Item Search

NameAudit NamePluginCategory
1.6 O19C-00-001000CIS Oracle Database 19c STIG v1.1.0 CAT I OracleDBOracleDB

ACCESS CONTROL

1.153 WN22-DC-000070CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IWindows

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

AIOS-12-010500 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.AirWatch - DISA Apple iOS 12 v2r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-12-010500 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.MobileIron - DISA Apple iOS 12 v2r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-13-010500 - Apple iOS/iPadOS must require a valid password be successfully entered before the mobile device data is unencrypted.AirWatch - DISA Apple iOS/iPadOS 13 v2r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000270 - The Apache web server must provide install options to exclude the installation of documentation, sample code, example applications, and tutorials.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000960 - The Apache web server software must be a vendor-supported version.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000960 - The Apache web server software must be a vendor-supported version.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

CISC-RT-000130 - The Cisco router must be configured to restrict traffic destined to itself.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000280 - The Cisco perimeter router must be configured to protect an enclave connected to an alternate gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000630 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

CISC-RT-000630 - The Cisco PE switch must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

CONTINGENCY PLANNING

CISC-RT-000670 - The Cisco PE router providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

CONTINGENCY PLANNING

CISC-RT-000680 - The Cisco PE switch providing Virtual Private LAN Services (VPLS) must be configured to have all attachment circuits defined to the virtual forwarding instance (VFI) with the globally unique VPN ID assigned for each customer VLAN.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000730 - The Cisco PE router must be configured to block any traffic that is destined to IP core infrastructure.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

DB2X-00-004510 - Applications using the database must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.DISA STIG IBM DB2 v10.5 LUW v2r1 DatabaseIBM_DB2DB

IDENTIFICATION AND AUTHENTICATION

DKER-EE-005170 - Docker Enterprise docker.service file ownership must be set to root:root.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005210 - Docker Enterprise /etc/docker directory ownership must be set to root:root - UbuntuDISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005310 - Docker Enterprise socket file ownership must be set to root:docker.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

EP11-00-013200 - The EDB Postgres Advanced Server must be configured on a platform that has a NIST certified FIPS 140-2 or 140-3 installation of OpenSSL.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

IDENTIFICATION AND AUTHENTICATION

EX13-CA-000150 - Exchange OWA must use https - InternalDISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000680 - Exchange internal Receive connectors must require encryption.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000690 - Exchange internal Send connectors must require encryption - DomainSecureEnabledDISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000690 - Exchange internal Send connectors must require encryption - TlsDomainDISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-DM-300040 - The F5 BIG-IP appliance must be configured to use at least two authentication servers to authenticate administrative users.DISA F5 BIG-IP TMOS NDM STIG v1r2F5

CONFIGURATION MANAGEMENT

GOOG-09-010900 - Google Android Pie devices must have a NIAP validated Google Android Pie operating system installed.MobileIron - DISA Google Android 9.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-10-010800 - Google Android 10 devices must have the latest available Google Android 10 operating system installed.AirWatch - DISA Google Android 10.x v2r1MDM

CONFIGURATION MANAGEMENT

JBOS-AS-000035 - The JBoss server must be configured with Role Based Access Controls.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

JBOS-AS-000050 - Silent Authentication must be removed from the Default Management Security Realm.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

JBOS-AS-000230 - JBoss process owner execution permissions must be limited.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000680 - Production JBoss servers must be supported by the vendor.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

JBOS-AS-000685 - The JRE installed on the JBoss server must be kept up to date.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

JUNI-RT-000710 - The Juniper PE router must be configured to block any traffic that is destined to IP core infrastructure.DISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-VN-000025 - The Juniper SRX Services Gateway VPN must configure Internet Key Exchange (IKE) with SHA1 or greater to protect the authenticity of communications sessions.DISA Juniper SRX Services Gateway VPN v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

MSFT-11-002000 - Microsoft Android 11 must be configured to enable encryption for data at rest on removable storage media or alternately, the use of removable storage media must be disabled.MobileIron - DISA Microsoft Android 11 COBO v1r2MDM

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

PPS9-00-004900 - The EDB Postgres Advanced Server must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for cryptographic operations.EDB PostgreSQL Advanced Server OS Linux Audit v2r3Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010650 - The SUSE operating system root account must be the only account having unrestricted access to the system.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SQL4-00-030600 - Where availability is paramount, the SQL Server must continue processing (preferably overwriting existing records, oldest first), in the event of lack of space for more Audit/Trace log records; and must keep processing after any failure of an Audit/Trace.DISA STIG SQL Server 2014 Instance DB Audit v2r4MS_SQLDB

AUDIT AND ACCOUNTABILITY

SQL4-00-039020 - When using command-line tools such as SQLCMD in a mixed-mode authentication environment, users must use a logon method that does not expose the password.DISA STIG SQL Server 2014 Instance DB Audit v2r4MS_SQLDB

IDENTIFICATION AND AUTHENTICATION

SQL6-D0-016200 - The SQL Server default account [sa] must be disabled.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

ACCESS CONTROL

SQL6-D0-018100 - When using command-line tools such as SQLCMD in a mixed-mode authentication environment, users must use a logon method that does not expose the password.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

WBSP-AS-000211 - The WebSphere Application Server Java 2 security must be enabled.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WN10-00-000040 - Windows 10 systems must be maintained at a supported servicing level.DISA Microsoft Windows 10 STIG v3r6Windows

SYSTEM AND SERVICES ACQUISITION

WN10-SO-000205 - The LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN16-00-000150 - Local volumes must use a format that supports NTFS attributes.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL

WN16-DC-000150 - Directory data (outside the root DSE) of a non-public directory must be configured to prevent anonymous access.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN16-SO-000380 - The LAN Manager authentication level must be set to send NTLMv2 response only and to refuse LM and NTLM.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN19-SO-000250 - Windows Server 2019 must restrict anonymous access to Named Pipes and Shares.DISA Microsoft Windows Server 2019 STIG v3r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN19-SO-000310 - Windows Server 2019 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN22-DC-000070 - Windows Server 2022 permissions on the Active Directory data files must only allow System and Administrators access.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY