Item Search

NameAudit NamePluginCategory
SLES-12-010000 - The SUSE operating system must be a vendor-supported release.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-12-010010 - Vendor-packaged SUSE operating system security patches and updates must be installed and up to date.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-12-010040 - The SUSE operating system must display a banner before granting local or remote access to the system via a graphical user logon.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010080 - The SUSE operating system must initiate a session lock after a 15-minute period of inactivity for the graphical user interface.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010130 - The SUSE operating system must lock an account after three consecutive invalid access attempts.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010160 - The SUSE operating system must enforce passwords that contain at least one lower-case character.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010170 - The SUSE operating system must enforce passwords that contain at least one numeric character.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010190 - The SUSE operating system must require the change of at least eight (8) of the total number of characters when passwords are changed.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010260 - The SUSE operating system must be configured to create or update passwords with a minimum lifetime of 24 hours (one day).DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010270 - The SUSE operating system must employ user passwords with a minimum lifetime of 24 hours (one day).DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010290 - The SUSE operating system must employ user passwords with a maximum lifetime of 60 days.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010320 - The SUSE operating system must prevent the use of dictionary words for passwords.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010330 - The SUSE operating system must never automatically remove or disable emergency administrator accounts.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010430 - SUSE operating systems with a basic input/output system (BIOS) must require authentication upon booting into single-user and maintenance modes.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010460 - The sticky bit must be set on all SUSE operating system world-writable directories.DISA SLES 12 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-010540 - The SUSE operating system file integrity tool must be configured to protect the integrity of the audit tools.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-010570 - The SUSE operating system must remove all outdated software components after updated versions have been installed.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-12-010580 - The SUSE operating system must disable the USB mass storage kernel module.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010590 - The SUSE operating system must disable the file system automounter.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SLES-12-010610 - The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010631 - The SUSE operating system must not have unnecessary account capabilities.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010640 - The SUSE operating system must not have duplicate User IDs (UIDs) for interactive users.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010670 - If Network Security Services (NSS) is being used by the SUSE operating system it must prohibit the use of cached authentications after one day.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010710 - All SUSE operating system local interactive users must have a home directory assigned in the /etc/passwd file.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010873 - The SUSE operating system library files must be owned by root.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-020110 - Audispd must take appropriate action when the SUSE operating system audit storage is full.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-020220 - The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

SLES-12-020260 - The SUSE operating system must generate audit records for all uses of the sudo command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020300 - The SUSE operating system must generate audit records for all uses of the umount command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020490 - The SUSE operating system must generate audit records for all uses of the creat, open, openat, open_by_handle_at, truncate, and ftruncate syscalls.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020610 - The SUSE operating system must generate audit records for all uses of the setfacl command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020680 - The SUSE operating system must generate audit records for all uses of the unix_chkpwd command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-020720 - The SUSE operating system must generate audit records for all uses of the pam_timestamp_check command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-12-030050 - The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access via SSH.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-030130 - The SUSE operating system must display the date and time of the last successful account logon upon an SSH logon.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-030180 - The SUSE operating system SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL, MAINTENANCE

SLES-12-030200 - The SUSE operating system SSH daemon must be configured to not allow authentication using known hosts authentication.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030220 - The SUSE operating system SSH daemon private host key files must have mode 0640 or less permissive.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030250 - The SUSE operating system SSH daemon must not allow compression or must only allow compression after successful authentication.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030300 - The SUSE operating system clock must, for networked systems, be synchronized to an authoritative DoD time source at least every 24 hours.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-030310 - The SUSE operating system must be configured to use Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

SLES-12-030320 - The SUSE operating system must implement kptr-restrict to prevent the leaking of internal kernel addresses.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

SLES-12-030350 - The SUSE operating system must be configured to use TCP syncookies.DISA SLES 12 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-030360 - The SUSE operating system must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030364 - The SUSE operating system must not be performing Internet Protocol version 6 (IPv6) packet forwarding unless the system is a router.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030390 - The SUSE operating system must prevent Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030401 - The SUSE operating system must not allow interfaces to accept Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages by default.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030410 - The SUSE operating system must not allow interfaces to send Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages by default.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030520 - The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-030611 - The SUSE operating system must use a virus scan program.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY