Item Search

NameAudit NamePluginCategory
1.27 VCLU-80-000141CIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.27 VCST-80-000142CIS VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.28 VCLU-80-000142CIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.29 VCLU-80-000143CIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.34 VCEM-80-000155CIS VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.34 VCLU-80-000155CIS VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.415 OL09-00-005015CIS Oracle Linux 9 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

2.2 Ensure the Log Config Module Is EnabledCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

AUDIT AND ACCOUNTABILITY

2.2 Ensure the Log Config Module Is EnabledCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

2.2.5 Ensure DHCP Server is not enabled - 'isc-dhcp-server'CIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

2.4 Ensure 'forms authentication' is set to use cookiesCIS IIS 8.0 v1.5.1 Level 2Windows

CONFIGURATION MANAGEMENT

2.4 Ensure 'forms authentication' is set to use cookies - DefaultCIS IIS 10 v1.2.1 Level 2Windows

SYSTEM AND SERVICES ACQUISITION

2.4 Ensure 'Signed-out search activity' is set to DisabledAirWatch - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

2.4 Ensure 'Signed-out search activity' is set to DisabledMobileIron - CIS Google Android 7 v1.0.0 L1MDM

CONFIGURATION MANAGEMENT

2.4 Ensure an industry standard authentication mechanism is used - authorizationCIS MongoDB 3.4 L2 Windows Audit v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

2.4 Ensure an industry standard authentication mechanism is used - authorizationCIS MongoDB L2 Unix Audit v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

2.4 Ensure an industry standard authentication mechanism is used - clusterAuthModeCIS MongoDB L2 Windows Audit v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

2.4 Ensure an industry standard authentication mechanism is used - clusterAuthModeCIS MongoDB 3.2 L2 Windows Audit v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

2.4 Ensure an industry standard authentication mechanism is used - modeCIS MongoDB 3.4 L2 Windows Audit v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

2.4 Ensure an industry standard authentication mechanism is used - modeCIS MongoDB 3.2 L2 Unix Audit v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure an industry standard authentication mechanism is used - modeCIS MongoDB 3.4 L2 Unix Audit v1.0.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure an industry standard authentication mechanism is used - modeCIS MongoDB L2 Windows Audit v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

2.4 Ensure DHCP services are disabled for untrusted interfaces - dhcpdCIS Cisco Firewall ASA 9 L1 v4.1.0Cisco

CONFIGURATION MANAGEMENT

2.4 Ensure Docker is allowed to make changes to iptablesCIS Docker v1.8.0 L1 OS LinuxUnix

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure Passwords are not stored in the service fileCIS PostgreSQL 17 v1.1.0 L1 Database UnixUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Set 'Do not automatically sign replies' to 'Enabled'CIS MS Office Outlook 2010 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.15 Verify that Docker socket file ownership is set to root:dockerCIS Docker 1.11.0 v1.0.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.4 Defend against Denial of Service AttacksCIS ISC BIND 9.0/9.5 v2.0.0Unix
5.3.2.4.1 Ensure pam_unix does not include nullokCIS SUSE Linux Enterprise 15 v2.0.1 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.4.1 Ensure pam_unix does not include nullokCIS SUSE Linux Enterprise 16 v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.4.1 Ensure pam_unix does not include nullokCIS SUSE Linux Enterprise 15 v2.0.1 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.3.2.4.1 Ensure pam_unix does not include nullokCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.5 NFS - 'wafl.wcc_minutes_valid has been configured'TNS NetApp Data ONTAP 7GNetApp

IDENTIFICATION AND AUTHENTICATION

18.10.93.4.2 (L1) Ensure 'Select when Preview Builds and Feature Updates are received' is set to 'Enabled: 180 or more days'CIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

CNTR-R2-001270 - Rancher RKE2 must prohibit the installation of patches, updates, and instantiation of container images without explicit privileged status.DISA Rancher Government Solutions RKE2 STIG v2r7Unix

CONFIGURATION MANAGEMENT

O19C-00-018600 - Oracle Database software must be evaluated and patched against newly found vulnerabilities.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

SYSTEM AND INFORMATION INTEGRITY

O19C-00-018600 - Oracle Database software must be evaluated and patched against newly found vulnerabilities.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

SYSTEM AND INFORMATION INTEGRITY

O112-BP-022200 - The Oracle password file ownership and permissions should be limited and the REMOTE_LOGIN_PASSWORDFILE parameter must be set to EXCLUSIVE or NONE.DISA STIG Oracle 11.2g v2r5 LinuxUnix

CONFIGURATION MANAGEMENT

O112-BP-022200 - The Oracle password file ownership and permissions should be limited and the REMOTE_LOGIN_PASSWORDFILE parameter must be set to EXCLUSIVE or NONE.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

SQL4-00-031900 - When supporting applications that require security labeling of data, SQL Server must associate organization-defined types of security labels having organization-defined security label values with information in storage.DISA STIG SQL Server 2014 Database Audit v1r7MS_SQLDB

ACCESS CONTROL

SQL4-00-032000 - When supporting applications that require security labeling of data, SQL Server must associate organization-defined types of security labels having organization-defined security label values with information in process.DISA STIG SQL Server 2014 Database Audit v1r7MS_SQLDB

ACCESS CONTROL

SQL4-00-032100 - When supporting applications that require security labeling of data, SQL Server must associate organization-defined types of security labels having organization-defined security label values with information in transmission.DISA STIG SQL Server 2014 Database Audit v1r7MS_SQLDB

ACCESS CONTROL

VCEM-80-000154 - The vCenter ESX Agent Manager service manager webapp must be removed.DISA VMware vSphere 8.0 vCenter Appliance ESX Agent Manager EAM STIG v2r2Unix

CONFIGURATION MANAGEMENT

VCLU-80-000154 - The vCenter Lookup service manager webapp must be removed.DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r2Unix

CONFIGURATION MANAGEMENT

VCST-80-000141 - The vCenter STS service example applications must be removed.DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v2r2Unix

CONFIGURATION MANAGEMENT

VCST-80-000141 The vCenter STS service example applications must be removed.DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) STIG v2r1Unix

CONFIGURATION MANAGEMENT

VCST-80-000142 - The vCenter STS service default ROOT web application must be removed.DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v2r2Unix

CONFIGURATION MANAGEMENT

VCST-80-000143 - The vCenter STS service default documentation must be removed.DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service STS STIG v2r2Unix

CONFIGURATION MANAGEMENT

VCST-80-000143 The vCenter STS service default documentation must be removed.DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) STIG v2r1Unix

CONFIGURATION MANAGEMENT

VCST-80-000154 The vCenter STS service manager webapp must be removed.DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) STIG v2r1Unix

CONFIGURATION MANAGEMENT