CNTR-K8-000700 - Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

EX13-MB-000035 - Exchange Circular Logging must be disabled.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

AUDIT AND ACCOUNTABILITY

EX16-MB-000080 - Exchange Email Subject Line logging must be disabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

AUDIT AND ACCOUNTABILITY

EX16-MB-000090 - Exchange Message Tracking Logging must be enabled.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

AUDIT AND ACCOUNTABILITY

F5BI-AP-300018 - The F5 BIG-IP appliance must generate event log records that can be forwarded to the centralized events log.DISA F5 BIG-IP TMOS ALG STIG v1r3F5

AUDIT AND ACCOUNTABILITY, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

F5BI-FW-300005 - The F5 BIG-IP appliance must generate traffic log entries containing information to establish the details of the event, including success or failure of the application of the firewall rule.DISA F5 BIG-IP TMOS Firewall STIG v1r1F5

AUDIT AND ACCOUNTABILITY

IIST-SI-000208 - An IIS 10.0 website behind a load balancer or proxy server must produce log records containing the source client IP, and destination information.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000102 - The enhanced logging for the IIS 10.0 web server must be enabled and capture all user and web server events.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000109 - An IIS 10.0 web server behind a load balancer or proxy server must produce log records containing the source client IP and destination information.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IISW-SV-000102 - The enhanced logging for the IIS 8.5 web server must be enabled and capture all user and web server events.DISA IIS 8.5 Server v2r7Windows

AUDIT AND ACCOUNTABILITY

OH12-1X-000061 - OHS must have a SSL log format defined for log records that allow the establishment of the source of events.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

AUDIT AND ACCOUNTABILITY

PHTN-30-000010 - The Photon operating system must configure auditd to log to disk.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

AUDIT AND ACCOUNTABILITY

PHTN-40-000016 - The Photon operating system must enable the auditd service.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

PPS9-00-001900 - The EDB Postgres Advanced Server must produce audit records containing sufficient information to establish the sources (origins) of the events - origins of the events.EDB PostgreSQL Advanced Server DB Audit v2r3PostgreSQLDB

AUDIT AND ACCOUNTABILITY

SLEM-05-653015 - SLEM 5 audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030050 - SUSE operating system audit records must contain information to establish what type of events occurred, the source of events, where events occurred, and the outcome of events.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

TCAT-AS-000050 - AccessLogValve must be configured for each application context.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCEM-67-000005 - ESX Agent Manager must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 6.7 EAM Tomcat v1r4Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCEM-70-000005 - ESX Agent Manager must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 7.0 EAM Tomcat v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCFL-67-000009 - vSphere Client must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCLD-67-000006 - VAMI must produce log records containing sufficient information to establish what type of events occurred.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

AUDIT AND ACCOUNTABILITY

VCLD-70-000006 - VAMI must produce log records containing sufficient information to establish what type of events occurred.DISA STIG VMware vSphere 7.0 VAMI v1r2Unix

AUDIT AND ACCOUNTABILITY

VCLD-80-000010 - The vCenter VAMI service must produce log records containing sufficient information to establish what type of events occurred.DISA VMware vSphere 8.0 vCenter Appliance Management Interface VAMI STIG v2r2Unix

AUDIT AND ACCOUNTABILITY

VCLD-80-000010 The vCenter VAMI service must produce log records containing sufficient information to establish what type of events occurred.DISA VMware vSphere 8.0 vCenter Appliance Management Interface (VAMI) STIG v2r1Unix

AUDIT AND ACCOUNTABILITY

VCLU-70-000005 - Lookup Service must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 7.0 Lookup Service v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCPF-67-000005 - Performance Charts must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 6.7 Perfcharts Tomcat v1r3Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCPF-70-000005 - Performance Charts must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 7.0 Perfcharts Tomcat v1r1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCPG-70-000002 - VMware Postgres log files must contain required fields.DISA STIG VMware vSphere 7.0 PostgreSQL v1r2Unix

AUDIT AND ACCOUNTABILITY

VCST-67-000005 - The Security Token Service must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCST-70-000005 - The Security Token Service must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 7.0 STS Tomcat v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCUI-67-000005 - vSphere UI must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 6.7 UI Tomcat v1r3Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCUI-70-000005 - vSphere UI must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 7.0 vCA UI v1r2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

WBLC-02-000078 - Oracle WebLogic must produce audit records containing sufficient information to establish the sources of the events.Oracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY