Item Search

NameAudit NamePluginCategory
1.2.6 Ensure the version of the operating system is an active vendor supported releaseCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

1.8.13 Ensure automatic logon via GUI is not allowedCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

1.32 UBTU-24-102000CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IUnix

ACCESS CONTROL

1.58 UBTU-22-255025CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.70 UBTU-24-300027CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.71 UBTU-24-300028CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.74 UBTU-24-300031CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.101 UBTU-24-600030CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IUnix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-037420 - AlmaLinux OS 9 must be configured so that the system's shadow file is configured to store only encrypted representations of passwords.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

APPL-12-002031 - The macOS system must be configured to disable the system preference pane for Apple ID.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

ARBA-ND-000262 - AOS must be configured to use DOD-approved Online Certificate Status Protocol (OCSP) responders or Certificate Revocation Lists (CRLs) to validate certificates used for public key infrastructure (PKI)-based authentication.DISA HPE Aruba Networking AOS NDM STIG v1r1ArubaOS

IDENTIFICATION AND AUTHENTICATION

CASA-VN-000130 - The Cisco ASA must be configured to not accept certificates that have been revoked when using PKI for authentication.DISA STIG Cisco ASA VPN v2r2Cisco

IDENTIFICATION AND AUTHENTICATION

EPAS-00-004250 - If DBMS authentication, using passwords, is employed, EDB Postgres Advanced Server must enforce the DOD standards for password complexity and lifetime.EnterpriseDB PostgreSQL Advanced Server DB v2r1PostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

F5BI-DM-300056 - The F5 BIG-IP appliance must be configured to use DOD approved OCSP responders or CRLs to validate certificates used for PKI-based authentication.DISA F5 BIG-IP TMOS NDM STIG v1r2F5

IDENTIFICATION AND AUTHENTICATION

F5BI-VN-300033 - For accounts using password authentication, the F5 BIG-IP appliance site-to-site IPsec VPN Gateway must use SHA-2 or later protocol to protect the integrity of the password authentication process.DISA F5 BIG-IP TMOS VPN STIG v1r1F5

IDENTIFICATION AND AUTHENTICATION

GEN000100 - The operating system must be a supported release.DISA STIG AIX 6.1 v1r14Unix

SYSTEM AND INFORMATION INTEGRITY

GEN000100 - The operating system must be a supported release.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

SYSTEM AND INFORMATION INTEGRITY

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - '.shosts'DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - 'hosts.equiv'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - 'shosts.equiv'DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN002220 - All shell files must have mode 0755 or less permissive.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN004600 - The SMTP service must be an up-to-date version - 'postfix'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

SYSTEM AND INFORMATION INTEGRITY

GEN004600 - The SMTP service must be an up-to-date version - 'sendmail'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

SYSTEM AND INFORMATION INTEGRITY

GEN004620 - The Sendmail server must have the debug feature disabled.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN004640 - The SMTP service must not have a uudecode alias active - '/usr/lib/aliases uudecode alias does not exist'DISA STIG AIX 6.1 v1r14Unix

SYSTEM AND INFORMATION INTEGRITY

GEN004640 - The SMTP service must not have a uudecode alias active - '/usr/lib/aliases'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

SYSTEM AND INFORMATION INTEGRITY

GEN005000 - Anonymous FTP accounts must not have a functional shell.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN005100 - The TFTP daemon must have mode 0755 or less permissive.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN005140 - Any active TFTP daemon must be authorized and approved in the system accreditation package.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005200 - X displays must not be exported to the world.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN005200 - X displays must not be exported to the world.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN008640 - The system must not use removable media as the boot loader - 'normal'DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN008680 - If the system boots from removable media, it must be stored in a safe or similarly secured container.DISA STIG AIX 6.1 v1r14Unix

SYSTEM AND COMMUNICATIONS PROTECTION

IBMW-LS-000450 - The WebSphere Liberty Server must use TLS-enabled LDAP.DISA IBM WebSphere Liberty Server STIG v2r2Unix

IDENTIFICATION AND AUTHENTICATION

MD4X-00-002950 - If passwords are used for authentication, MongoDB must implement LDAP or Kerberos for authentication to enforce the DoD standards for password complexity and lifetime.DISA STIG MongoDB Enterprise Advanced 4.x v1r4 OSUnix

IDENTIFICATION AND AUTHENTICATION

MD4X-00-003000 - If passwords are used for authentication, MongoDB must store only hashed, salted representations of passwords.DISA STIG MongoDB Enterprise Advanced 4.x v1r4 OSUnix

IDENTIFICATION AND AUTHENTICATION

MD4X-00-003100 - MongoDB must enforce authorized access to all PKI private keys stored/utilized by MongoDB.DISA STIG MongoDB Enterprise Advanced 4.x v1r4 OSUnix

IDENTIFICATION AND AUTHENTICATION

MD7X-00-003800 - If passwords are used for authentication, MongoDB must store only hashed, salted representations of passwords.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 UnixUnix

IDENTIFICATION AND AUTHENTICATION

MD8X-00-003900 - MongoDB must enforce authorized access to all PKI private keys stored/used by the DBMS.DISA MongoDB Enterprise Advanced 8.x STIG v1r1 UnixUnix

IDENTIFICATION AND AUTHENTICATION

MYS8-00-004800 - The MySQL Database Server 8.0 must enforce authorized access to all PKI private keys stored/utilized by the MySQL Database Server 8.0.DISA Oracle MySQL 8.0 v2r2 OS LinuxUnix

IDENTIFICATION AND AUTHENTICATION

MYS8-00-005200 - If passwords are used for authentication, the MySQL Database Server 8.0 must transmit only encrypted representations of passwords.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-014800 - Oracle Database must, for password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-014800 - Oracle Database must, for password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key.DISA Oracle Database 19c STIG v1r5 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key.DISA Oracle Database 19c STIG v1r3 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200070 - RHEL 10 must not have the "tftp" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-600740 - RHEL 10 must be configured to use the shadow file to store only encrypted representations of passwords.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-20-010006 - The Ubuntu operating system must map the authenticated identity to the user or group account for PKI-based authentication.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION

VCPG-67-000014 - VMware Postgres must enforce authorized access to all PKI private keys.DISA STIG VMware vSphere 6.7 PostgreSQL v1r2Unix

IDENTIFICATION AND AUTHENTICATION

WN25-AC-000090 - Windows Server 2025 reversible password encryption must be disabled.DISA Microsoft Windows Server 2025 STIG v1r1Windows

IDENTIFICATION AND AUTHENTICATION