Item Search

NameAudit NamePluginCategory
3.121 - The system does not have a backup administrator accountDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

AZLX-23-000100 - Amazon Linux 2023 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-000210 - Amazon Linux 2023 must restrict exposed kernel pointer addresses access.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

AZLX-23-000225 - Amazon Linux 2023 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND INFORMATION INTEGRITY

AZLX-23-000300 - Amazon Linux 2023 must not have the vsftpd package installed.DISA Amazon Linux 2023 STIG v1r4Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

AZLX-23-000310 - Amazon Linux 2023 must not have the nfs-utils package installed.DISA Amazon Linux 2023 STIG v1r4Unix

CONFIGURATION MANAGEMENT

AZLX-23-000315 - Amazon Linux 2023 must not have the telnet-server package installed.DISA Amazon Linux 2023 STIG v1r4Unix

CONFIGURATION MANAGEMENT

AZLX-23-001015 - Amazon Linux 2023 must require users to reauthenticate for privilege escalation.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

AZLX-23-001025 - Amazon Linux 2023 must have the audit package installed.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

AZLX-23-001050 - Amazon Linux 2023 must have the chrony package installed.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY

AZLX-23-001060 - Amazon Linux 2023 must have the Advanced Intrusion Detection Environment (AIDE) package installed.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

AZLX-23-001075 - Amazon Linux 2023 must have the firewalld package installed.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AZLX-23-001105 - Amazon Linux 2023 must have the libreswan package installed.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

AZLX-23-001180 - Amazon Linux 2023 must have SSH installed.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-001205 - Amazon Linux 2023 server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-2/140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL

AZLX-23-001225 - Amazon Linux 2023 must force a frequent session key renegotiation for SSH connections to the server.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-001250 - Amazon Linux 2023 must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-001300 - Amazon Linux 2023 must implement certificate status checking for multifactor authentication.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

AZLX-23-002020 - Amazon Linux 2023 must use a separate file system for the system audit data path.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY

AZLX-23-002075 - Amazon Linux 2023 must encrypt, via the OpenSSL TLS (ossl) driver, the transfer of audit records off-loaded onto a different system or media from the system being audited by rsyslog.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY

AZLX-23-002125 - Amazon Linux 2023 must audit all uses of the setxattr, fsetxattr, lsetxattr, removexattr, fremovexattr, and lremovexattr system calls.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

AZLX-23-002155 - Amazon Linux 2023 must audit all uses of the chcon command.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

AZLX-23-002165 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/lastlog.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

AZLX-23-002205 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

AZLX-23-002220 - Amazon Linux 2023 must off-load audit records onto a different system in the event the audit storage volume is full.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY

AZLX-23-002235 - Amazon Linux 2023 audit logs file must have mode "0600" or less permissive to prevent unauthorized access to the audit log.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

AZLX-23-002240 - Amazon Linux 2023 must allow only the information system security manager (ISSM) (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY

AZLX-23-002250 - Amazon Linux 2023 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

AZLX-23-002260 - Amazon Linux 2023 must produce audit records containing information to establish the identity of any individual or process associated with the event.DISA Amazon Linux 2023 STIG v1r4Unix

AUDIT AND ACCOUNTABILITY

AZLX-23-002285 - Amazon Linux 2023 library directories must have mode "755" or less permissive.DISA Amazon Linux 2023 STIG v1r4Unix

CONFIGURATION MANAGEMENT

AZLX-23-002365 - Amazon Linux 2023 must enforce password complexity by requiring that at least one numeric character be used.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

AZLX-23-002396 - Amazon Linux 2023 must automatically exit interactive command shell user sessions after 10 minutes of inactivity.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-002400 - Amazon Linux 2023 must enforce 24 hours/1 day as the minimum password lifetime.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

AZLX-23-002420 - Amazon Linux 2023 must automatically lock an account when three unsuccessful logon attempts occur.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL

AZLX-23-002445 - Amazon Linux 2023 must enable the SELinux targeted policy.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND INFORMATION INTEGRITY

AZLX-23-002450 - Amazon Linux 2023 must use a Linux Security Module configured to enforce limits on system services.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

AZLX-23-002500 - Amazon Linux 2023 must ensure a sticky bit be set on all public directories.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-002510 - Amazon Linux 2023 must terminate idle user sessions.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-002575 - Amazon Linux 2023 must prevent the loading of a new kernel for later execution.DISA Amazon Linux 2023 STIG v1r4Unix

CONFIGURATION MANAGEMENT

AZLX-23-002605 - Amazon Linux 2023 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures are configured on impacted network interfaces.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-002620 - Amazon Linux 2023 must configure the use of the pam_faillock.so module in the /etc/pam.d/system-auth file.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL

FGFW-ND-000050 - The FortiGate device must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.DISA Fortigate Firewall NDM STIG v1r4FortiGate

ACCESS CONTROL

FGFW-ND-000095 - The FortiGate device must generate audit records containing information that establishes the identity of any individual or process associated with the event.DISA Fortigate Firewall NDM STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FGFW-ND-000165 - The FortiGate device must use LDAP for authentication.DISA Fortigate Firewall NDM STIG v1r4FortiGate

CONFIGURATION MANAGEMENT

FGFW-ND-000170 - The FortiGate device must be running an operating system release that is currently supported by the vendor.DISA Fortigate Firewall NDM STIG v1r4FortiGate

CONFIGURATION MANAGEMENT

FGFW-ND-000185 - The FortiGate device must support organizational requirements to conduct backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner.DISA Fortigate Firewall NDM STIG v1r4FortiGate

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

FGFW-ND-000205 - The FortiGate device must implement replay-resistant authentication mechanisms for network access to privileged accountsDISA Fortigate Firewall NDM STIG v1r4FortiGate

IDENTIFICATION AND AUTHENTICATION

FGFW-ND-000230 - The FortiGate device must enforce password complexity by requiring that at least one lowercase character be used.DISA Fortigate Firewall NDM STIG v1r4FortiGate

IDENTIFICATION AND AUTHENTICATION

FGFW-ND-000235 - The FortiGate device must enforce password complexity by requiring at least one numeric character be used.DISA Fortigate Firewall NDM STIG v1r4FortiGate

IDENTIFICATION AND AUTHENTICATION

FGFW-ND-000285 - The FortiGate device must only allow authorized administrators to view or change the device configuration, system files, and other files stored either in the device or on removable media (such as a flash drive).DISA Fortigate Firewall NDM STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION