Item Search

NameAudit NamePluginCategory
APPNET0010 - The version of .NET running on the system must be a supported version.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

APPNET0031 - Digital signatures assigned to strongly named assemblies must be verified.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

APPNET0061 - .Net Framework versions installed on the system must be supported.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

CONFIGURATION MANAGEMENT

APPNET0063 - .NET must be configured to validate strong names on full-trust assemblies.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

APPNET0065 - Trust must be established prior to enabling the loading of remote code in .Net 4.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

APPNET0066 - .NET default proxy settings must be reviewed and approved.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

CONFIGURATION MANAGEMENT

UBTU-22-214010 - Ubuntu 22.04 LTS must be configured so that the Advance Package Tool (APT) prevents the installation of patches, service packs, device drivers, or operating system components without verification they have been digitally signed using a certificate that is recognized and approved by the organization.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-215010 - Ubuntu 22.04 LTS must have the "libpam-pwquality" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-215020 - Ubuntu 22.04 LTS must not have the "systemd-timesyncd" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-215035 - Ubuntu 22.04 LTS must not have the "telnet" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-232026 - Ubuntu 22.04 LTS must generate error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232080 - Ubuntu 22.04 LTS must configure the directories used by the system journal to be owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232090 - Ubuntu 22.04 LTS must configure the files used by the system journal to be owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232095 - Ubuntu 22.04 LTS must configure the files used by the system journal to be group-owned by "systemd-journal".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232120 - Ubuntu 22.04 LTS must configure the "/var/log" directory to be owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-252010 - Ubuntu 22.04 LTS must, for networked systems, compare internal information system clocks at least every 24 hours with a server synchronized to one of the redundant United States Naval Observatory (USNO) time servers, or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-252020 - Ubuntu 22.04 LTS must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC).DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-254020 - Ubuntu 22.04 LTS must ensure SSSD performs certificate path validation, including revocation checking, against a trusted anchor for PKI-based authentication.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-254030 - Ubuntu 22.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-255015 - Ubuntu 22.04 LTS must use SSH to protect the confidentiality and integrity of transmitted information.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-255030 - Ubuntu 22.04 LTS must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-255040 - Ubuntu 22.04 LTS must be configured so that remote X connections are disabled, unless to fulfill documented and validated mission requirements.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-255060 - Ubuntu 22.04 LTS SSH server must be configured to use only FIPS-validated key exchange algorithms.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-291010 - Ubuntu 22.04 LTS must disable automatic mounting of Universal Serial Bus (USB) mass storage driver.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-291015 - Ubuntu 22.04 LTS must disable all wireless network adapters.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-411010 - Ubuntu 22.04 LTS must prevent direct login into the root account.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-412030 - Ubuntu 22.04 LTS must automatically exit interactive command shell user sessions after 15 minutes of inactivity.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-412035 - Ubuntu 22.04 LTS default filesystem permissions must be defined in such a way that all authenticated users can read and modify only their own files.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-611035 - Ubuntu 22.04 LTS must enforce a minimum 15-character password length.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-611045 - Ubuntu 22.04 LTS must be configured so that when passwords are changed or new passwords are established, pwquality must be used.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-611065 - Ubuntu 22.04 LTS must not have accounts configured with blank or null passwords.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-612040 - Ubuntu 22.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-651010 - Ubuntu 22.04 LTS must use a file integrity tool to verify correct operation of all security functions.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-651035 - Ubuntu 22.04 LTS must have a crontab script running weekly to offload audit events of standalone systems.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-653060 - Ubuntu 22.04 LTS must be configured so that the audit log directory is not write-accessible by unauthorized users.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654035 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chsh command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654040 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the crontab command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654045 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use the fdisk command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654075 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the pam_timestamp_check command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654100 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the su command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654115 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the umount command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654140 - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

UBTU-22-654160 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chown, fchown, fchownat, and lchown system calls.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654180 - Ubuntu 22.04 LTS must generate audit records for any use of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654200 - Ubuntu 22.04 LTS must generate audit records for the /var/log/wtmp file.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654205 - Ubuntu 22.04 LTS must generate audit records for the /var/run/utmp file.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654210 - Ubuntu 22.04 LTS must generate audit records for the use and modification of faillog file.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654215 - Ubuntu 22.04 LTS must generate audit records for the use and modification of the lastlog file.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654224 - The operating system must restrict privilege elevation to authorized personnel.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-654235 - Ubuntu 22.04 LTS must generate audit records for privileged activities, nonlocal maintenance, diagnostic sessions and other system-level access.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE