Item Search

NameAudit NamePluginCategory
1.3.2 Set the 'banner-text' for 'banner login'CIS Cisco IOS 12 L1 v4.0.0Cisco

ACCESS CONTROL

1.12 CISC-RT-000210CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.12 CISC-RT-000210CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.23 CISC-RT-000320CIS Cisco IOS Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.24 CISC-ND-000620CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

IDENTIFICATION AND AUTHENTICATION

1.68 CISC-RT-000670CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT ICisco

CONTINGENCY PLANNING

2.1.1.1.2 Set the 'ip domain name'CIS Cisco IOS 12 L1 v4.0.0Cisco

CONFIGURATION MANAGEMENT

3.3.1.4 Set 'address-family ipv4 autonomous-system'CIS Cisco IOS XE 17.x v2.2.1 L2Cisco

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1.4 Set 'address-family ipv4 autonomous-system'CIS Cisco IOS XE 16.x v2.2.0 L2Cisco

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.3.2.1 Set 'authentication message-digest' for OSPF areaCIS Cisco IOS XE 17.x v2.2.1 L1Cisco

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

5.5.1.2 Ensure minimum days between password changes is configured - login.defsCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.5.1.2 Ensure minimum days between password changes is configured - password shadowCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.22 Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT

18.4.5 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT, RISK ASSESSMENT

18.5.4 (L1) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.5.4 (L1) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2016 v4.0.0 L1 DCWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.5.4 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2019 v5.0.0 L1 MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.5.4 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

CONFIGURATION MANAGEMENT

18.5.4 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.5.5 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

18.5.5 Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

ARST-RT-000430 - The out-of-band management (OOBM) Arista gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the NOC.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000430 - The out-of-band management (OOBM) Arista gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the NOC.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.DISA Cisco IOS Router NDM STIG v3r8Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-RT-000440 - The Cisco out-of-band management (OOBM) gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the Network Operations Center (NOC).DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000580 - The Cisco BGP router must be configured to use its loopback address as the source address for iBGP peering sessions.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

Ensure IPv6 router advertisements are not accepted - /etc/sysctl ipv6 all acceptTenable Cisco Firepower Management Center OS Best Practices AuditUnix

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure IPv6 router advertisements are not accepted - /etc/sysctl ipv6 default acceptTenable Cisco Firepower Management Center OS Best Practices AuditUnix

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure IPv6 router advertisements are not accepted - sysctl ipv6 all acceptTenable Cisco Firepower Management Center OS Best Practices AuditUnix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003600 - The system must not forward IPv4 source-routed packets - 'net.ipv4.conf.default.accept_source_route'DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL

GEN003600 - The system must not forward IPv4 source-routed packets - 'net.ipv4.conf.default.accept_source_route'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003600 - The system must not forward IPv4 source-routed packets.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN003600 - The system must not forward IPv4 source-routed packets.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005580 - A system used for routing must not run other network services or applications.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

GEN007920 - The system must not forward IPv6 source-routed packets - 'net.ipv6.conf.default.forwarding'DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

GEN007920 - The system must not forward IPv6 source-routed packets - 'net.ipv6.conf.default.forwarding'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN007920 - The system must not forward IPv6 source-routed packets.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN007920 - The system must not forward IPv6 source-routed packets.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

JUEX-NM-000490 - The Juniper EX switch must use an an NTP service that is hosted by a trusted source or a DOD-compliant enterprise or local NTP server.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

OL07-00-040610 - The Oracle Linux operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040620 - The Oracle Linux operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets by default.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OS10-RTR-000480 - The Dell OS10 out-of-band management (OOBM) gateway router must be configured to block any traffic destined to itself that is not sourced from the OOBM network or the NOC.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-254010 - RHEL 9 must not accept router advertisements on all IPv6 interfaces.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-09-254030 - RHEL 9 must not accept router advertisements on all IPv6 interfaces by default.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

CONFIGURATION MANAGEMENT

RHEL-10-800220 - RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SHPT-00-000760 - SharePoint must implement security functions as largely independent modules to avoid unnecessary interactions between modules - Central Administration is a separate App PoolDISA STIG SharePoint 2010 v1r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SHPT-00-000760 - SharePoint must implement security functions as largely independent modules to avoid unnecessary interactions between modules - No Applications assigned to Default App PoolDISA STIG SharePoint 2010 v1r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-030360 - The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

UBTU-16-030530 - The Ubuntu operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT