Item Search

NameAudit NamePluginCategory
AS24-W1-000030 - The Apache web server must use encryption strength in accordance with the categorization of data hosted by the Apache web server when remote connections are provided - ssl_moduleDISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000090 - The Apache web server must produce log records containing sufficient information to establish what type of events occurred.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000240 - The Apache web server must not perform user management for hosted applications.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000280 - Apache web server application directories, libraries, and configuration files must only be accessible to privileged users.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000330 - The Apache web server must have Web Distributed Authoring (WebDAV) disabled.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000360 - The Apache web server must be configured to use a specified IP address and port - Zero IPs OnlyDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000590 - The Apache web server must restrict the ability of users to launch denial-of-service (DoS) attacks against other information systems or networks.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshake - RequestReadTimeoutDISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL

AS24-W1-000800 - The Apache web server must only accept client certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs).DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000310 - The Apache web server must allow the mappings to unused and vulnerable scripts to be removed.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W2-000430 - Apache web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000540 - The Apache web server must augment re-creation to a stable and known baseline.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W2-000690 - Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

ACCESS CONTROL

AS24-W2-000880 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to force the encryption of cookiesDISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-80-000005 - The ESXi host must enforce the limit of three consecutive invalid logon attempts by a user.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

ACCESS CONTROL

ESXI-80-000114 - The ESXi host must offload logs via syslog.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

ESXI-80-000124 - The ESXi host must synchronize internal information system clocks to an authoritative time source.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

AUDIT AND ACCOUNTABILITY

ESXI-80-000145 - The ESXi host must enable bidirectional Challenge-Handshake Authentication Protocol (CHAP) authentication for Internet Small Computer Systems Interface (iSCSI) traffic.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

IDENTIFICATION AND AUTHENTICATION

ESXI-80-000193 - The ESXi host must be configured to disable nonessential capabilities by disabling Secure Shell (SSH).DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

ACCESS CONTROL, CONFIGURATION MANAGEMENT

ESXI-80-000195 - The ESXi host must automatically stop shell services after 10 minutes.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-80-000234 - The ESXi host must enable strict x509 verification for SSL syslog endpoints.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

CONFIGURATION MANAGEMENT

ESXI-80-000240 - The ESXi host when using Host Profiles and/or Auto Deploy must use the vSphere Authentication Proxy to protect passwords when adding themselves to Active Directory.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

CONFIGURATION MANAGEMENT

ESXI-80-000246 - The ESXi host must not enable log filtering.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

CONFIGURATION MANAGEMENT

EX13-MB-000065 - Exchange must not send Customer Experience reports to Microsoft.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

CONFIGURATION MANAGEMENT

EX13-MB-000095 - The Exchange POP3 service must be disabled.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

CONFIGURATION MANAGEMENT

EX13-MB-000140 - The Exchange Mailbox database must not be overwritten by a restore.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-MB-000200 - Exchange Send connectors delivery retries must be controlled.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-MB-000210 - The Exchange Send connector connections count must be limited.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-MB-000230 - The Exchange Outbound Connection Timeout must be 10 minutes or less.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-MB-000270 - The Exchange Global Recipient Count Limit must be set.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

EX13-MB-000275 - The Exchange Receive connector timeout must be limited.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

ACCESS CONTROL

EX13-MB-003030 - The applications built-in Malware Agent must be disabled.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-MB-002910 - Exchange must use encryption for Outlook Web App (OWA) access.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

ACCESS CONTROL

EX19-MB-000006 - Exchange must use encryption for RPC client access.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

ACCESS CONTROL

EX19-MB-000008 - Exchange must have forms-based authentication enabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

ACCESS CONTROL

EX19-MB-000020 - Exchange must have authenticated access set to integrated Windows authentication only.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

ACCESS CONTROL

EX19-MB-000034 - The RBAC role for audit log management must be defined and restricted.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

AUDIT AND ACCOUNTABILITY

EX19-MB-000048 - Exchange queue monitoring must be configured with threshold and action.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

AUDIT AND ACCOUNTABILITY

EX19-MB-000131 - The Exchange Outbound Connection Limit per Domain Count must be controlled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000132 - The Exchange Outbound Connection Timeout must be 10 minutes or less.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000136 - Exchange external/internet-bound automated response messages must be disabled.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-MB-000142 - The Exchange Global Recipient Count Limit must be set.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-MB-000229 - The Exchange email application must not share a partition with another application.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000232 - The Exchange SMTP automated banner response must not reveal server details.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-13-002800 - Google Android 13 must be configured to enable audit logging.AirWatch - DISA Google Android 13 COBO STIG v2r3MDM

AUDIT AND ACCOUNTABILITY

GOOG-13-006100 - Google Android 13 must be configured to not allow passwords that include more than four repeating or sequential characters - CharactersAirWatch - DISA Google Android 13 COBO STIG v2r3MDM

CONFIGURATION MANAGEMENT

GOOG-13-006100 - Google Android 13 must be configured to not allow passwords that include more than four repeating or sequential characters - NumbersAirWatch - DISA Google Android 13 COBO STIG v2r3MDM

CONFIGURATION MANAGEMENT

SQL2-00-010000 - DBA OS or domain accounts must be granted only those host system privileges necessary for the administration of SQL Server.DISA STIG SQL Server 2012 Database OS Audit v1r20Windows

CONFIGURATION MANAGEMENT