Item Search

NameAudit NamePluginCategory
1.24 CISC-ND-000620CIS Cisco IOS Switch NDM STIG v1.1.0 CAT ICisco

IDENTIFICATION AND AUTHENTICATION

1.25 WN19-00-000250CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.25 WN19-00-000250CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.42 CISC-ND-001470CIS Cisco IOS XE Switch NDM STIG v1.1.0 CAT ICisco

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

1.64 SOL-11.1-020530CIS Solaris 11 SPARC STIG v1.0.0 CAT IUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.64 SOL-11.1-020530CIS Solaris 11 X86 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.160 AZLX-23-002450CIS Amazon Linux 2023 STIG v1.0.0 CAT IUnix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

1.298 RHEL-09-431010CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IUnix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.25 Ensure the rsh-server package is not installedCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

2.1.31 Ensure a TFTP server has not been installed on the systemCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

AIOS-17-011200 - iPhone and iPad must have the latest available iOS/iPadOS operating system installed.AirWatch - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT

AIOS-17-011200 - iPhone and iPad must have the latest available iOS/iPadOS operating system installed.MobileIron - DISA Apple iOS/iPadOS 17 v2r2MDM

CONFIGURATION MANAGEMENT

APPL-26-002066 - The macOS system must disable unattended or automatic login to the system.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

ARBA-ND-000267 - AOS must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.DISA HPE Aruba Networking AOS NDM STIG v1r1ArubaOS

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000270 - The Apache web server must provide install options to exclude the installation of documentation, sample code, example applications, and tutorials.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AZLX-23-002450 - Amazon Linux 2023 must use a Linux Security Module configured to enforce limits on system services.DISA Amazon Linux 2023 STIG v1r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

CISC-ND-000720 - The Cisco router must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000720 - The Cisco router must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001470 - The Cisco router must be running an IOS release that is currently supported by Cisco Systems.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000640 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance with the appropriate Route Target (RT).DISA Cisco IOS XE Router RTR STIG v3r5Cisco

CONTINGENCY PLANNING

CISC-RT-000670 - The Cisco PE switch providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

DTAM001 - McAfee VirusScan On-Access General Policies must be configured to enable on-access scanning at system startup.DISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

DTAM138 - McAfee VirusScan Access Protection Policies must be configured to prevent McAfee services from being stopped.DISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

DTAM138 - McAfee VirusScan Access Protection Rules must be configured to prevent McAfee services from being stopped.DISA McAfee VirusScan 8.8 Local Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

F5BI-AP-300045 - The F5 BIG-IP appliance must be configured to prohibit or restrict the use of unnecessary or prohibited functions, ports, protocols, and/or services, including those defined in the PPSM CAL and vulnerability assessments.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

CONFIGURATION MANAGEMENT

F5BI-DM-300057 - The F5 BIG-IP appliance must set the idle time before automatic logout to five minutes of inactivity except to fulfill documented and validated mission requirements.DISA F5 BIG-IP TMOS NDM STIG v1r2F5

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

GEN000000-LNX00580 - The x86 CTRL-ALT-DELETE key sequence must be disabled.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN000000-SOL00440 - The root account must be the only account with GID of 0.DISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN003820 - The rsh daemon must not be running.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN003820 - The rsh daemon must not be running.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN003820 - The rsh daemon must not be running.DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL

GEN004400 - Files executed through a mail aliases file must be owned by root and must reside within a directory owned and writable only by root.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN004400 - Files executed through a mail aliases file must be owned by root and must reside within a directory owned and writable only by root.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN005100 - The TFTP daemon must have mode 0755 or less permissive.DISA STIG Solaris 10 SPARC v2r4Unix

ACCESS CONTROL

GEN005100 - The TFTP daemon must have mode 0755 or less permissive.DISA STIG Solaris 10 X86 v2r4Unix

ACCESS CONTROL

GEN005500 - The SSH daemon must be configured to only use the SSHv2 protocol.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

JUEX-NM-000670 - The Juniper EX switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).DISA Juniper EX Series Network Device Management v2r4Juniper

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

MD4X-00-001300 - MongoDB must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for cryptographic operations.DISA STIG MongoDB Enterprise Advanced 4.x v1r4 OSUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

MD7X-00-004400 - MongoDB must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for cryptographic operations.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 UnixUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

MD7X-00-004400 MongoDB must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for cryptographic operations.DISA MongoDB Enterprise Advanced 7.x STIG v1r1Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

OS10-NDM-000370 - The Dell OS10 Switch must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

IDENTIFICATION AND AUTHENTICATION

RHEL-09-431010 - RHEL 9 must use a Linux Security Module configured to enforce limits on system services.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

SLEM-05-255050 - SLEM 5 SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2/140-3 approved cryptographic hash algorithms.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

MAINTENANCE

SQL6-D0-000300 - SQL Server must enforce approved authorizations for logical access to database information and system resources in accordance with applicable access control policies.DISA MS SQL Server 2016 Database STIG v3r5MS_SQLDB

ACCESS CONTROL

VCPG-70-000013 - VMware Postgres must use FIPS 140-2 approved Transport Layer Security (TLS) ciphers.DISA STIG VMware vSphere 7.0 PostgreSQL v1r2Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

WN16-00-000110 - Systems must be maintained at a supported servicing level.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN25-00-000030 - Windows Server 2025 administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

WNFWA-000004 - Windows Defender Firewall with Advanced Security must block unsolicited inbound connections when connected to a domain.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

CONFIGURATION MANAGEMENT

WNFWA-000012 - Windows Defender Firewall with Advanced Security must block unsolicited inbound connections when connected to a private network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

CONFIGURATION MANAGEMENT

WNFWA-000020 - Windows Defender Firewall with Advanced Security must block unsolicited inbound connections when connected to a public network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

CONFIGURATION MANAGEMENT