Item Search

NameAudit NamePluginCategory
AIX7-00-001010 - The AIX SYSTEM attribute must not be set to NONE for any account.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001102 - AIX must employ strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.DISA IBM AIX 7.x STIG v3r3Unix

MAINTENANCE

CISC-ND-000470 - The Cisco router must be configured to prohibit the use of all unnecessary and nonsecure functions and services.DISA Cisco IOS Router NDM STIG v3r8Cisco

CONFIGURATION MANAGEMENT

ESXI5-VM-000099 - The version of ESXi running on the server must be a supported version.DISA VMware ESXi Version 5 Virtual Machine STIG v2r1VMware

CONFIGURATION MANAGEMENT

GEN003850 - The telnet daemon must not be running.DISA STIG Solaris 10 SPARC v2r4Unix

IDENTIFICATION AND AUTHENTICATION

IIST-SI-000221 - Anonymous IIS 10.0 website access accounts must be restricted.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000156 - All accounts installed with the IIS 10.0 web server software and tools must have passwords assigned and default passwords changed.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

OL6-00-000211 - The telnet daemon must not be running - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000211 - The telnet daemon must not be running - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000338 - The TFTP daemon must operate in secure mode which provides access only to a single directory on the host file system.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL07-00-010440 - The Oracle Linux operating system must not allow an unattended or automatic logon to the system via a graphical user interface.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-010450 - The Oracle Linux operating system must not allow an unrestricted logon to the system.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020010 - The Oracle Linux operating system must not have the ypserv package installed.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020310 - The Oracle Linux operating system must be configured so that the root account must be the only account having unrestricted access to the system.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL08-00-010187 - OL 8 must implement DOD-approved encryption in the bind package.DISA Oracle Linux 8 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-010290 - The OL 8 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Oracle Linux 8 STIG v2r9Unix

ACCESS CONTROL, MAINTENANCE

PANW-NM-000069 - The Palo Alto Networks security platform must terminate management sessions after 10 minutes of inactivity except to fulfill documented and validated mission requirements.DISA Palo Alto Networks NDM STIG v3r4Palo_Alto

SYSTEM AND COMMUNICATIONS PROTECTION

PGS9-00-000900 - PostgreSQL must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

ACCESS CONTROL

RHEL-06-000021 - The Red Hat Enterprise Linux operating system must not contain .shosts or shosts.equiv files.DISA Red Hat Enterprise Linux 6 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-06-000341 - The snmpd service must not use a default password.DISA Red Hat Enterprise Linux 6 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-07-010491 - Red Hat Enterprise Linux operating systems version 7.2 or newer using Unified Extensible Firmware Interface (UEFI) must require authentication upon booting into single-user and maintenance modes.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

ACCESS CONTROL

RHEL-07-020250 - The Red Hat Enterprise Linux operating system must be a vendor supported release.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

RHEL-07-040690 - The Red Hat Enterprise Linux operating system must not have a File Transfer Protocol (FTP) server package installed unless needed.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

RHEL-10-300050 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE

RHEL-10-300060 - RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE

RHEL-10-300080 - RHEL 10 must implement DOD-approved encryption in the bind package.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010330 - All SUSE operating system persistent disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at-rest protection.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-020130 - The FTP daemon must not be installed unless required.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020140 - The TFTP service daemon must not be installed unless required.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080010 - The operating system must be a supported release.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080160 - SNMP default community strings and passphrases must be changed from vendor defaults.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SP13-00-000095 - SharePoint must employ NSA-approved cryptography to protect classified information.DISA Microsoft SharePoint 2013 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SPLK-CL-000050 - Splunk Enterprise must use TLS 1.2 and SHA-2 or higher cryptographic algorithms.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

IDENTIFICATION AND AUTHENTICATION

UBTU-16-010330 - Unattended or automatic login via the Graphical User Interface must not be allowed - autologin-user-timeoutDISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-16-010360 - There must be no shosts.equiv files on the Ubuntu operating system.DISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-16-010631 - The x86 Ctrl-Alt-Delete key sequence in the Ubuntu operating system must be disabled if a Graphical User Interface is installed.DISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-18-010000 - Ubuntu operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.DISA STIG Ubuntu 18.04 LTS v2r15Unix

ACCESS CONTROL

VCFL-67-000005 - vSphere Client must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-05-000150 - Oracle WebLogic must uniquely identify and authenticate users (or processes acting on behalf of users).Oracle WebLogic Server 12c Linux v2r2Unix

IDENTIFICATION AND AUTHENTICATION

WN12-00-000008 - Administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-GE-000001 - Systems must be maintained at a supported OS or service pack level.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-GE-000027 - File Transfer Protocol (FTP) servers must be configured to prevent access to the system drive.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000004 - Local accounts with blank passwords must be restricted to prevent access from the network.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000050 - Anonymous SID/Name translation must not be allowed.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000051 - Anonymous enumeration of SAM accounts must not be allowed.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000052 - Anonymous enumeration of shares must be restricted.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000058 - Anonymous access to Named Pipes and Shares must be restricted.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000059 - Network shares that can be accessed anonymously must not be allowed.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000067 - The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000067 - The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT