Item Search

NameAudit NamePluginCategory
1.1.5.1 Ensure calendar and contacts integration is set to disabledCIS Zoom L1 v1.0.0Zoom

CONFIGURATION MANAGEMENT

3.2.1.20 Ensure 'Allow setting up new nearby devices' is set to 'Disabled'AirWatch - CIS Apple iOS 11 v1.0.0 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.2.1.24 Ensure 'Allow setting up new nearby devices' is set to 'Disabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

SECURITY ASSESSMENT AND AUTHORIZATION

3.2.1.25 Ensure 'Allow setting up new nearby devices' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

SECURITY ASSESSMENT AND AUTHORIZATION

3.2.1.28 Ensure 'Allow setting up new nearby devices' is set to 'Disabled'AirWatch - CIS Apple iOS 18 v1.0.0 L1 Institution OwnedMDM

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1.28 Ensure 'Allow setting up new nearby devices' is set to 'Disabled'AirWatch - CIS Apple iPadOS 17 Institutionally Owned L1MDM

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.2.1 Ensure syslog-ng service is enabledCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

5.17 Create specialized keychains for different purposesCIS Apple OSX 10.10 Yosemite L2 v1.2.0Unix
5.17 Create specialized keychains for different purposesCIS Apple OSX 10.11 El Capitan L2 v1.1.0Unix
5.126 - Web Publishing and online ordering wizards prevented from downloading list of providers.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

6.5 Use parental controls for systems that are not centrally managedCIS Apple OSX 10.10 Yosemite L2 v1.2.0Unix
AIOS-12-011400 - Apple iOS device must have the latest available iOS operating system installed.AirWatch - DISA Apple iOS 12 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-14-009600 - iPhone and iPad must have the latest available iOS/iPadOS operating system installed.MobileIron - DISA Apple iOS/iPadOS 14 v1r3MDM

CONFIGURATION MANAGEMENT

AIOS-15-007300 - Apple iOS/iPadOS 15 allow list must be configured to not include applications with the following characteristics: voice dialing application if available when MD is locked.MobileIron - DISA Apple iOS/iPadOS 14 v1r4MDM

CONFIGURATION MANAGEMENT

AIOS-16-007300 - Apple iOS/iPadOS 16 allow list must be configured to not include applications with the following characteristics: allow voice dialing when MD is locked.MobileIron - DISA Apple iOS/iPadOS 16 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-17-007400 - Apple iOS/iPadOS 17 allow list must be configured to not include applications with the following characteristics: - backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);- transmits MD diagnostic data to non-DOD servers;- allows synchronization of data or applications between devices associated with user; and- allows unencrypted (or encrypted but not FIPS 140-2/FIPS 140-3 validated) data sharing with other MDs or printers - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Apple iOS/iPadOS 17 v2r1MDM

CONFIGURATION MANAGEMENT

AIOS-18-007400 - Apple iOS/iPadOS 18 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);- Transmits MD diagnostic data to non-DOD servers;- Allows synchronization of data or applications between devices associated with user; and- Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers.- Apps which backup their own data to a remote system - allows unencrypted (or encrypted but not FIPS 140-2 validated) data sharing with other MDs or printers.AirWatch - DISA Apple iOS/iPadOS 18 v1r1MDM

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002087 - All files and directories contained in users home directories on AIX must be group-owned by a group in which the home directory owner is a member.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

Big Sur - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Big Sur v1.4.0 - 800-53r4 HighUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

Big Sur - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Big Sur v1.4.0 - CNSSI 1253Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Catalina v1.5.0 - 800-53r4 ModerateUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Catalina v1.5.0 - 800-53r4 HighUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Secure Name Address Resolution ServiceNIST macOS Catalina v1.5.0 - 800-53r5 HighUnix

SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Secure Name Address Resolution ServiceNIST macOS Catalina v1.5.0 - 800-53r5 ModerateUnix

SYSTEM AND COMMUNICATIONS PROTECTION

GEN001550 - All files and directories contained in user home directories must be group-owned by a group of which the home directory's owner is a member.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN001550 - All files and directories contained in user home directories must be group-owned by a group of which the home directorys owner is a member.DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

GEN001550 - All files and directories in user's home directories must be group-owned by a group the home directory's owner is a member.DISA STIG AIX 6.1 v1r14Unix

ACCESS CONTROL

GEN001700 - System start-up files must only execute programs owned by a privileged UID or an application.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN001700 - System start-up files must only execute programs owned by a privileged UID or an application.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN003020 - Cron must not execute programs in, or subordinate to, world-writable directories.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003380 - The 'at' daemon must not execute programs in, or subordinate to, world-writable directories.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN003380 - The 'at' daemon must not execute programs in, or subordinate to, world-writable directories.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN003611 - The system must log martian packets.DISA STIG AIX 5.3 v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN004430 - Files executed through a mail aliases file must not have extended ACLs.DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

GOOG-10-010800 - Google Android 10 devices must have the latest available Google Android 10 operating system installed.MobileIron - DISA Google Android 10.x v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-13-010800 - Android 13 devices must have the latest available Google Android 13 operating system installed.AirWatch - DISA Google Android 13 COPE v2r2MDM

CONFIGURATION MANAGEMENT

GOOG-14-710800 - Android 14 devices must have the latest available Google Android 14 operating system installed.MobileIron - DISA Google Android 14 BYOAD v1r1MDM

CONFIGURATION MANAGEMENT

HONW-09-010900 - Honeywell Mobility Edge Android Pie devices must have a NIAP validated Honeywell Mobility Edge Android Pie devices operating system installed.MobileIron - DISA Honeywell Android 9.x COPE v1r2MDM

CONFIGURATION MANAGEMENT

MADB-10-007800 - MariaDB must prohibit user installation of logic modules (stored procedures, functions, triggers, views, etc.) without explicit privileged status.DISA MariaDB Enterprise 10.x v2r3 DBMySQLDB

CONFIGURATION MANAGEMENT

Monterey - Issue or Obtain Public Key Certificates from an Approved Service ProviderNIST macOS Monterey v1.0.0 - 800-53r5 ModerateUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

MOTO-09-010800 - Motorola Android Pie devices must have the latest available Motorola Android Pie operating system installed.MobileIron - DISA Motorola Android Pie.x COPE v1r2MDM

CONFIGURATION MANAGEMENT

MOTS-11-010800 - Motorola Solutions Android 11 devices must have the latest available Motorola Solutions Android 11 operating system installed.AirWatch - DISA Motorola Solutions Android 11 COBO v1r3MDM

CONFIGURATION MANAGEMENT

SOL-11.1-020380 - System start-up files must only execute programs owned by a privileged UID or an application.DISA STIG Solaris 11 SPARC v3r1Unix

CONFIGURATION MANAGEMENT

SQL2-00-010500 - SQL Server auditing configuration maximum number of files must be configured to reduce the likelihood of storage capacity being exceeded, while meeting organization-defined auditing requirements - 'max_files'DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

AUDIT AND ACCOUNTABILITY

SQL2-00-039100 - The SQL Server Browser service must be disabled if its use is not necessary.DISA STIG SQL Server 2012 Database OS Audit v1r20Windows

CONFIGURATION MANAGEMENT

SRG-OS-000157-ESXI5 - The SSH client must be configured to not use CBC-based ciphers.DISA STIG VMWare ESXi Server 5 STIG v2r1VMware

CONFIGURATION MANAGEMENT

WN10-CC-000310 - Users must be prevented from changing installation options.DISA Microsoft Windows 10 STIG v3r4Windows

CONFIGURATION MANAGEMENT

WN12-00-000005 - Users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-CC-000115 - Users must be prevented from changing installation options.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN16-00-000010 - Users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT