Item Search

NameAudit NamePluginCategory
1.6.12 Ensure the OpenSSL library is configured to use only ciphers employing FIPS 140-2-approved algorithmsCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

1.9 DTOO193CIS Microsoft Office System 2016 STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.12 DTOO201CIS Microsoft Office System 2016 STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.62 WN16-AU-000060CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IIWindows

AUDIT AND ACCOUNTABILITY

5.1.21 Ensure sshd PermitRootLogin is disabledCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.1.24 Ensure sshd private key files have a passcodeCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.1.30 Ensure sshd is configured to use only FIPS-validated key exchange algorithmsCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

5.2.9 Ensure sudo timestamp_timeout is configuredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.2.4 Ensure password same consecutive characters is configuredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.2.4 Ensure password same consecutive characters is configuredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.2.10 Ensure lcredit is configured in /etc/security/pwquality.confCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.3.4 Ensure remember is configured on the pam_pwhistory module in /etc/pam.d/password-authCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

6.2.2.3 Ensure all remote access methods are monitoredCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL

7.1.22 Ensure the /bin /sbin /usr/bin /usr/sbin /usr/local/bin and /usr/local/sbin directories are mode 0755 or more restrictiveCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

7.1.26 Ensure the system-wide shared library files are owned by rootCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

DTOO110 - Word - Blocking as default file block opening behavior must be enforced.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO111 - Enabling IE Bind to Object functionality must be present.DISA STIG Microsoft Project 2016 v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO111 - Publisher - Enabling IE Bind to Object functionality must be present.DISA STIG Office 2010 Publisher v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO111 - Word - Enabling IE Bind to Object functionality must be present.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO124 - Publisher - Scripted Window Security must be enforced.DISA STIG Office 2010 Publisher v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO124 - Scripted Window Security must be enforced.DISA STIG Microsoft Project 2016 v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO126 - Add-on Management functionality must be allowed.DISA STIG Microsoft Project 2016 v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO126 - Project - Add-on Management functionality must be allowed.DISA STIG Office 2010 Project v1r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO127 - Publisher - Application add-ins must be signed by Trusted Publisher.DISA STIG Office 2010 Publisher v1r12Windows

CONFIGURATION MANAGEMENT

DTOO127 - Word - Application add-ins must be signed by Trusted Publisher.DISA STIG Office 2010 Word v1r12Windows

CONFIGURATION MANAGEMENT

DTOO129 - Links that invoke instances of Internet Explorer from within an Office product must be blockedDISA STIG Microsoft Publisher 2016 v1r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO131 - Trust Bar Notifications for unsigned application add-ins must be blockedDISA STIG Microsoft Publisher 2016 v1r3Windows

CONFIGURATION MANAGEMENT

DTOO132 - File Downloads must be configured for proper restrictionsDISA STIG Microsoft Publisher 2016 v1r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO132 - Project - File Downloads must be configured for proper restrictions.DISA STIG Office 2010 Project v1r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO134 - Word - Disallowance of Trusted Locations on the network must be enforced.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO142 - Word - Force encrypted macros to be scanned in open XML documents must be determined and configured.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO211 - Publisher - ActiveX Installs must be configured for proper restriction.DISA STIG Office 2010 Publisher v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO328 - Word - Online translation dictionaries must be in use.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO334 - Word - Word 2000 binary documents and templates must be configured to edit in protected view.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO337 - Word - Word 95 binary documents and templates must be configured to edit in protected view.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO346 - Untrusted intranet zone access to Project servers must not be allowed.DISA STIG Microsoft Project 2016 v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

GEN000240 - The system clock must be synchronized to an authoritative DoD time source - 'NTP daemon is started at boot'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000241 - The system clock must be synchronized continuously, or at least daily - 'NTP daemon is started at boot'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000700 - User passwords must be changed at least every 60 days.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000790 - The system must prevent the use of dictionary words for passwords.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000930 - The root account's home directory must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001120 - The system must not permit root logins using remote access programs, such as ssh.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001210 - All system command files must not have extended ACLs - '/usr/ucb/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001310 - All library files must not have extended ACLs - '/lib/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001310 - All library files must not have extended ACLs - '/usr/lib/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001590 - All run control scripts must have no extended ACLs - '/etc/init.d'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001730 - All global initialization files must not have extended ACLs - '/etc/profile'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001730 - All global initialization files must not have extended ACLs - '/etc/security/.profile'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001810 - Skeleton files must not have extended ACLs - '/etc/security/.profile'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001840 - All global initialization files' executable search paths must contain only absolute paths - '/etc/csh.login'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT