Item Search

NameAudit NamePluginCategory
2.2.1.6 Ensure 'Force automatic date and time' is set to 'Enabled'MobileIron - CIS Apple iOS 26 v1.0.0 L1 End User OwnedMDM

AUDIT AND ACCOUNTABILITY

2.2.1.6 Ensure 'Force automatic date and time' is set to 'Enabled'MobileIron - CIS Apple iOS 18 v2.0.0 L1 End User OwnedMDM

AUDIT AND ACCOUNTABILITY

2.2.1.7 Ensure 'Force automatic date and time' is set to 'Enabled'MobileIron - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

AUDIT AND ACCOUNTABILITY

2.2.1.7 Ensure 'Force automatic date and time' is set to 'Enabled'MobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

AUDIT AND ACCOUNTABILITY

3.1 Ignore Erroneous or Unwanted Queries - Link local addressesCIS BIND DNS v3.0.1 Authoritative Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Ignore Erroneous or Unwanted Queries - Multicast addressesCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

CONFIGURATION MANAGEMENT

3.1 Ignore Erroneous or Unwanted Queries - RFC 1918 10/8; addressesCIS BIND DNS v3.0.1 Caching Only Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Ignore Erroneous or Unwanted Queries - RFC 1918 10/8; addressesCIS BIND DNS v3.0.1 Authoritative Name ServerUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1.17 Ensure 'Force automatic date and time' is set to 'Enabled'AirWatch - CIS Apple iPadOS 18 v2.0.0 L1 Institutionally OwnedMDM

AUDIT AND ACCOUNTABILITY

3.2.1.17 Ensure 'Force automatic date and time' is set to 'Enabled'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

AUDIT AND ACCOUNTABILITY

3.2.1.17 Ensure 'Force automatic date and time' is set to 'Enabled'AirWatch - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally OwnedMDM

AUDIT AND ACCOUNTABILITY

3.5 Verify that docker.socket file ownership is set to root:rootCIS Docker 1.6 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

5.4.1 Ensure password creation requirements are configured - dcreditCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - lcreditCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - lcreditCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - minlenCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - ocreditCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - ocreditCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - password-auth retry=3CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - system-auth retry=3CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - system-auth retry=3CIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - system-auth try_first_passCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1 Ensure password creation requirements are configured - ucreditCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

15 - NAS File System Auditing - CIFS auditing is enabledNetApp Security Hardening Guide for ONTAP 9 v1.7.0Netapp_API

AUDIT AND ACCOUNTABILITY

FireEye - A scheduled system backup job is configuredTNS FireEyeFireEye

CONTINGENCY PLANNING

GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.MobileIron - DISA Google Android 12 COBO v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.MobileIron - DISA Google Android 12 COPE v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.AirWatch - DISA Google Android 12 COPE v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.AirWatch - DISA Google Android 12 COBO v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-12-007400 - Google Android 12 must be configured to disable developer modes.AirWatch - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-007400 - Google Android 12 must be configured to disable developer modes.AirWatch - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-007400 - Google Android 12 must be configured to disable developer modes.MobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-007400 - Google Android 12 must be configured to disable developer modes.MobileIron - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

IISW-SI-000201 - The IIS 8.5 website session state must be enabled.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000203 - A private IIS 8.5 website must only accept Secure Socket Layer connections.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000204 - A public IIS 8.5 website must only accept Secure Socket Layer connections when authentication is required.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 8.5 website must be enabled.DISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000210 - The IIS 8.5 website must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.DISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000219 - Each IIS 8.5 website must be assigned a default host header.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000220 - A private websites authentication mechanism must use client certificates to transmit session identifier to assure integrity.DISA IIS 8.5 Site v2r9Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 website, patches, loaded modules, and directory paths.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SI-000234 - Debugging and trace information used to diagnose the IIS 8.5 website must be disabled.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND INFORMATION INTEGRITY

IISW-SI-000235 - The Idle Time-out monitor for each IIS 8.5 website must be enabled.DISA IIS 8.5 Site v2r9Windows

ACCESS CONTROL

IISW-SI-000239 - The IIS 8.5 websites must utilize ports, protocols, and services according to PPSM guidelines.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000241 - The IIS 8.5 private website have a server certificate issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs).DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000257 - The application pools pinging monitor for each IIS 8.5 website must be enabled.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000262 - Interactive scripts on the IIS 8.5 web server must have restrictive access controls.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

IISW-SI-000263 - Backup interactive scripts on the IIS 8.5 server must be removed.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

JUNI-ND-000970 - The Juniper router must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.DISA STIG Juniper Router NDM v3r2Juniper

AUDIT AND ACCOUNTABILITY

SLES-15-010200 - SUSE operating systems with Unified Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

ACCESS CONTROL