Item Search

NameAudit NamePluginCategory
ARDC-CN-000055 - Adobe Reader DC must disable the Adobe Send and Track plugin for Outlook.DISA STIG Adobe Acrobat Reader DC Continuous Track v2r1Windows

CONFIGURATION MANAGEMENT

ARDC-CN-000080 - Adobe Reader DC must disable Acrobat Upsell.DISA STIG Adobe Acrobat Reader DC Continuous Track v2r1Windows

CONFIGURATION MANAGEMENT

ARDC-CN-000085 - Adobe Reader DC must disable Adobe Send for Signature.DISA STIG Adobe Acrobat Reader DC Continuous Track v2r1Windows

CONFIGURATION MANAGEMENT

CISC-RT-000060 - The Cisco switch must be configured to have all inactive layer 3 interfaces disabled.DISA Cisco NX OS Switch RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000590 - The Cisco MPLS router must be configured to use its loopback address as the source address for LDP peering sessions.DISA Cisco IOS Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

CISC-RT-000600 - The Cisco MPLS switch must be configured to synchronize Interior Gateway Protocol (IGP) and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange.DISA Cisco NX OS Switch RTR STIG v3r3Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000920 - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to filter received source-active multicast advertisements for any undesirable multicast groups and sources.DISA Cisco NX OS Switch RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000930 - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to filter source-active multicast advertisements to external MSDP peers to avoid global visibility of local-only multicast sources and groups.DISA Cisco IOS Router RTR STIG v3r3Cisco

ACCESS CONTROL

GEN000000-LNX00720 - Auditing must be enabled at boot by setting a kernel parameter.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN002260 - The system must be checked for extraneous device files at least weekly.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN002750 - The audit system must be configured to audit account creation - flags +ua and -uaDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN002750 - The audit system must be configured to audit account creation - naflags uaDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - 'group'DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - 'groupmod'DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - 'shadow'DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - 'usermod'DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL

GEN002751 - The audit system must be configured to audit account modification - naflags uaDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN002753 - The audit system must be configured to audit account termination - naflags uaDISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN002870 - The system must be configured to send audit records to a remote audit server - NFSDISA STIG Solaris 10 X86 v2r4Unix

AUDIT AND ACCOUNTABILITY

IIST-SV-000205 - The IIS 10.0 web server must enable HTTP Strict Transport Security (HSTS).DISA IIS 10.0 Server v3r3Windows

CONFIGURATION MANAGEMENT

JBOS-AS-000245 - Welcome Web Application must be disabled - Welcome Web Application must be disabled.DISA JBoss EAP 6.3 STIG v2r6Unix

CONFIGURATION MANAGEMENT

JUNI-RT-000550 - The Juniper BGP router must be configured to limit the prefix size on any inbound route advertisement to /24 or the least significant prefixes issued to the customer - prefix-length-rangeDISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000690 - The Juniper PE router must be configured to implement Protocol Independent Multicast (PIM) snooping for each Virtual Private LAN Services (VPLS) bridge domain.DISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000940 - The Juniper Multicast Source Discovery Protocol (MSDP) router must be configured to use its loopback address as the source address when originating MSDP traffic.DISA STIG Juniper Router RTR v3r2Juniper

CONTINGENCY PLANNING

OH12-1X-000118 - OHS must have the LoadModule mpm_winnt_module directive disabled - cgi_moduleDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000126 - OHS must have the LoadModule speling_module directive disabled.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000142 - OHS must have the LoadModule uniqueid_module directive disabled.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000164 - OHS must have the LoadModule cgi_module directive disabled within the IfModule mpm_winnt_module directive - cgi_moduleDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000204 - OHS must have the RewriteOptions directive set properly.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000215 - All utility programs, not necessary for operations, must be removed or disabled.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000233 - OHS hosted web sites must utilize ports, protocols, and services according to PPSM guidelines.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000351 - OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths - ErrorDocument 400DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND INFORMATION INTEGRITY

OH12-1X-000351 - OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths - ErrorDocument 403DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND INFORMATION INTEGRITY

OH12-1X-000351 - OHS must have defined error pages for common error codes that minimize the identity of the web server, patches, loaded modules, and directory paths - ErrorDocument 411DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND INFORMATION INTEGRITY

OL07-00-021600 - The Oracle Linux operating system must be configured so that the file integrity tool is configured to verify Access Control Lists (ACLs) - ACLsDISA Oracle Linux 7 STIG v3r2Unix

CONFIGURATION MANAGEMENT

SQL6-D0-000500 - SQL Server must protect against a user falsely repudiating by use of system-versioned tables (Temporal Tables).DISA STIG SQL Server 2016 Database Audit v3r2MS_SQLDB

AUDIT AND ACCOUNTABILITY

TCAT-AS-000260 - HTTP status code must be logged.DISA STIG Apache Tomcat Application Server 9 v3r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

TCAT-AS-000580 - Documentation must be removed.DISA STIG Apache Tomcat Application Server 9 v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

TCAT-AS-001640 - Application servers must use NIST-approved or NSA-approved key management technology and processes.DISA STIG Apache Tomcat Application Server 9 v3r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-001730 - Connector address attribute must be set.DISA STIG Apache Tomcat Application Server 9 v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

WBLC-02-000069 - Oracle WebLogic must generate audit records for the DoD-selected list of auditable events.Oracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-02-000073 - Oracle WebLogic must produce process events and severity levels to establish what type of HTTPD-related events and severity levels occurred.Oracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-02-000074 - Oracle WebLogic must produce audit records containing sufficient information to establish what type of JVM-related events and severity levels occurred.Oracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-02-000076 - Oracle WebLogic must produce audit records containing sufficient information to establish when (date and time) the events occurred.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000079 - Oracle WebLogic must produce audit records that contain sufficient information to establish the outcome (success or failure) of application server and application events.Oracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000079 - Oracle WebLogic must produce audit records that contain sufficient information to establish the outcome (success or failure) of application server and application events.Oracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBLC-02-000083 - Oracle WebLogic must provide a real-time alert when organization-defined audit failure events occur - Module-HealthStateOracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-02-000086 - Oracle WebLogic must notify administrative personnel as a group in the event of audit processing failure - Module-HealthStateOracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBLC-02-000086 - Oracle WebLogic must notify administrative personnel as a group in the event of audit processing failure - SMTP NotificationOracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-08-000210 - Oracle WebLogic must terminate the network connection associated with a communications session at the end of the session or after a DoD-defined time period of inactivity.Oracle WebLogic Server 12c Linux v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION