Item Search

NameAudit NamePluginCategory
1.167 UBTU-24-900590CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.171 UBTU-22-654200CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

3.2.6 Ensure bluetooth kernel module is not availableCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

5.1.29 Ensure the SSH server is configured to use only ciphers employing FIPS 140-2-approved algorithmsCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

5.1.30 Ensure sshd is configured to use only FIPS-validated key exchange algorithmsCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

5.3.3.2.8 Ensure the operating system enforces a minimum 15-character password lengthCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

6.1.4 Ensure AIDE is configured to use cryptographic mechanisms to protect the integrity of audit toolsCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

7.1.17 Ensure system-wide shared library directories must be owned by rootCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

7.1.24 Ensure the /bin /sbin /usr/bin /usr/sbin /usr/local/bin and /usr/local/sbin directories are group-owned by rootCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

GEN000580 - The system must require passwords to contain a minimum of 14 characters.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000590 - The system must use a FIPS 140-2 approved cryptographic hashing algorithm for generating account password hashes.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000750 - The system must require at least four characters be changed between the old and new passwords during a password change.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000800 - The system must prohibit the reuse of passwords within five iterations.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001160 - All files and directories must have a valid owner.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001190 - All network services daemon files must not have extended ACLs - /usr/bin/*DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001190 - All network services daemon files must not have extended ACLs - /usr/sbin/*DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001210 - All system command files must not have extended ACLs - '/usr/sbin/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001361 - NIS/NIS+/yp command files must not have extended ACLs - '/var/yp'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001365 - The /etc/resolv.conf file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001369 - The /etc/hosts file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001390 - The /etc/passwd file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001590 - All run control scripts must have no extended ACLs - '/etc/rc*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001610 - Run control scripts' lists of preloaded libraries must contain only absolute paths.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001730 - All global initialization files must not have extended ACLs - '/etc/csh.login'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/bashrc'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/csh.cshrc'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/security/environ'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001845 - Global initialization files' library search paths must contain only absolute paths - '/etc/environment'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001845 - Global initialization files' library search paths must contain only absolute paths - '/etc/security/.login'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001850 - Global initialization files' lists of preloaded libraries must contain only absolute paths - '/etc/environment'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001850 - Global initialization files' lists of preloaded libraries must contain only absolute paths - '/etc/security/environ'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001890 - Local initialization files must not have extended ACLs - '.bash_logout'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001890 - Local initialization files must not have extended ACLs - '.bash_profile'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001890 - Local initialization files must not have extended ACLs - '.bashrc'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001890 - Local initialization files must not have extended ACLs - '.cshrc'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001890 - Local initialization files must not have extended ACLs - '.env'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001890 - Local initialization files must not have extended ACLs - '.exrc'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001890 - Local initialization files must not have extended ACLs - '.profile'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001900 - All local initialization files' executable search paths must contain only absolute paths.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002380 - The owner, group, mode, ACL, and location of files with the setuid bit set must be documented using site-defined proceduresDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN002760 - System must be configured to audit all admin/privileged/security actions - 'User audit class assignments should be reviewed'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN003060 - Default system accounts must be included in the cron.allow file - 'snapp'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'sshd'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'sys'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.deny file - 'adm'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.deny file - 'invscout'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.deny file - 'pconsole'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003090 - Crontab files must not have extended ACLs.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003110 - Cron and crontab directories must not have extended ACLs - '/var/spool/cron' - acls disabledDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

WG410 IIS6 - Interactive scripts must have proper access controls. - 'AspScriptTimeout set to 90 or less'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION