Item Search

NameAudit NamePluginCategory
AOSX-13-000995 - The macOS system must be configured with the sudoers file configured to authenticate users on a per -tty basis.DISA STIG Apple Mac OSX 10.13 v2r5Unix

CONFIGURATION MANAGEMENT

AOSX-13-001465 - The macOS system must use a DoD antivirus program.DISA STIG Apple Mac OSX 10.13 v2r5Unix

CONFIGURATION MANAGEMENT

AOSX-15-000016 - The macOS system must be integrated into a directory services infrastructure.DISA STIG Apple Mac OSX 10.15 v1r10Unix

CONFIGURATION MANAGEMENT

AOSX-15-002070 - The macOS system must use an approved antivirus program.DISA STIG Apple Mac OSX 10.15 v1r10Unix

CONFIGURATION MANAGEMENT

ARDC-CL-000340 - Unsupported version of Adobe Acrobat Reader DC Classic must be uninstalled.DISA STIG Adobe Acrobat Reader DC Classic Track v2r1Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-U1-000960 - The Apache web server software must be a vendor-supported version.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002000 - Docker Enterprise hosts network namespace must not be shared.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002070 - The Docker Enterprise default seccomp profile must not be disabled.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002110 - All Docker Enterprise containers must be restricted from acquiring additional privileges.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002120 - The Docker Enterprise hosts user namespace must not be shared.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005190 - Docker Enterprise docker.socket file ownership must be set to root:root.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005330 - Docker Enterprise daemon.json file ownership must be set to root:root.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

EP11-00-002400 - The EDB Postgres Advanced Server must be configurable to overwrite audit log records, oldest first (First-In-First-Out - FIFO), in the event of unavailability of space for more audit log records.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

AUDIT AND ACCOUNTABILITY

EX13-CA-000150 - Exchange OWA must use https - ExternalDISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-EG-000340 - Exchange internal Receive connectors must require encryption.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000660 - Exchange must provide redundancy.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-DM-000027 - The BIG-IP appliance must be configured to enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level in accordance with applicable policy for the device.DISA F5 BIG-IP Device Management STIG v2r4F5

ACCESS CONTROL

F5BI-LT-000007 - The BIG-IP Core implementation must be configured to restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.DISA F5 BIG-IP Local Traffic Manager STIG v2r4F5

ACCESS CONTROL

GEN001100 - Root passwords must never be passed over a network in clear text form - 'ssh is running'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IISW-SV-000156 - All accounts installed with the IIS 8.5 web server software and tools must have passwords assigned and default passwords changed.DISA IIS 8.5 Server v2r7Windows

CONFIGURATION MANAGEMENT

JBOS-AS-000025 - Java permissions must be set for hosted applications.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

JRE8-WN-000180 - The version of Oracle JRE 8 running on the system must be the most current available.DISA STIG Oracle JRE 8 Windows v2r1Windows

SYSTEM AND INFORMATION INTEGRITY

JUNI-RT-000610 - The Juniper PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA STIG Juniper Router RTR v3r2Juniper

CONTINGENCY PLANNING

JUSX-DM-000167 - For nonlocal maintenance sessions, the Juniper SRX Services Gateway must explicitly deny the use of J-Web.DISA Juniper SRX Services Gateway NDM v3r3Juniper

CONFIGURATION MANAGEMENT

JUSX-IP-000010 - The Juniper Networks SRX Series Gateway IDPS must install updates for predefined signature objects, applications signatures, IDPS policy templates, and device software when new releases are available in accordance with organizational configuration management policy and procedures.DISA Juniper SRX Services Gateway IDPS v2r1Juniper

SYSTEM AND INFORMATION INTEGRITY

MD3X-00-000800 - MongoDB must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.DISA STIG MongoDB Enterprise Advanced 3.x v2r3 OSUnix

IDENTIFICATION AND AUTHENTICATION

O112-BP-021900 - The Oracle REMOTE_OS_AUTHENT parameter must be set to FALSE.DISA STIG Oracle 11.2g v2r5 DatabaseOracleDB

CONFIGURATION MANAGEMENT

O112-C1-011100 - Vendor-supported software must be evaluated and patched against newly found vulnerabilities.DISA STIG Oracle 11.2g v2r5 WindowsWindows

SYSTEM AND INFORMATION INTEGRITY

O112-N1-015601 - Applications must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.DISA STIG Oracle 11.2g v2r5 DatabaseOracleDB

IDENTIFICATION AND AUTHENTICATION

O121-C2-002700 - The DBMS must enforce approved authorizations for logical access to the system in accordance with applicable policy.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

ACCESS CONTROL

OH12-1X-000226 - OHS administration must be performed over a secure path or at the local console.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

OH12-1X-000266 - OHS accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OH12-1X-000295 - OHS must have the SSLFIPS directive enabled to implement required cryptographic protections using cryptographic modules complying with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when encrypting data that must be compartmentalized.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OH12-1X-000309 - OHS must have the SSLFIPS directive enabled to prevent unauthorized disclosure of information during transmission.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OH12-1X-000310 - OHS must have the SSLEngine, SSLProtocol, SSLWallet directives enabled and configured to prevent unauthorized disclosure of information during transmission - SSLWalletDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL6-00-000030 - The system must not allow accounts configured with blank or null passwords - system-authDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

PPS9-00-004820 - When using command-line tools such as psql, users must use a logon method that does not expose the password.EDB PostgreSQL Advanced Server DB Audit v2r3PostgreSQLDB

IDENTIFICATION AND AUTHENTICATION

PPS9-00-012900 - The EDB Postgres Advanced Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the requirements of the data owner.EDB PostgreSQL Advanced Server OS Linux Audit v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-010000 - The SUSE operating system must be a vendor-supported release.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-12-010610 - The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

WDNS-CM-000014 - The Windows 2012 DNS Server must be configured to enable DNSSEC Resource Records.DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows

CONFIGURATION MANAGEMENT

WDNS-SC-000020 - The Windows 2012 DNS Server must protect the authenticity of dynamic updates via transaction signing.DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN16-00-000120 - The Windows Server 2016 system must use an anti-virus program.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN19-00-000010 - Windows Server 2019 users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN19-00-000030 - Windows Server 2019 administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN19-CC-000470 - Windows Server 2019 Windows Remote Management (WinRM) client must not use Basic authentication.DISA Microsoft Windows Server 2019 STIG v3r8Windows

MAINTENANCE

WN19-DC-000150 - Windows Server 2019 directory data (outside the root DSE) of a non-public directory must be configured to prevent anonymous access.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN25-DC-000070 - Windows Server 2025 permissions on the Active Directory data files must only allow system administrators (SAs) access.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

WPAW-00-001300 - A Windows PAW used to manage domain controllers and directory services must not be used to manage any other type of high-value IT resource.DISA Microsoft Windows PAW STIG v3r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION