| AZLX-23-000050 - Amazon Linux 2023 must enable FIPS mode. | DISA Amazon Linux 2023 STIG v1r4 | Unix | ACCESS CONTROL |
| AZLX-23-000215 - Amazon Linux 2023 must disable access to network bpf system call from nonprivileged processes. | DISA Amazon Linux 2023 STIG v1r4 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| AZLX-23-000305 - Amazon Linux 2023 must not have the sendmail package installed. | DISA Amazon Linux 2023 STIG v1r4 | Unix | CONFIGURATION MANAGEMENT |
| AZLX-23-001000 - Amazon Linux 2023 must have the sudo package installed. | DISA Amazon Linux 2023 STIG v1r4 | Unix | ACCESS CONTROL |
| AZLX-23-001010 - Amazon Linux 2023 must require reauthentication when using the "sudo" command. | DISA Amazon Linux 2023 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AZLX-23-001030 - Amazon Linux 2023 must produce audit records containing information to establish what type of events occurred. | DISA Amazon Linux 2023 STIG v1r4 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| AZLX-23-001065 - Amazon Linux 2023 must routinely check the baseline configuration for unauthorized changes and notify the system administrator (SA) when anomalies in the operation of any security functions are discovered. | DISA Amazon Linux 2023 STIG v1r4 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| AZLX-23-001090 - Amazon Linux 2023 must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial-of-service (DoS) attacks. | DISA Amazon Linux 2023 STIG v1r4 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| AZLX-23-001185 - Amazon Linux 2023 must implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. | DISA Amazon Linux 2023 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| AZLX-23-001206 - The Amazon Linux 2023 SSH client must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Amazon Linux 2023 STIG v1r4 | Unix | ACCESS CONTROL |
| AZLX-23-001215 - Amazon Linux 2023 SSH daemon must not allow Generic Security Service Application Program Interface (GSSAPI) authentication. | DISA Amazon Linux 2023 STIG v1r4 | Unix | CONFIGURATION MANAGEMENT |
| AZLX-23-001220 - Amazon Linux 2023 SSH daemon must not allow Kerberos authentication. | DISA Amazon Linux 2023 STIG v1r4 | Unix | CONFIGURATION MANAGEMENT |
| AZLX-23-001240 - Amazon Linux 2023 must not permit direct logons to the root account using remote access via SSH. | DISA Amazon Linux 2023 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AZLX-23-002315 - Amazon Linux 2023 must ensure the /var/log directory have mode "0755" or less permissive. | DISA Amazon Linux 2023 STIG v1r4 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| AZLX-23-002335 - Amazon Linux 2023 must ensure the /var/log/messages file be group-owned by root. | DISA Amazon Linux 2023 STIG v1r4 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| AZLX-23-002340 - Amazon Linux 2023 must ensure the /var/log/messages file be owned by root. | DISA Amazon Linux 2023 STIG v1r4 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| AZLX-23-002345 - Amazon Linux 2023 system commands must be owned by root. | DISA Amazon Linux 2023 STIG v1r4 | Unix | CONFIGURATION MANAGEMENT |
| AZLX-23-002370 - Amazon Linux 2023 must require the change of at least 50 percent of the total number of characters when passwords are changed. | DISA Amazon Linux 2023 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AZLX-23-002465 - Amazon Linux 2023 must automatically lock an account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes occur. | DISA Amazon Linux 2023 STIG v1r4 | Unix | ACCESS CONTROL |
| AZLX-23-002480 - Amazon Linux 2023 must insure all interactive users have a primary group that exists. | DISA Amazon Linux 2023 STIG v1r4 | Unix | AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| AZLX-23-002490 - Amazon Linux 2023 password-auth must be configured to use a sufficient number of hashing rounds. | DISA Amazon Linux 2023 STIG v1r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| AZLX-23-002515 - Amazon Linux 2023 must enable auditing of processes that start prior to the audit daemon. | DISA Amazon Linux 2023 STIG v1r4 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| AZLX-23-002565 - Amazon Linux 2023 must synchronize internal information system clocks to the authoritative time source at least every 24 hours. | DISA Amazon Linux 2023 STIG v1r4 | Unix | AUDIT AND ACCOUNTABILITY |
| AZLX-23-005000 - Amazon Linux 2023 audit system must protect logon user identifiers (UIDs) from unauthorized change. | DISA Amazon Linux 2023 STIG v1r4 | Unix | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000035 - The FortiGate device must allow full access to only those individuals or roles designated by the ISSM. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | ACCESS CONTROL |
| FGFW-ND-000040 - The FortiGate device must audit the execution of privileged functions | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | ACCESS CONTROL |
| FGFW-ND-000045 - The FortiGate device must enforce the limit of three consecutive invalid logon attempts, after which time it must lock out the user account from accessing the device for 15 minutes | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | ACCESS CONTROL |
| FGFW-ND-000055 - The FortiGate device must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log on for further access. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | ACCESS CONTROL |
| FGFW-ND-000070 - The FortiGate device must generate audit records when successful/unsuccessful attempts to delete administrator privileges occur | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000085 - The FortiGate device must generate audit records showing starting and ending time for administrator access to the system | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000090 - The FortiGate device must generate audit records when concurrent logons from different workstations occur | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000105 - The FortiGate device must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000110 - The FortiGate device must off-load audit records on to a different system or media than the system being audited. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000115 - The FortiGate device must generate an immediate real-time alert of all audit failure events requiring real-time alerts. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000125 - The FortiGate device must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT). | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000130 - The FortiGate device must protect audit information from unauthorized deletion. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | AUDIT AND ACCOUNTABILITY |
| FGFW-ND-000145 - The FortiGate device must prohibit installation of software without explicit privileged status. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | CONFIGURATION MANAGEMENT |
| FGFW-ND-000150 - The FortiGate device must enforce access restrictions associated with changes to device configuration. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | CONFIGURATION MANAGEMENT |
| FGFW-ND-000160 - The FortiGate device must enforce access restrictions associated with changes to the system components. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | CONFIGURATION MANAGEMENT |
| FGFW-ND-000195 - The FortiGate device must use DoD-approved Certificate Authorities (CAs) for public key certificates. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| FGFW-ND-000200 - The FortiGate device must prohibit the use of all unnecessary and/or non-secure functions, ports, protocols, and/or services. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | CONFIGURATION MANAGEMENT |
| FGFW-ND-000210 - The FortiGate device must authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC) | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| FGFW-ND-000220 - The FortiGate device must enforce a minimum 15-character password length. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| FGFW-ND-000240 - The FortiGate device must enforce password complexity by requiring that at least one special character be used. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| FGFW-ND-000245 - The FortiGate device must use LDAPS for the LDAP connection. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| FGFW-ND-000255 - The FortiGate device must use FIPS 140-2 approved algorithms for authentication to a cryptographic module. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | IDENTIFICATION AND AUTHENTICATION |
| FGFW-ND-000260 - The FortiGate devices must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | MAINTENANCE |
| FGFW-ND-000270 - The FortiGate device must terminate idle sessions after 10 minutes of inactivity. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | MAINTENANCE |
| FGFW-ND-000275 - The FortiGate device must terminate idle sessions after 10 minutes of inactivity. | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | SYSTEM AND COMMUNICATIONS PROTECTION |
| FGFW-ND-000300 - The FortiGate device must limit the number of logon and user sessions | DISA Fortigate Firewall NDM STIG v1r4 | FortiGate | ACCESS CONTROL |