Item Search

NameAudit NamePluginCategory
1.2.4 Ensure software packages have been digitally signed by a Certificate Authority (CA)CIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

1.5 UBTU-24-100040CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.14 UBTU-22-215030CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IUnix

CONFIGURATION MANAGEMENT

1.191 WN22-MS-000010CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IWindows

ACCESS CONTROL

4.1.2.10 Ensure the auditing processing failures are handled.CIS Amazon Linux 2 STIG v2.0.1 STIGUnix

AUDIT AND ACCOUNTABILITY

CNTR-K8-001160 - Secrets in Kubernetes must not be stored as environment variables.DISA Kubernetes STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

DTAG008 - The antivirus signature file age must not exceed 7 days.DISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

DTAM171 - (U) McAfee VirusScan must have the current security patches installed.DISA McAfee VirusScan 8.8 Local Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

ESXI-06-000011 - The SSH daemon must be configured to use only the SSHv2 protocol.DISA VMware vSphere ESXi 6.0 STIG v1r5 UnixUnix

ACCESS CONTROL

ESXI-06-000047 - The Image Profile and VIB Acceptance Levels must be verified.DISA VMware vSphere ESXi 6.0 STIG v1r5 UnixUnix

CONFIGURATION MANAGEMENT

ESXI-06-000060 - The virtual switch MAC Address Change policy must be set to reject.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-100047 - The VMM must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs and guest VMs by verifying Image Profile and VIP Acceptance Levels.DISA VMware vSphere ESXi 6.0 STIG v1r5 UnixUnix

CONFIGURATION MANAGEMENT

ESXI-06-200047 - The VMM must implement cryptographic mechanisms to prevent unauthorized modification of all information at rest on all VMM components by verifying Image Profile and VIP Acceptance Levels.DISA VMware vSphere ESXi 6.0 STIG v1r5 UnixUnix

CONFIGURATION MANAGEMENT

GEN000100 - The operating system must be a supported release.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN000560 - The system must not have accounts configured with blank or null passwords.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN001640 - Run control scripts must not execute world-writable programs or scripts.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN001640 - Run control scripts must not execute world-writable programs or scripts.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - '.shosts'DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - 'hosts.equiv'DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN002220 - All shell files must have mode 0755 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003840 - The rexec daemon must not be running.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003840 - The rexec daemon must not be running.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004620 - The sendmail server must have the debug feature disabled.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN004620 - The Sendmail server must have the debug feature disabled.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004640 - The SMTP service must not have a uudecode alias active.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN004640 - The SMTP service must not have a uudecode alias active.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005000 - Anonymous FTP accounts must not have a functional shell.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005000 - Anonymous FTP accounts must not have a functional shell.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005080 - The TFTP daemon must operate in secure mode which provides access only to a single directory on the host file system.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005080 - The TFTP daemon must operate in secure mode which provides access only to a single directory on the host file system.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005140 - Any active TFTP daemon must be authorized and approved in the system accreditation package.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default - /etc/sma/snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default - /etc/sma/snmp/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default - /etc/snmp/conf/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default - /etc/snmp/conf/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default - /usr/sfw/lib/sma_snmp/snmpd.confDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN005300 - SNMP communities, users, and passphrases must be changed from the default - /var/sma_snmp/snmpd.confDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN006380 - The system must not use UDP for NIS/NIS+.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008600 - The system must be configured to only boot from the system boot device.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN008640 - The system must not use removable media as the boot loader.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN008660 - For systems capable of using GRUB, the system must be configured with GRUB as the default boot loader unless another boot loader has been authorized, justified, and documented using site-defined procedures.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN008700 - The system boot loader must require authentication - '/boot/grub/grub.conf'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

MADB-10-003700 - If MariaDB authentication, using passwords, is employed, then MariaDB must enforce the DOD standards for password complexity.DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDBMySQLDB

IDENTIFICATION AND AUTHENTICATION

MADB-10-003800 - If passwords are used for authentication, MariaDB must store only hashed, salted representations of passwords.DISA MariaDB Enterprise 10.x STIG v2r5 UnixUnix

IDENTIFICATION AND AUTHENTICATION

MYS8-00-005000 - If Database Management System (DBMS) authentication using passwords is employed, the DBMS must enforce the DOD standards for password complexity and lifetime - DBMS authentication using passwords is employed, the DBMS must enforce the DoD standards for password complexity and lifetime.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

IDENTIFICATION AND AUTHENTICATION

PHTN-40-000039 - The operating system must store only encrypted representations of passwords.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

IDENTIFICATION AND AUTHENTICATION

WN11-AC-000045 - Reversible password encryption must be disabled.DISA Microsoft Windows 11 STIG v2r8Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000195 - The system must be configured to prevent the storage of the LAN Manager hash of passwords.DISA Microsoft Windows 11 STIG v2r8Windows

IDENTIFICATION AND AUTHENTICATION

WN22-AC-000090 - Windows Server 2022 reversible password encryption must be disabled.DISA Microsoft Windows Server 2022 STIG v2r8Windows

IDENTIFICATION AND AUTHENTICATION

WN22-SO-000300 - Windows Server 2022 must be configured to prevent the storage of the LAN Manager hash of passwords.DISA Microsoft Windows Server 2022 STIG v2r8Windows

IDENTIFICATION AND AUTHENTICATION