Item Search

NameAudit NamePluginCategory
1.1 Set 'Turn on Enhanced Protected Mode' to 'Enabled'CIS IE 11 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.1.8 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 v1.0.0 End User Owned L1MDM

ACCESS CONTROL

2.2.1.8 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'MobileIron - CIS Apple iOS 10 v2.0.0 End User Owned L1MDM
2.2.1.8 Ensure 'Treat AirDrop as unmanaged destination' is set to 'Enabled'MobileIron - CIS Apple iOS 11 v1.0.0 End User Owned L1MDM
2.3.10.10 (L1) Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL

2.3.10.10 Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

ACCESS CONTROL

2.3.10.10 Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

ACCESS CONTROL

2.3.10.10 Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

ACCESS CONTROL

2.3.10.10 Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

ACCESS CONTROL

5.4.1.5 Ensure inactive password lock is configuredCIS Debian Linux 13 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Oracle Linux 10 v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Oracle Linux 9 v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Ubuntu Linux 20.04 LTS v3.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS AlmaLinux OS 9 v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Debian Linux 12 v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Rocky Linux 10 v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Rocky Linux 9 v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.5.1.5 Ensure inactive password lock is configuredCIS Amazon Linux 2 v4.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

6.4 Configure 'Turn on Suggested Sites'CIS IE 11 v1.0.0Windows

CONFIGURATION MANAGEMENT

8.1.12 Set 'Java permissions' to 'Enabled:Disable Java'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

8.3.16 Set 'Java permissions' to 'Enabled:Disable Java'CIS IE 9 v1.0.0Windows

CONFIGURATION MANAGEMENT

49.18 Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'CIS Microsoft Intune for Windows 11 v5.0.0 L1Windows

ACCESS CONTROL

49.18 Ensure 'Network access: Restrict clients allowed to make remote calls to SAM' is set to 'Administrators: Remote Access: Allow'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

ACCESS CONTROL

DISA_IBM_WebSphere_Liberty_Server_STIG_v2r2.audit from DISA IBM WebSphere Liberty Server STIG v2r2DISA IBM WebSphere Liberty Server STIG v2r2Unix
DISA_STIG_Apache_Site-2.2_Unix_v1r11.audit from DISA Apache 2.2 Unix STIG v1r11DISA STIG Apache Site 2.2 Unix v1r11Unix
DISA_STIG_Apple_macOS_13_v1r5.audit from DISA Apple macOS 13 (Ventura) v1r5 STIGDISA STIG Apple macOS 13 v1r5Unix
DISA_STIG_Apple_macOS_15_Sequoia_v1r7.audit from DISA Apple macOS 15 Sequoia STIG v1r7DISA Apple macOS 15 Sequoia STIG v1r7Unix
DISA_STIG_Apple_macOS_26_Tahoe_v1r3.audit from DISA Apple macOS 26 Tahoe STIG v1r3DISA Apple macOS 26 Tahoe STIG v1r3Unix
DISA_STIG_Canonical_Ubuntu_20.04_LTS_v2r4.audit from DISA Canonical Ubuntu 20.04 LTS STIG v2r4DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix
DISA_STIG_EDB_PostgreSQL_Advanced_Server_v9.6_v2r3_OS_Linux.audit from DISA EDB Postgres Advanced Server v9.6 v2r3 STIGEDB PostgreSQL Advanced Server OS Linux Audit v2r3Unix
DISA_STIG_IIS_10.0_Web_Site_v2r14.audit from DISA Microsoft IIS 10.0 Site v2r14 STIGDISA IIS 10.0 Site v2r14Windows
DISA_STIG_Microsoft_Internet_Explorer_11_v2r7.audit from DISA Microsoft Internet Explorer 11 v2r7 STIGDISA STIG IE 11 v2r7Windows
EX16-ED-000570 - Exchange must render hyperlinks from email sources from non-.mil domains as unclickable.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-ED-000122 - Active hyperlinks in messages from non .mil domains must be rendered unclickable.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

GEN002820-7 - The audit system must be configured to audit all discretionary access control permission modifications - 'lchown'DISA STIG for Oracle Linux 5 v2r1Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

GEN002860 - Audit logs must be rotated daily.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002860 - Audit logs must be rotated daily.DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN002860 - Audit logs must be rotated daily.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

KNOX-07-003000 - The Samsung must be configured to enable encryption for information at rest on removable storage media.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

KNOX-07-003000 - The Samsung must be configured to enable encryption for information at rest on removable storage media.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

KNOX-07-006100 - The Samsung Android 7 with Knox must be configured to disable multi-user modes.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

WBLC-08-000210 - Oracle WebLogic must terminate the network connection associated with a communications session at the end of the session or after a DoD-defined time period of inactivity.Oracle WebLogic Server 12c Linux v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION