Item Search

NameAudit NamePluginCategory
1.9 SQLI-22-004300CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT II MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

1.47 RHEL-10-200620CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.143 ALMA-09-018830CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

3.1 Ignore Erroneous or Unwanted Queries - Link local addressesCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

CONFIGURATION MANAGEMENT

3.1 Ignore Erroneous or Unwanted Queries - Link local addressesCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

CONFIGURATION MANAGEMENT

3.1 Ignore Erroneous or Unwanted Queries - Multicast addressesCIS BIND DNS v3.0.1 Caching Only Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Ignore Erroneous or Unwanted Queries - Multicast addressesCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

CONFIGURATION MANAGEMENT

3.1 Ignore Erroneous or Unwanted Queries - RFC 1918 172.16/12; addressesCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

CONFIGURATION MANAGEMENT

3.1 Ignore Erroneous or Unwanted Queries - RFC 1918 172.16/12; addressesCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

CONFIGURATION MANAGEMENT

3.1 Ignore Erroneous or Unwanted Queries - RFC 1918 192.168/16; addressesCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

CONFIGURATION MANAGEMENT

3.6 Verify that docker.socket file permissions are set to 644 or more restrictiveCIS Docker 1.6 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

5.4.7 Ensure minimum and maximum requirements are set for password changes - difokCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.7 Ensure minimum and maximum requirements are set for password changes - maxclassrepeatCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.7 Ensure minimum and maximum requirements are set for password changes - maxrepeatCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.7 Ensure minimum and maximum requirements are set for password changes - minclassCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.7 Ensure minimum and maximum requirements are set for password changes - minlenCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.140 - The HBSS McAfee Agent is not installed. - FrameworkServiceDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

12 - AutoSupport - Transport typeNetApp Security Hardening Guide for ONTAP 9 v1.7.0Netapp_API
APPNET0060 - Remoting Services HTTP channels must utilize authentication and encryption.DISA Microsoft DotNet Framework 4.0 STIG v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-12-006500 - Google Android 12 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DoD-approved commercial app repository, MDM server, mobile application store].MobileIron - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-006500 - Google Android 12 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DoD-approved commercial app repository, MDM server, mobile application store].AirWatch - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-006500 - Google Android 12 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DoD-approved commercial app repository, MDM server, mobile application store].MobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-010300 - Google Android 12 must be provisioned as a fully managed device and configured to create a work profile.AirWatch - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-010300 - Google Android 12 must be provisioned as a fully managed device and configured to create a work profile.MobileIron - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

JBOS-AS-000080 - The JBoss server must generate log records for access and authentication events to the management interface.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-255050 - Ubuntu 22.04 LTS must configure the SSH daemon to use FIPS 140-3-approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-255065 - Ubuntu 22.04 LTS must use strong authenticators in establishing nonlocal maintenance and diagnostic sessions.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

MAINTENANCE

UBTU-22-271015 - Ubuntu 22.04 LTS must display the Standard Mandatory DOD Notice and Consent Banner before granting local access to the system via a graphical user logon.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-271020 - Ubuntu 22.04 LTS must retain a user's session lock until that user reestablishes access using established identification and authentication procedures.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-271025 - Ubuntu 22.04 LTS must initiate a graphical session lock after 10 minutes of inactivity.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-411015 - Ubuntu 22.04 LTS must uniquely identify interactive users.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-411030 - Ubuntu 22.04 LTS must enforce a 60-day maximum password lifetime restriction. Passwords for new users must have a 60-day maximum password lifetime restriction.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-411035 - Ubuntu 22.04 LTS must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-411040 - Ubuntu 22.04 LTS must automatically expire temporary accounts within 72 hours.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-611010 - Ubuntu 22.04 LTS must enforce password complexity by requiring at least one uppercase character be used.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-611070 - Ubuntu 22.04 LTS must encrypt all stored passwords with a FIPS 140-3-approved cryptographic hashing algorithm.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-22-651030 - Ubuntu 22.04 LTS must use cryptographic mechanisms to protect the integrity of audit tools.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-652010 - Ubuntu 22.04 LTS must be configured to preserve log records from failure events.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-652015 - Ubuntu 22.04 LTS must monitor remote access methods.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL

UBTU-22-653020 - Ubuntu 22.04 LTS audit event multiplexor must be configured to offload audit logs onto a different system from the system being audited.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-653030 - Ubuntu 22.04 LTS must shut down by default upon audit failure.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-653050 - Ubuntu 22.04 LTS must be configured to permit only authorized users ownership of the audit log files.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-653075 - Ubuntu 22.04 LTS must permit only authorized groups to own the audit configuration files.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654055 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use the kmod command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654060 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful attempts to use modprobe command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654065 - Ubuntu 22.04 LTS must generate audit records for successful/unsuccessful uses of the mount command.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

UBTU-22-654145 - Ubuntu 22.04 LTS must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

UBTU-22-654190 - Ubuntu 22.04 LTS must generate audit records for all events that affect the systemd journal files.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

CONFIGURATION MANAGEMENT

UBTU-22-654225 - Ubuntu 22.04 LTS must generate audit records when successful/unsuccessful attempts to modify the /etc/sudoers.d directory occur.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

WG400 A22 - All interactive programs (CGI) must be placed in a designated directory with appropriate permissions.DISA STIG Apache Site 2.2 Unix v1r11Unix

ACCESS CONTROL