Item Search

NameAudit NamePluginCategory
2.3.7.10 Ensure 'Interactive logon: Smart card removal behavior' is set to 'Lock Workstation' or 'Force Logoff' (STIG DC & MS only)CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG MSWindows

ACCESS CONTROL

5.003 - Booting into alternate operating systems is permitted.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

18.10.57.2 Ensure 'Turn on Basic feed authentication over HTTP' is set to 'Not configured' or 'Disabled' (STIG only)CIS Microsoft Windows Server 2022 STIG v2.0.0 STIG DCWindows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.2 Ensure 'Turn on Basic feed authentication over HTTP' is set to 'Not configured' or 'Disabled' (STIG only)CIS Microsoft Windows Server 2016 STIG v3.0.0 STIG DCWindows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

18.10.57.2 Ensure 'Turn on Basic feed authentication over HTTP' is set to 'Not configured' or 'Disabled' (STIG only)CIS Microsoft Windows Server 2019 STIG v3.0.0 STIG MSWindows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-70-000009 - The ESXi host SSH daemon must be configured with the DOD logon banner.DISA STIG VMware vSphere 7.0 ESXi OS v1r4Unix

ACCESS CONTROL

GOOG-12-006000 - Google Android 12 must be configured to enforce a minimum password length of six characters.AirWatch - DISA Google Android 12 COBO v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-12-006000 - Google Android 12 must be configured to enforce a minimum password length of six characters.MobileIron - DISA Google Android 12 COPE v1r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-14-006000 - Google Android 14 must be configured to enforce a minimum password length of six characters.AirWatch - DISA Google Android 14 COBO v2r2MDM

IDENTIFICATION AND AUTHENTICATION

GOOG-15-006000 - Google Android 15 must be configured to enforce a minimum password length of six characters.MobileIron - DISA Google Android 15 COPE v1r2MDM

IDENTIFICATION AND AUTHENTICATION

OL6-00-000291 - The xorg-x11-server-common (X Windows) package must not be installed, unless required.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000299 - The system must require passwords to contain no more than three consecutive repeating characters - system-authDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000303 - The operating system must employ automated mechanisms, per organization defined frequency, to detect the addition of unauthorized components/devices into the operating system.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000304 - The operating system must employ automated mechanisms to detect the presence of unauthorized software on organizational information systems and notify designated organizational officials in accordance with the organization defined frequency.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000321 - The system must provide VPN connectivity for communications over untrusted networks.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000334 - Accounts must be locked upon 35 days of inactivity.DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000336 - The sticky bit must be set on all public directories.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000339 - The FTP daemon must be configured for logging or verbose mode - 'log_ftp_protocol'DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000339 - The FTP daemon must be configured for logging or verbose mode - 'xferlog_std_format'DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000346 - The system default umask for daemons must be 027 or 022.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000385 - Audit log directories must have mode 0755 or less permissive.DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000504 - The operating system must conduct backups of user-level information contained in the operating system per organization defined frequency to conduct backups consistent with recovery time and recovery point objectives.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000511 - The audit system must take appropriate action when there are disk errors on the audit storage volume.DISA STIG Oracle Linux 6 v2r7Unix

AUDIT AND ACCOUNTABILITY

OL6-00-000526 - Automated file system mounting tools must not be enabled unless needed - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000540 - The Oracle Linux operating system must specify the default 'include' directory for the /etc/sudoers file - includedirDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

PHTN-30-000004 - The Photon operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

ACCESS CONTROL

PHTN-30-000007 - The Photon operating system must have sshd authentication logging enabled.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

ACCESS CONTROL

PHTN-30-000010 - The Photon operating system must configure auditd to log to disk.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

AUDIT AND ACCOUNTABILITY

PHTN-30-000012 - The Photon operating system must be configured to audit the execution of privileged functions.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

AUDIT AND ACCOUNTABILITY

PHTN-30-000028 - The Photon operating system must be configured so that passwords for new users are restricted to a 90-day maximum lifetime.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

IDENTIFICATION AND AUTHENTICATION

PHTN-30-000056 - The Photon operating system must configure auditd to keep logging in the event max log file size is reached.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

AUDIT AND ACCOUNTABILITY

PHTN-30-000064 - The Photon operating system must configure sshd to use FIPS 140-2 ciphers.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

PHTN-30-000066 - The Photon operating system must remove all software components after updated versions have been installed.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

SYSTEM AND INFORMATION INTEGRITY

PHTN-30-000073 - The Photon operating system must enforce a delay of at least four seconds between logon prompts following a failed logon attempt.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000082 - The Photon operating system must configure sshd to disallow Kerberos authentication.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000095 - The Photon operating system must be configured so the '/etc/cron.allow' file is protected from unauthorized modification.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000103 - The Photon operating system must log IPv4 packets with impossible addresses.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000111 - The Photon operating system must protect all boot configuration files from unauthorized modification.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000117 - The Photon operating system must store only encrypted representations of passwords.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

IDENTIFICATION AND AUTHENTICATION

PHTN-30-000119 - The Photon operating system must configure sshd to restrict AllowTcpForwarding.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000120 - The Photon operating system must configure sshd to restrict LoginGraceTime.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

VCEM-67-000005 - ESX Agent Manager must record user access in a format that enables monitoring of remote access.DISA STIG VMware vSphere 6.7 EAM Tomcat v1r4Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

VCEM-67-000010 - ESX Agent Manager must not be configured with unsupported realms.DISA STIG VMware vSphere 6.7 EAM Tomcat v1r4Unix

CONFIGURATION MANAGEMENT

VCEM-67-000013 - ESX Agent Manager must have mappings set for Java servlet pages.DISA STIG VMware vSphere 6.7 EAM Tomcat v1r4Unix

CONFIGURATION MANAGEMENT

VCEM-67-000027 - Rsyslog must be configured to monitor and ship ESX Agent Manager log files - firstbootDISA STIG VMware vSphere 6.7 EAM Tomcat v1r4Unix

AUDIT AND ACCOUNTABILITY

VCEM-67-000027 - Rsyslog must be configured to monitor and ship ESX Agent Manager log files - stdoutDISA STIG VMware vSphere 6.7 EAM Tomcat v1r4Unix

AUDIT AND ACCOUNTABILITY

VMCH-70-000001 - Copy operations must be disabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000003 - Paste operations must be disabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000012 - Unauthorized USB devices must be disconnected on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000016 - Unauthorized removal, connection, and modification of devices must be prevented on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT