Item Search

NameAudit NamePluginCategory
AIX7-00-001038 - AIX must not have accounts configured with blank or null passwords.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

ALMA-09-043140 - AlmaLinux OS 9 must implement DOD-approved encryption in the bind package.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-65-000071 - The ESXi host must verify the integrity of the installation media before installing ESXi.DISA STIG VMware vSphere ESXi 6.5 v2r4VMware

CONFIGURATION MANAGEMENT

GEN001100 - Root passwords must never be passed over a network in clear text form.DISA STIG for Oracle Linux 5 v2r1Unix

IDENTIFICATION AND AUTHENTICATION

GEN003850 - The telnet daemon must not be running - 'chkconfig'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

IDENTIFICATION AND AUTHENTICATION

MD3X-00-000020 - MongoDB must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.DISA STIG MongoDB Enterprise Advanced 3.x v2r3 DBMongoDB

ACCESS CONTROL

O19C-00-001000 - Oracle Database must enforce approved authorizations for logical access to the system in accordance with applicable policy.DISA Oracle Database 19c STIG v1r3 OracleDBOracleDB

ACCESS CONTROL

O112-BP-022700 - The Oracle Listener must be configured to require administration authentication.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-C1-004500 - DBA OS accounts must be granted only those host system privileges necessary for the administration of the DBMS.DISA STIG Oracle 11.2g v2r5 WindowsWindows

CONFIGURATION MANAGEMENT

O112-N1-015602 - When using command-line tools such as Oracle SQL*Plus, which can accept a plain-text password, users must use an alternative login method that does not expose the password.DISA STIG Oracle 11.2g v2r5 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

O121-C1-015000 - DBMS default accounts must be assigned custom passwords.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C2-016600 - The DBMS must implement required cryptographic protections using cryptographic modules complying with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.DISA Oracle Database 12c STIG v3r5 UnixUnix

IDENTIFICATION AND AUTHENTICATION

O121-N1-015601 - Applications must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-N1-015602 - When using command-line tools such as Oracle SQL*Plus, which can accept a plain-text password, users must use an alternative logon method that does not expose the password.DISA Oracle Database 12c STIG v3r5 WindowsWindows

CONFIGURATION MANAGEMENT

OH12-1X-000308 - OHS must have the LoadModule ossl_module directive enabled to prevent unauthorized disclosure of information during transmission.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL6-00-000206 - The telnet-server package must not be installed.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL6-00-000213 - The rsh-server package must not be installed.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL07-00-010290 - The Oracle Linux operating system must not allow accounts configured with blank or null passwords.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-010482 - Oracle Linux operating systems version 7.2 or newer with a Basic Input/Output System (BIOS) must require authentication upon booting into single-user and maintenance modes - BIOS must require authentication upon booting into single-user and maintenance modes.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL07-00-020000 - Oracle Linux 7 must not install packages from the Extra Packages for Enterprise Linux (EPEL) repository.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-032000 - The Oracle Linux operating system must use a virus scan program.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

PGS9-00-012300 - PostgreSQL must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for cryptographic operations.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-06-000206 - The telnet-server package must not be installed.DISA Red Hat Enterprise Linux 6 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-06-000218 - The rlogind service must not be running.DISA Red Hat Enterprise Linux 6 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-07-010440 - The Red Hat Enterprise Linux operating system must not allow an unattended or automatic logon to the system via a graphical user interface.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

RHEL-07-010450 - The Red Hat Enterprise Linux operating system must not allow an unrestricted logon to the system.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

RHEL-07-020000 - The Red Hat Enterprise Linux operating system must not have the rsh-server package installed.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

RHEL-07-040540 - The Red Hat Enterprise Linux operating system must not contain .shosts files.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

SOL-11.1-010410 - The operating system must configure auditing to reduce the likelihood of storage capacity being exceeded.DISA Solaris 11 X86 STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020110 - The NIS package must not be installed.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040370 - Login must not be permitted with empty/null passwords for SSH.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040410 - The system must not allow autologin capabilities from the GNOME desktop.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-070050 - There must be no user .rhosts files.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SP13-00-000085 - SharePoint must implement required cryptographic protections using cryptographic modules complying with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.DISA Microsoft SharePoint 2013 STIG v2r4Windows

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000010 - Splunk Enterprise must be installed with FIPS mode enabled, to implement NIST FIPS 140-2 approved ciphers for all cryptographic functions.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-16-010250 - The Ubuntu operating system must not be configured to allow blank or null passwords.DISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-16-010380 - Ubuntu operating systems booted with a BIOS must require authentication upon booting into single-user and maintenance modes.DISA STIG Ubuntu 16.04 LTS v2r3Unix

ACCESS CONTROL

UBTU-16-010390 - Ubuntu operating systems booted with United Extensible Firmware Interface (UEFI) implemented must require authentication upon booting into single-user mode and maintenance.DISA STIG Ubuntu 16.04 LTS v2r3Unix

ACCESS CONTROL

UBTU-16-010630 - The x86 Ctrl-Alt-Delete key sequence must be disabled.DISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-16-010670 - The root account must be the only account having unrestricted access to the system.DISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-16-030020 - The rsh-server package must not be installed.DISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-16-030250 - The Ubuntu operating system must be configured so that the SSH daemon does not allow authentication using an empty password - PermitEmptyPasswordsDISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-18-010005 - The Ubuntu operating system must implement NIST FIPS-validated cryptography to protect classified information and for the following: to provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA STIG Ubuntu 18.04 LTS v2r15Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-18-010018 - The Ubuntu operating system must not have the Network Information Service (NIS) package installed.DISA STIG Ubuntu 18.04 LTS v2r15Unix

CONFIGURATION MANAGEMENT

UBTU-18-010151 - The Ubuntu Operating system must disable the x86 Ctrl-Alt-Delete key sequence.DISA STIG Ubuntu 18.04 LTS v2r15Unix

CONFIGURATION MANAGEMENT

WBLC-05-000150 - Oracle WebLogic must uniquely identify and authenticate users (or processes acting on behalf of users).Oracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WN12-GE-000001 - Systems must be maintained at a supported OS or service pack level.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000004 - Local accounts with blank passwords must be restricted to prevent access from the network.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000057 - Unauthorized remotely accessible registry paths and sub-paths must not be configured.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN12-SO-000059 - Network shares that can be accessed anonymously must not be allowed.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION