| SLES-12-010000 - The SUSE operating system must be a vendor-supported release. | DISA SLES 12 STIG v3r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| SLES-12-010010 - Vendor-packaged SUSE operating system security patches and updates must be installed and up to date. | DISA SLES 12 STIG v3r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| SLES-12-010040 - The SUSE operating system must display a banner before granting local or remote access to the system via a graphical user logon. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010080 - The SUSE operating system must initiate a session lock after a 15-minute period of inactivity for the graphical user interface. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010130 - The SUSE operating system must lock an account after three consecutive invalid access attempts. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010160 - The SUSE operating system must enforce passwords that contain at least one lower-case character. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010170 - The SUSE operating system must enforce passwords that contain at least one numeric character. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010190 - The SUSE operating system must require the change of at least eight (8) of the total number of characters when passwords are changed. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010260 - The SUSE operating system must be configured to create or update passwords with a minimum lifetime of 24 hours (one day). | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010270 - The SUSE operating system must employ user passwords with a minimum lifetime of 24 hours (one day). | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010290 - The SUSE operating system must employ user passwords with a maximum lifetime of 60 days. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010320 - The SUSE operating system must prevent the use of dictionary words for passwords. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-010330 - The SUSE operating system must never automatically remove or disable emergency administrator accounts. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010430 - SUSE operating systems with a basic input/output system (BIOS) must require authentication upon booting into single-user and maintenance modes. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-010460 - The sticky bit must be set on all SUSE operating system world-writable directories. | DISA SLES 12 STIG v3r5 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SLES-12-010540 - The SUSE operating system file integrity tool must be configured to protect the integrity of the audit tools. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY |
| SLES-12-010570 - The SUSE operating system must remove all outdated software components after updated versions have been installed. | DISA SLES 12 STIG v3r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| SLES-12-010580 - The SUSE operating system must disable the USB mass storage kernel module. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010590 - The SUSE operating system must disable the file system automounter. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010610 - The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-010631 - The SUSE operating system must not have unnecessary account capabilities. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-010640 - The SUSE operating system must not have duplicate User IDs (UIDs) for interactive users. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010670 - If Network Security Services (NSS) is being used by the SUSE operating system it must prohibit the use of cached authentications after one day. | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-010710 - All SUSE operating system local interactive users must have a home directory assigned in the /etc/passwd file. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-010873 - The SUSE operating system library files must be owned by root. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-020110 - Audispd must take appropriate action when the SUSE operating system audit storage is full. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY |
| SLES-12-020220 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| SLES-12-020260 - The SUSE operating system must generate audit records for all uses of the sudo command. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| SLES-12-020300 - The SUSE operating system must generate audit records for all uses of the umount command. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| SLES-12-020490 - The SUSE operating system must generate audit records for all uses of the creat, open, openat, open_by_handle_at, truncate, and ftruncate syscalls. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| SLES-12-020610 - The SUSE operating system must generate audit records for all uses of the setfacl command. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| SLES-12-020680 - The SUSE operating system must generate audit records for all uses of the unix_chkpwd command. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| SLES-12-020720 - The SUSE operating system must generate audit records for all uses of the pam_timestamp_check command. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| SLES-12-030050 - The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access via SSH. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-030130 - The SUSE operating system must display the date and time of the last successful account logon upon an SSH logon. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL |
| SLES-12-030180 - The SUSE operating system SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms. | DISA SLES 12 STIG v3r5 | Unix | ACCESS CONTROL, MAINTENANCE |
| SLES-12-030200 - The SUSE operating system SSH daemon must be configured to not allow authentication using known hosts authentication. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-030220 - The SUSE operating system SSH daemon private host key files must have mode 0640 or less permissive. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-030250 - The SUSE operating system SSH daemon must not allow compression or must only allow compression after successful authentication. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-030300 - The SUSE operating system clock must, for networked systems, be synchronized to an authoritative DoD time source at least every 24 hours. | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY |
| SLES-12-030310 - The SUSE operating system must be configured to use Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT). | DISA SLES 12 STIG v3r5 | Unix | AUDIT AND ACCOUNTABILITY |
| SLES-12-030320 - The SUSE operating system must implement kptr-restrict to prevent the leaking of internal kernel addresses. | DISA SLES 12 STIG v3r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| SLES-12-030350 - The SUSE operating system must be configured to use TCP syncookies. | DISA SLES 12 STIG v3r5 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SLES-12-030360 - The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-030364 - The SUSE operating system must not be performing Internet Protocol version 6 (IPv6) packet forwarding unless the system is a router. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-030390 - The SUSE operating system must prevent Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages from being accepted. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-030401 - The SUSE operating system must not allow interfaces to accept Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages by default. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-030410 - The SUSE operating system must not allow interfaces to send Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default. | DISA SLES 12 STIG v3r5 | Unix | CONFIGURATION MANAGEMENT |
| SLES-12-030520 - The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM). | DISA SLES 12 STIG v3r5 | Unix | IDENTIFICATION AND AUTHENTICATION |
| SLES-12-030611 - The SUSE operating system must use a virus scan program. | DISA SLES 12 STIG v3r5 | Unix | SYSTEM AND INFORMATION INTEGRITY |