Item Search

NameAudit NamePluginCategory
1.2 Ensure Auto Update Is EnabledCIS Apple macOS 12.0 Monterey v4.0.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.77 RHEL-10-200740CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.80 OL09-00-000400CIS Oracle Linux 9 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

3.121 - The system does not have a backup administrator accountDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

AIOS-14-011000 - Apple iOS/iPadOS must implement the management setting: disable paired Apple Watch.MobileIron - DISA Apple iOS/iPadOS 14 v1r3MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

APPNET0048 - Developer certificates used with the .NET Publisher Membership Condition must be approved by the ISSO.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

APPNET0052 - Encryption keys used for the .NET Strong Name Membership Condition must be protected.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

IDENTIFICATION AND AUTHENTICATION

APPNET0071 - Remoting Services TCP channels must utilize authentication and encryption.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

APPNET0075 - Update and configure the .NET Framework to support TLS.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

CONFIGURATION MANAGEMENT

GOOG-12-007800 - Google Android 12 must be configured to generate audit records for the following auditable events: detected integrity violations.AirWatch - DISA Google Android 12 COBO v1r2MDM

AUDIT AND ACCOUNTABILITY

GOOG-12-009800 - Google Android 12 users must complete required training.MobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

SLES-15-010420 - Advanced Intrusion Detection Environment (AIDE) must verify the baseline SUSE operating system configuration at least weekly.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

SPLK-CL-000045 - Splunk Enterprise must use an SSO proxy service, F5 device, or SAML implementation to accept the DOD common access card (CAC) or other smart card credential for identity management, personal authentication, and multifactor authentication.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

IDENTIFICATION AND AUTHENTICATION

SQL6-D0-004300 - SQL Server must be configured to generate audit records for DoD-defined auditable events within all DBMS/database components.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

UBTU-22-212010 - Ubuntu 22.04 LTS, when booted, must require authentication upon booting into single-user and maintenance modes.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-214015 - Ubuntu 22.04 LTS must be configured so that the Advance Package Tool (APT) removes all software components after updated versions have been installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-215015 - Ubuntu 22.04 LTS must have the "chrony" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-215025 - Ubuntu 22.04 LTS must not have the "ntp" package installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-231010 - Ubuntu 22.04 LTS must implement cryptographic mechanisms to prevent unauthorized disclosure and modification of all information that requires protection at rest.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-232015 - Ubuntu 22.04 LTS must have system commands set to a mode of "755" or less permissive.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-232050 - Ubuntu 22.04 LTS must have system commands owned by "root" or a system account.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-232055 - Ubuntu 22.04 LTS must have system commands group-owned by "root" or a system account.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-232085 - Ubuntu 22.04 LTS must configure the directories used by the system journal to be group-owned by "systemd-journal".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232100 - Ubuntu 22.04 LTS must be configured so that the "journalctl" command is owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232105 - Ubuntu 22.04 LTS must be configured so that the "journalctl" command is group-owned by "root".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232125 - Ubuntu 22.04 LTS must configure the "/var/log" directory to be group-owned by "syslog".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-232130 - Ubuntu 22.04 LTS must configure "/var/log/syslog" file to be owned by "syslog".DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-22-251020 - Ubuntu 22.04 LTS must have an application firewall enabled.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-251025 - Ubuntu 22.04 LTS must configure the Uncomplicated Firewall (ufw) to rate-limit impacted network interfaces.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-252015 - Ubuntu 22.04 LTS must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-254015 - Ubuntu 22.04 LTS must use the "SSSD" package for multifactor authentication services.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-255010 - Ubuntu 22.04 LTS must have SSH installed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-255025 - Ubuntu 22.04 LTS must not allow unattended or automatic login via SSH.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-255035 - Ubuntu 22.04 LTS must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-255050 - Ubuntu 22.04 LTS must configure the SSH daemon to use FIPS 140-3-approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-255065 - Ubuntu 22.04 LTS must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

MAINTENANCE

UBTU-22-431015 - Ubuntu 22.04 LTS must be configured to use AppArmor.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

UBTU-22-432015 - Ubuntu 22.04 LTS must ensure only users who need access to security functions are part of sudo group.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-611040 - Ubuntu 22.04 LTS must require the change of at least eight characters when passwords are changed.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-612020 - Ubuntu 22.04 LTS must implement smart card logins for multifactor authentication for local and network access to privileged and nonprivileged accounts.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-631015 - Ubuntu 22.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-653025 - Ubuntu 22.04 LTS must alert the information system security officer (ISSO) and system administrator (SA) in the event of an audit processing failure.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654015 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chacl command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654020 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chage command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654025 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the chcon command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654150 - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

UBTU-22-654165 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the creat, open, openat, open_by_handle_at, truncate, and ftruncate system calls.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654230 - Ubuntu 22.04 LTS must prevent all software from executing at higher privilege levels than users executing the software and the audit system must be configured to audit the execution of privileged functions.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-671010 - Ubuntu 22.04 LTS must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCSA-70-000294 - vCenter Native Key Providers must be backed up with a strong password.DISA STIG VMware vSphere 7.0 vCenter v1r3VMware

CONFIGURATION MANAGEMENT