Item Search

NameAudit NamePluginCategory
1.51 CISC-RT-000490CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

ACCESS CONTROL

1.61 CISC-RT-000600CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IIICisco

CONFIGURATION MANAGEMENT

1.67 CISC-RT-000660CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

IDENTIFICATION AND AUTHENTICATION

1.68 CISC-RT-000660CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

IDENTIFICATION AND AUTHENTICATION

1.91 CISC-RT-000900CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.92 CISC-RT-000900CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.92 CISC-RT-000910CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

IDENTIFICATION AND AUTHENTICATION

2.1.4 Set 'no service dhcp'CIS Cisco IOS 12 L1 v4.0.0Cisco

CONFIGURATION MANAGEMENT

3.1 URPFCIS Cisco IOS XR 7.x v1.0.1 L2Cisco

SYSTEM AND INFORMATION INTEGRITY

3.2 Authentication and Verification of ISIS Routing Protocols - authentication-type hmac-md5/authentication-keychainTenable ZTE ROSNG Best PracticesZTE_ROSNG
3.3.1.4 Ensure net.ipv4.conf.all.send_redirects is configuredCIS Debian Linux 13 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.4 Ensure net.ipv4.conf.all.send_redirects is configuredCIS Debian Linux 13 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.4 Ensure net.ipv4.conf.all.send_redirects is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.5 Ensure net.ipv4.conf.default.send_redirects is configuredCIS Debian Linux 13 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.5 Ensure net.ipv4.conf.default.send_redirects is configuredCIS Amazon Linux 2 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.5 Ensure net.ipv4.conf.default.send_redirects is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.5 Ensure net.ipv4.conf.default.send_redirects is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.5 Ensure net.ipv4.conf.default.send_redirects is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.5 Ensure net.ipv4.conf.default.send_redirects is configuredCIS Debian Linux 12 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.5 Ensure net.ipv4.conf.default.send_redirects is configuredCIS Debian Linux 13 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.1 Set 'authentication message-digest' for OSPF areaCIS Cisco IOS XE 16.x v2.2.0 L2Cisco

IDENTIFICATION AND AUTHENTICATION

3.3.3.1 Set 'neighbor password'CIS Cisco IOS XE 16.x v2.2.0 L2Cisco

IDENTIFICATION AND AUTHENTICATION

4.1.1 Disable IP Forwarding - net.ipv4.ip_forward = 0CIS Red Hat Enterprise Linux 5 L1 v2.2.1Unix

CONFIGURATION MANAGEMENT

18.4.5 (L1) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT, RISK ASSESSMENT

AMLS-L3-000140 - The Arista Multilayer Switch must be configured so inactive router interfaces are disabled.DISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

ACCESS CONTROL

AMLS-L3-000180 - The Arista Multilayer Switch must enforce that Interior Gateway Protocol instances configured on the out-of-band management gateway router only peer with their own routing domain.DISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

ACCESS CONTROL

AMLS-L3-000230 - The Arista Multilayer Switch must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding.DISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000450 - The Arista perimeter router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000570 - The Arista BGP router must be configured to limit the prefix size on any inbound route advertisement to /24 or the least significant prefixes issued to the customer.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000570 - The Arista BGP router must be configured to limit the prefix size on any inbound route advertisement to /24 or the least significant prefixes issued to the customer.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000600 - The Arista BGP router must be configured to enable the Generalized TTL Security Mechanism (GTSM).DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000680 - The Arista Multicast Source Discovery Protocol (MSDP) router must be configured to only accept MSDP packets from known MSDP peers.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000680 - The Arista Multicast Source Discovery Protocol (MSDP) router must be configured to only accept MSDP packets from known MSDP peers.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

BGP: Disable Capability NegotiationTNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000310 - The Cisco perimeter router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA Cisco IOS Router RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000490 - The Cisco BGP router must be configured to reject inbound route advertisements for any Bogon prefixes.DISA Cisco IOS Router RTR STIG v3r4Cisco

ACCESS CONTROL

CISC-RT-000670 - The Cisco PE router providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate pseudowire ID for each attachment circuit.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

DG0071-ORACLE11 - New passwords must be required to differ from old passwords by more than four characters - 'PASSWORD_VERIFY_FUNCTION is not set to NULL or DEFAULT'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
Huawei: Insecure HTTP is not configured.TNS Huawei VRP Best Practice AuditHuawei

CONFIGURATION MANAGEMENT

JUEX-NM-000240 - The Juniper EX switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

ACCESS CONTROL

JUSX-DM-000020 - The Juniper SRX Services Gateway must generate an alert message to the management console and generate a log event record that can be forwarded to the ISSO and designated system administrators when the local accounts (i.e., the account of last resort or root account) are modified.DISA Juniper SRX Services Gateway NDM v3r3Juniper

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

JUSX-DM-000021 - The Juniper SRX Services Gateway must generate an alert message to the management console and generate a log event record that can be forwarded to the ISSO and designated system administrators when accounts are disabled.DISA Juniper SRX Services Gateway NDM v3r3Juniper

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

JUSX-DM-000055 - The Juniper SRX Services Gateway must generate log records containing the full-text recording of privileged commands.DISA Juniper SRX Services Gateway NDM v3r3Juniper

AUDIT AND ACCOUNTABILITY

JUSX-DM-000106 - The Juniper SRX Services Gateway must generate an alarm or send an alert message to the management console when a component failure is detected.DISA Juniper SRX Services Gateway NDM v3r3Juniper

CONFIGURATION MANAGEMENT

JUSX-IP-000027 - The Juniper Networks SRX Series Gateway IDPS must perform real-time monitoring of files from external sources at network entry/exit points.DISA Juniper SRX Services Gateway IDPS v2r1Juniper

SYSTEM AND INFORMATION INTEGRITY

OL6-00-000268 - The rdisc service must not be running - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000268 - The rdisc service must not be running - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL09-00-006026 - OL 9 must not forward IPv4 source-routed packets by default.DISA Oracle Linux 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

RHEL-10-800240 - RHEL 10 must not forward Internet Protocol version 6 (IPv6) source-routed packets.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WN22-MS-000010 - Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL