Item Search

NameAudit NamePluginCategory
1.12 CISC-ND-000330CIS Cisco IOS XE Switch NDM STIG v1.1.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.24 CISC-ND-001030CIS Cisco NX OS Switch NDM STIG v1.1.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.32 CISC-ND-001150CIS Cisco IOS Switch NDM STIG v1.1.0 CAT IICisco

IDENTIFICATION AND AUTHENTICATION

1.34 CISC-ND-001260CIS Cisco NX OS Switch NDM STIG v1.1.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.35 CISC-ND-001250CIS Cisco IOS XE Switch NDM STIG v1.1.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

2.2.2 Set 'buffer size' for 'logging buffered'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

AUDIT AND ACCOUNTABILITY

2.3 (L1) Host must enable Secure Boot enforcementCIS VMware ESXi 8.0 v1.3.0 L1 VMwareVMware

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.3.2.7 Ensure net.ipv6.conf.all.accept_ra is configuredCIS Oracle Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.7 Ensure net.ipv6.conf.all.accept_ra is configuredCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.7 Ensure net.ipv6.conf.all.accept_ra is configuredCIS Rocky Linux 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.7 Ensure net.ipv6.conf.all.accept_ra is configuredCIS Rocky Linux 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.8 Ensure net.ipv6.conf.default.accept_ra is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.8 Ensure net.ipv6.conf.default.accept_ra is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.8 Ensure net.ipv6.conf.default.accept_ra is configuredCIS Red Hat Enterprise Linux 10 v1.0.1 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.9 Ensure 'audit_log_file' Has Appropriate PermissionsCIS Oracle MySQL Enterprise Edition 8.0 v1.5.0 L1 MySQL RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.9 Ensure 'server_audit_file_path' Has Appropriate PermissionsCIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

3.9 Ensure 'server_audit_file_path' Has Appropriate PermissionsCIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS on Linux UnixUnix

ACCESS CONTROL, MEDIA PROTECTION

CISC-ND-000550 - The Cisco switch must be configured to enforce a minimum 15-character password length.DISA Cisco IOS XE Switch NDM STIG v3r6Cisco

IDENTIFICATION AND AUTHENTICATION

JUNI-ND-000110 - The Juniper router must be configured to automatically audit account disabling actions.DISA STIG Juniper Router NDM v3r2Juniper

ACCESS CONTROL

JUNI-ND-000150 - The Juniper router must be configured to enforce the limit of three consecutive invalid logon attempts after which time lock out the user account from accessing the device for 15 minutes.DISA STIG Juniper Router NDM v3r2Juniper

ACCESS CONTROL

JUNI-ND-000210 - The Juniper router must be configured to protect against an individual falsely denying having performed organization-defined actions to be covered by non-repudiation.DISA STIG Juniper Router NDM v3r2Juniper

AUDIT AND ACCOUNTABILITY

JUNI-ND-000390 - The Juniper router must be configured to protect audit information from unauthorized deletion.DISA STIG Juniper Router NDM v3r2Juniper

AUDIT AND ACCOUNTABILITY

JUNI-ND-000470 - The Juniper router must be configured to prohibit the use of all unnecessary and nonsecure functions and services.DISA STIG Juniper Router NDM v3r2Juniper

CONFIGURATION MANAGEMENT

JUNI-ND-000490 - The Juniper router must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.DISA STIG Juniper Router NDM v3r2Juniper

ACCESS CONTROL

JUNI-ND-000710 - The Juniper router must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA STIG Juniper Router NDM v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-ND-000990 - The Juniper router must be configured to generate an alert for all audit failure events.DISA STIG Juniper Router NDM v3r2Juniper

AUDIT AND ACCOUNTABILITY

JUNI-ND-001060 - The Juniper router must be configured to prohibit installation of software without explicit privileged status.DISA STIG Juniper Router NDM v3r2Juniper

CONFIGURATION MANAGEMENT

JUNI-ND-001210 - The Juniper router must be configured to protect against known types of Denial of Service (DoS) attacks by employing organization-defined security safeguards - DoS attacks by employing organization-defined security safeguardsDISA STIG Juniper Router NDM v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-ND-001280 - The Juniper router must be configured to generate log records when concurrent logons from different workstations occur.DISA STIG Juniper Router NDM v3r2Juniper

AUDIT AND ACCOUNTABILITY

JUNI-RT-000020 - The Juniper router must be configured to implement message authentication for all control plane protocols - IS-IS keyDISA STIG Juniper Router RTR v3r2Juniper

ACCESS CONTROL, CONFIGURATION MANAGEMENT

JUNI-RT-000040 - The Juniper router must be configured to use encryption for routing protocol authentication - BGPDISA STIG Juniper Router RTR v3r2Juniper

IDENTIFICATION AND AUTHENTICATION

JUNI-RT-000040 - The Juniper router must be configured to use encryption for routing protocol authentication - IS-ISDISA STIG Juniper Router RTR v3r2Juniper

IDENTIFICATION AND AUTHENTICATION

JUNI-RT-000220 - The Juniper router must be configured to produce audit records containing information to establish the source of the events.DISA STIG Juniper Router RTR v3r2Juniper

AUDIT AND ACCOUNTABILITY

JUNI-RT-000280 - The Juniper perimeter router must be configured to protect an enclave connected to an approved gateway by using an inbound filter that only permits packets with destination addresses within the site's address space.DISA STIG Juniper Router RTR v3r2Juniper

ACCESS CONTROL

JUNI-RT-000340 - The Juniper perimeter router must be configured to filter egress traffic at the internal interface on an inbound direction.DISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000360 - The Juniper perimeter router must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces - LLDP disabled on all external interfaces.DISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000382 - The Juniper perimeter router must be configured drop IPv6 packets with a Routing Header type 0, 1, or 3255.DISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000385 - The Juniper perimeter router must be configured to drop IPv6 packets containing an extension header with the Endpoint Identification option - dstopsDISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000390 - The Juniper out-of-band management (OOBM) gateway router must be configured to transport management traffic to the Network Operations Center (NOC) via dedicated circuit, MPLS/VPN service, or IPsec tunnel - IPsecDISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000390 - The Juniper out-of-band management (OOBM) gateway router must be configured to transport management traffic to the Network Operations Center (NOC) via dedicated circuit, MPLS/VPN service, or IPsec tunnel - MgmtDISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000410 - The Juniper out-of-band management (OOBM) gateway router must be configured to have separate IGP instances for the managed network and management network.DISA STIG Juniper Router RTR v3r2Juniper

ACCESS CONTROL

JUNI-RT-000440 - The Juniper router must be configured to only permit management traffic that ingresses and egresses the OOBM interface - InboundDISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000450 - The Juniper router providing connectivity to the NOC must be configured to forward all in-band management traffic via an IPsec tunnel - IPsecDISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000460 - The Juniper BGP router must be configured to enable the Generalized TTL Security Mechanism (GTSM) - InterfacesDISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUNI-RT-000535 - The Juniper BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer - bgp importDISA STIG Juniper Router RTR v3r2Juniper

ACCESS CONTROL

JUNI-RT-000540 - The Juniper BGP router must be configured to use the maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.DISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

TCAT-AS-000470 - Stack tracing must be disabled.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

CONFIGURATION MANAGEMENT

VCSA-70-000274 - The vCenter Server must not configure all port groups to virtual local area network (VLAN) values reserved by upstream physical switches.DISA STIG VMware vSphere 7.0 vCenter v1r3VMware

CONFIGURATION MANAGEMENT

VCTR-67-000020 - The vCenter Server must not configure all port groups to VLAN values reserved by upstream physical switches.DISA STIG VMware vSphere 6.7 vCenter v1r4VMware

CONFIGURATION MANAGEMENT

VCWN-06-000020 - All port groups must not be configured to VLAN values reserved by upstream physical switches.DISA VMware vSphere vCenter Server Version 6 STIG v1r4VMware

CONFIGURATION MANAGEMENT