Item Search

NameAudit NamePluginCategory
1.3.2 Set the 'banner-text' for 'banner login'CIS Cisco IOS 12 L1 v4.0.0Cisco

ACCESS CONTROL

1.12 CISC-RT-000210CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.24 CISC-ND-000620CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

IDENTIFICATION AND AUTHENTICATION

1.27 CISC-RT-000330CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.27 CISC-RT-000340CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.28 CISC-RT-000340CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.68 CISC-RT-000670CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT ICisco

CONTINGENCY PLANNING

2.1.1.1.2 Set the 'ip domain name'CIS Cisco IOS 12 L1 v4.0.0Cisco

CONFIGURATION MANAGEMENT

3.3.1.4 Set 'address-family ipv4 autonomous-system'CIS Cisco IOS XE 17.x v2.2.1 L2Cisco

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1.4 Set 'address-family ipv4 autonomous-system'CIS Cisco IOS XE 16.x v2.2.0 L2Cisco

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.3.2.1 Set 'authentication message-digest' for OSPF areaCIS Cisco IOS XE 17.x v2.2.1 L1Cisco

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

5.5.1.2 Ensure minimum days between password changes is configured - login.defsCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.5.1.2 Ensure minimum days between password changes is configured - password shadowCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.22 Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT

18.4.5 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, RISK ASSESSMENT

18.5.4 (L1) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.5.4 (L1) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 DCWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.5.4 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2019 v5.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.5.4 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

CONFIGURATION MANAGEMENT

18.5.4 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.5.5 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.5.5 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

AMLS-L3-000220 - The Arista Multilayer Switch must enable neighbor router authentication for control plane protocols except RIP - BGPDISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

ACCESS CONTROL, CONFIGURATION MANAGEMENT

ARST-RT-000430 - The out-of-band management (OOBM) Arista gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the NOC.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000430 - The out-of-band management (OOBM) Arista gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the NOC.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001440 - The Cisco router must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001440 - The Cisco router must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001440 - The Cisco switch must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.DISA Cisco IOS XE Switch NDM STIG v3r6Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000440 - The Cisco out-of-band management (OOBM) gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the Network Operations Center (NOC).DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000580 - The Cisco BGP router must be configured to use its loopback address as the source address for iBGP peering sessions.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

Ensure IPv6 router advertisements are not accepted - sysctl ipv6 all acceptTenable Cisco Firepower Management Center OS Best Practices AuditUnix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN005580 - A system used for routing must not run other network services or applications.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

GEN007920 - The system must not forward IPv6 source-routed packets - 'net.ipv6.conf.all.forwarding'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN007920 - The system must not forward IPv6 source-routed packets - 'net.ipv6.conf.default.forwarding'DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

MS.AAD.7.3v1 - Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers.CISA SCuBA Microsoft 365 Entra ID v1.5.0microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

OL6-00-000349 - The system must be configured to require the use of a CAC, PIV compliant hardware token, or Alternate Logon Token (ALT) for authentication.DISA STIG Oracle Linux 6 v2r7Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-040610 - The Oracle Linux operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OS10-RTR-000480 - The Dell OS10 out-of-band management (OOBM) gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the NOC.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

SYSTEM AND COMMUNICATIONS PROTECTION

Review the list of all Domains created since the last scanTenable Best Practices RackSpace v2.0.0Rackspace

CONFIGURATION MANAGEMENT

Review the list of all Domains updated since the last scanTenable Best Practices RackSpace v2.0.0Rackspace

CONFIGURATION MANAGEMENT

RHEL-07-040620 - The Red Hat Enterprise Linux operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets by default.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

RHEL-07-040830 - The Red Hat Enterprise Linux operating system must not forward IPv6 source-routed packets.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

RHEL-09-254010 - RHEL 9 must not accept router advertisements on all IPv6 interfaces.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-254030 - RHEL 9 must not accept router advertisements on all IPv6 interfaces by default.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-10-800220 - RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-030360 - The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-15-040300 - The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT

SLES-15-040310 - The SUSE operating system must not forward Internet Protocol version 6 (IPv6) source-routed packets.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SLES-15-040320 - The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets by default.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT

SLES-15-040321 - The SUSE operating system must not forward Internet Protocol version 6 (IPv6) source-routed packets by default.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT