Item Search

NameAudit NamePluginCategory
1.7.3 Ensure the Standard Mandatory DoD Notice and Consent Banner are configuredCIS Amazon Linux 2 STIG v2.0.1 STIGUnix

CONFIGURATION MANAGEMENT

1.19 WN19-00-000190CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIWindows

IDENTIFICATION AND AUTHENTICATION

1.19 WN19-00-000190CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIWindows

IDENTIFICATION AND AUTHENTICATION

1.62 WN16-AU-000060CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIWindows

AUDIT AND ACCOUNTABILITY

1.168 UBTU-24-900600CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

5.1.21 Ensure sshd PermitRootLogin is disabledCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.1.21 Ensure sshd PermitRootLogin is disabledCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.2.11 Ensure dcredit is configured in /etc/security/pwquality.confCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.3.3.3.5 Ensure remember is configured on the pam_pwhistory module in /etc/pam.d/system-authCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.9 Ensure existing passwords use FIPS 140-2 approved cryptographic hashing algorithmCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.13 Ensure the maximum time period for existing passwords is restricted to 60 daysCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

6.3.2.5 Ensure the operating system allocates audit record storage capacityCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

AUDIT AND ACCOUNTABILITY

7.1.24 Ensure the /bin /sbin /usr/bin /usr/sbin /usr/local/bin and /usr/local/sbin directories are group-owned by rootCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

7.1.25 Ensure the system-wide shared library files are mode 0755 or more restrictiveCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

CONFIGURATION MANAGEMENT

DTOO104 - Word - Disabling of user name and password syntax from being used in URLs must be enforced.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO111 - Enabling IE Bind to Object functionality must be presentDISA STIG Microsoft Publisher 2016 v1r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO117 - Word - Saved from URL mark to assure Internet zone processing must be enforced.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO121 - Word - Files from the Internet zone must be opened in Protected View.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO123 - Navigation to URLs embedded in Office products must be blockedDISA STIG Microsoft Publisher 2016 v1r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO131 - Word - Trust Bar Notifications for unsigned application add-ins must be blocked.DISA STIG Office 2010 Word v1r12Windows

CONFIGURATION MANAGEMENT

DTOO209 - Word - Protection from zone elevation must be enforced.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTOO302 - Word - The automatically update links feature must be configured as off.DISA STIG Office 2010 Word v1r12Windows

SYSTEM AND COMMUNICATIONS PROTECTION

GEN000000-AIX00040 - The securetcpip command must be usedDISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000253 - The time synchronization configuration file (such as /etc/ntp.conf) must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000360 - Group Identifiers (GIDs) reserved for system accounts must not be assigned to non-system groups.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000680 - The system must require passwords to contain no more than three consecutive repeating characters.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001210 - All system command files must not have extended ACLs - '/sbin/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001270 - System log files must not have extended ACLs, except as needed to support authorized software.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001394 - The /etc/group file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001430 - The /etc/security/passwd file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001730 - All global initialization files must not have extended ACLs - '/etc/environment'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001901 - Local initialization files' library search paths must contain only absolute paths - 'LIBPATH'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002230 - All shell files must not have extended ACLs.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN002560 - The system and user default umask must be 077 - user initialization filesDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'bin'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'lp'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.allow file - 'lpd'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must be included in the cron.deny file - 'bin'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003060 - Default system accounts must GEN003580be included in the cron.deny file - 'sshd'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003110 - Cron and crontab directories must not have extended ACLs - '/var/spool/cron/crontabs/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003210 - The cron.deny file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'daemon' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'lp' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'nobody' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'sshd' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'sys' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'uucp' - at.allowDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003320 - System accounts must not be listed in at.allow or must be included in at.deny - 'uucp' - at.denyDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003580 - The system must use initial TCP sequence numbers most resistant to sequence number guessing attacks.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN003601 - TCP backlog queue sizes must be set appropriately.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION