Item Search

NameAudit NamePluginCategory
1.001 - Physical security of the Automated Information System (AIS) does not meet DISA requirements.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

1.3.2 Set the 'banner-text' for 'banner login'CIS Cisco IOS XE 16.x v2.2.0 L1Cisco

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.2 Set the 'banner-text' for 'banner login'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.3 Set the 'banner-text' for 'banner motd'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.3 Set the 'banner-text' for 'banner motd'CIS Cisco IOS XE 16.x v2.2.0 L1Cisco

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.4 Set the 'banner-text' for 'webauth banner'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.4 Set the 'banner-text' for 'webauth banner'CIS Cisco IOS XE 16.x v2.2.0 L1Cisco

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.22 ESXI-80-000187CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT II UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.221 WN10-SO-000230CIS Microsoft Windows 10 STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.223 WN11-SO-000230CIS Microsoft Windows 11 STIG v1.2.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.243 WN19-SO-000360CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.243 WN19-SO-000360CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.243 WN22-SO-000360CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.243 WN22-SO-000360CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

2.4 (L2) Ensure default self-signed certificate for ESXi communication is not usedCIS VMware ESXi 7.0 v1.5.0 L2 Bare MetalUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

8.1.5.2 Ensure Advanced Threat Protection Alerts for Storage Accounts Are MonitoredCIS Microsoft Azure Foundations v6.0.0 L2microsoft_azure

AUDIT AND ACCOUNTABILITY

AMLS-L2-000110 - The Arista Multilayer Switch must enforce approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies.DISA STIG Arista MLS DCS-7000 Series L2S v1r3Arista

ACCESS CONTROL

AOSX-13-000570 - The macOS system must implement NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA STIG Apple Mac OSX 10.13 v2r5Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

ARST-L2-000160 - The Arista MLS layer 2 switch must have all trunk links enabled statically.DISA Arista MLS EOS 4.X L2S STIG v2r3Arista

CONFIGURATION MANAGEMENT

AS24-W2-000350 - Users and scripts running on behalf of users must be contained to the document root or home directory tree of the Apache web server.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W2-000390 - Only authenticated system administrators or the designated PKI Sponsor for the Apache web server must have access to the Apache web servers private key.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

IDENTIFICATION AND AUTHENTICATION

BIND-9X-002050 - A BIND 9.x server must implement NIST FIPS-validated cryptography for provisioning digital signatures and generating cryptographic hashes.DISA BIND 9.x STIG v3r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CASA-VN-000230 - The Cisco ASA must be configured to use FIPS-validated SHA-2 at 384 bits or higher for Internet Key Exchange (IKE) Phase 1 - IKE Phase 1.DISA STIG Cisco ASA VPN v2r2Cisco

IDENTIFICATION AND AUTHENTICATION

DG0127-ORACLE11 - DBMS account passwords should not be set to easily guessed words or values - 'limit'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
DG0127-ORACLE11 - DBMS account passwords should not be set to easily guessed words or values - 'name'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

IDENTIFICATION AND AUTHENTICATION

DG0127-ORACLE11 - DBMS account passwords should not be set to easily guessed words or values - 'profile'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
EX19-MB-000016 - Exchange must have administrator audit logging enabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

ACCESS CONTROL

EX19-MB-000019 - Exchange servers must use approved DOD certificates.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

ACCESS CONTROL

EX19-MB-000041 - Exchange message tracking logging must be enabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

AUDIT AND ACCOUNTABILITY

EX19-MB-000052 - Exchange must protect audit data against unauthorized read access.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

AUDIT AND ACCOUNTABILITY

EX19-MB-000061 - Exchange local machine policy must require signed scripts.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

CONFIGURATION MANAGEMENT

EX19-MB-000063 - Exchange Send Fatal Errors to Microsoft must be disabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

CONFIGURATION MANAGEMENT

EX19-MB-000064 - Exchange must not send customer experience reports to Microsoft.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

CONFIGURATION MANAGEMENT

EX19-MB-000105 - Exchange Mailbox databases must reside on a dedicated partition.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000106 - Exchange internet-facing send connectors must specify a smart host.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000117 - Exchange email-forwarding SMTP domains must be restricted.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000124 - Exchange Message size restrictions must be controlled on Receive connectors.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000134 - Exchange servers must have an approved DOD email-aware virus protection software installed.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-MB-000135 - Exchange internal receive connectors must not allow anonymous connections.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-MB-000139 - Exchange must have anti-spam filtering configured.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

PANW-AG-000141 - The Palo Alto Networks security platform providing encryption intermediary services must implement NIST FIPS-validated cryptography to generate cryptographic hashes.DISA Palo Alto Networks ALG STIG v3r4Palo_Alto

SYSTEM AND COMMUNICATIONS PROTECTION

PANW-AG-000143 - The Palo Alto Networks security platform, if used for TLS/SSL decryption, must use NIST FIPS-validated cryptography to implement encryption.DISA Palo Alto Networks ALG STIG v3r4Palo_Alto

SYSTEM AND COMMUNICATIONS PROTECTION

PHTN-67-000032 - The Photon operating system must only allow installation of packages signed by VMware.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT

SYMP-AG-000460 - Symantec ProxySG providing reverse proxy encryption intermediary services must implement NIST FIPS-validated cryptography to generate cryptographic hashes.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

SYMP-AG-000480 - Symantec ProxySG providing reverse proxy encryption intermediary services must use NIST FIPS-validated cryptography to implement encryption services.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

VCENTER-000034 - The Update Manager must not directly connect to public patch repositories on the Internet.DISA STIG VMWare ESXi vCenter 5 STIG v2r1VMware

CONFIGURATION MANAGEMENT

WN16-MS-000010 - Only administrators responsible for the member server or standalone or nondomain-joined system must have Administrator rights on the system.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL

WN22-MS-000010 - Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2022 STIG v2r10Windows

ACCESS CONTROL

WN25-MS-000010 - Windows Server 2025 must only allow administrators responsible for the member server or stand-alone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL

WN25-MS-000010 - Windows Server 2025 must only allow administrators responsible for the member server or stand-alone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2025 STIG v1r3Windows

ACCESS CONTROL