Item Search

NameAudit NamePluginCategory
1.5.6 Ensure the Ctrl-Alt-Delete key sequence is disabled.CIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

1.71 UBTU-22-271030CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.89 UBTU-22-432015CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IUnix

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.8 Ensure FTP Server is not installedCIS Amazon Linux 2 STIG v2.0.1 L1 ServerUnix

CONFIGURATION MANAGEMENT

5.2.4 Ensure users must provide password for escalationCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

IDENTIFICATION AND AUTHENTICATION

6.2.9 Ensure root is the only UID 0 accountCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

AIOS-18-006950 - Apple iOS/iPadOS 18 must be configured to enforce a passcode reuse prohibition of at least two generations.MobileIron - DISA Apple iOS/iPadOS 18 v2r3MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-18-006950 - Apple iOS/iPadOS 18 must be configured to enforce a passcode reuse prohibition of at least two generations.AirWatch - DISA Apple iOS/iPadOS 18 v2r3MDM

IDENTIFICATION AND AUTHENTICATION

AIOS-26-006950 - Apple iOS/iPadOS 26 must be configured to enforce a passcode reuse prohibition of at least two generations.MobileIron - DISA Apple iOS/iPadOS 26 v1r3MDM

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037310 - AlmaLinux OS 9 must be configured so that libuser is configured to store only encrypted representations of passwords.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037530 - AlmaLinux OS 9 must be configured so that the Pluggable Authentication Module is configured to store only encrypted representations of passwords.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037640 - AlmaLinux OS 9 must be configured so that interactive user account passwords are using strong password hashes.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-037750 - AlmaLinux OS 9 must not have any File Transfer Protocol (FTP) packages installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-002031 - The macOS system must be configured to disable the system preference pane for Apple ID.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-13-002031 - The macOS system must be configured to disable the system preference pane for Apple ID.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-002038 - The macOS system must be configured to disable the "tftp" service.DISA STIG Apple macOS 13 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

CD12-00-009500 - If passwords are used for authentication, PostgreSQL must store only hashed, salted representations of passwords.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

CD12-00-010200 - PostgreSQL must enforce authorized access to all PKI private keys stored/utilized by PostgreSQL.DISA STIG Crunchy Data PostgreSQL OS v3r1Unix

IDENTIFICATION AND AUTHENTICATION

CD16-00-003800 - If passwords are used for authentication, PostgreSQL must store only hashed, salted representations of passwords.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

CD16-00-004100 - PostgreSQL must enforce authorized access to all PKI private keys stored/used by PostgreSQL.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

CNTR-K8-001161 - Sensitive information must be stored using Kubernetes Secrets or an external Secret store provider.DISA Kubernetes STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

EPAS-00-004400 - If passwords are used for authentication, the EDB Postgres Advanced Server must transmit only encrypted representations of passwords.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

IDENTIFICATION AND AUTHENTICATION

EPAS-00-004600 - The EDB Postgres Advanced Server must enforce authorized access to all PKI private keys stored/used by the EDB Postgres Advanced Server.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

IDENTIFICATION AND AUTHENTICATION

F5BI-AP-300052 - The F5 BIG-IP appliance must configure certification path validation to ensure revoked machine credentials are prohibited from establishing an allowed session.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

IDENTIFICATION AND AUTHENTICATION

F5BI-AP-300154 - The F5 BIG-IP appliance must configure certificate path validation to ensure revoked user credentials are prohibited from establishing an allowed session.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

IDENTIFICATION AND AUTHENTICATION

GEN000560 - The system must not have accounts configured with blank or null passwords.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - '.rhosts'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - '.shosts'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - 'hosts.equiv'DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - 'shosts.equiv'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN004220 - Administrative accounts must not run a web browser, except as needed for local service administration.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN004400 - Files executed through a mail aliases file must be owned by root and reside within a directory owned and writable only by root.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN004400 - Files executed through an aliases file must be owned by root and reside within a directory owned and writable only by root.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN004600 - The SMTP service must be an up-to-date version.DISA STIG AIX 6.1 v1r14Unix

SYSTEM AND INFORMATION INTEGRITY

GEN004640 - The SMTP service must not have a uudecode alias active - '/etc/aliases'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

SYSTEM AND INFORMATION INTEGRITY

GEN005000 - Anonymous FTP accounts must not have a functional shell.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN005080 - The TFTP daemon must operate in 'secure mode' which provides access only to a single directory on the host file system.DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default.DISA STIG AIX 6.1 v1r14Unix

IDENTIFICATION AND AUTHENTICATION

GEN008600 - The system must be configured to only boot from the system boot device.DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN008660 - For using GRUB, the system must be configured with GRUB as the default unless another boot loader has been authorized.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN008680 - If the system boots from removable media, it must be stored in a safe or similarly secured container.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-015200 - Oracle Database, when using public key infrastructure (PKI)-based authentication, must enforce authorized access to the corresponding private key.DISA Oracle Database 19c STIG v1r5 UnixUnix

IDENTIFICATION AND AUTHENTICATION

OS10-NDM-000480 - The Dell OS10 Switch must be configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

IDENTIFICATION AND AUTHENTICATION

SQLI-22-008200 - If passwords are used for authentication, SQL Server must transmit only encrypted representations of passwords.DISA Microsoft SQL Server 2022 Instance STIG v1r4 MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

SYMP-NM-000260 - Symantec ProxySG must transmit only encrypted representations of passwords - HTTP-Console DisabledDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

IDENTIFICATION AND AUTHENTICATION

UBTU-20-010405 - The Ubuntu operating system must not have the telnet package installed.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-24-100030 - Ubuntu 24.04 LTS must not have the telnet package installed.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

VCPG-67-000013 - VMware Postgres must be configured to use TLS.DISA STIG VMware vSphere 6.7 PostgreSQL v1r2Unix

IDENTIFICATION AND AUTHENTICATION

VCPG-70-000012 - VMware Postgres must enforce authorized access to all public key infrastructure (PKI) private keys.DISA STIG VMware vSphere 7.0 PostgreSQL v1r2Unix

IDENTIFICATION AND AUTHENTICATION

WN25-DC-000290 - Windows Server 2025 domain Controller PKI certificates must be issued by the DOD PKI or an approved External Certificate Authority (ECA).DISA Microsoft Windows Server 2025 STIG v1r1Windows

IDENTIFICATION AND AUTHENTICATION