Item Search

NameAudit NamePluginCategory
1.82 RHEL-10-300050CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, MAINTENANCE

1.83 RHEL-10-300060CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, MAINTENANCE

AADC-CN-001075 - The Adobe Acrobat Pro DC Continuous latest security-related software updates must be installed.DISA STIG Adobe Acrobat Pro DC Continuous Track v2r1Windows

SYSTEM AND INFORMATION INTEGRITY

AOSX-13-002060 - The macOS system must be integrated into a directory services infrastructure.DISA STIG Apple Mac OSX 10.13 v2r5Unix

CONFIGURATION MANAGEMENT

AOSX-14-000016 - The macOS system must be integrated into a directory services infrastructure.DISA STIG Apple Mac OSX 10.14 v2r6Unix

CONFIGURATION MANAGEMENT

AOSX-14-002070 - The macOS system must use an approved antivirus program.DISA STIG Apple Mac OSX 10.14 v2r6Unix

CONFIGURATION MANAGEMENT

AOSX-14-004021 - The macOS system must be configured with the sudoers file configured to authenticate users on a per -tty basis.DISA STIG Apple Mac OSX 10.14 v2r6Unix

CONFIGURATION MANAGEMENT

ARDC-CN-000340 - Adobe Reader DC must have the latest Security-related Software Updates installed.DISA STIG Adobe Acrobat Reader DC Continuous Track v2r1Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-U1-000270 - The Apache web server must provide install options to exclude the installation of documentation, sample code, example applications, and tutorials - Welcome pageDISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

AS24-U1-000270 - The Apache web server must provide install options to exclude the installation of documentation, sample code, example applications, and tutorials.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

CONFIGURATION MANAGEMENT

AS24-U1-000940 - The account used to run the Apache web server must not have a valid login shell and password defined.DISA STIG Apache Server 2.4 Unix Server v3r2Unix

CONFIGURATION MANAGEMENT

AS24-U1-000960 - The Apache web server software must be a vendor-supported version.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

AS24-W1-000940 - All accounts installed with the Apache web server software and tools must have passwords assigned and default passwords changed.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

CISC-ND-000470 - The Cisco router must be configured to prohibit the use of all unnecessary and nonsecure functions and services.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT

CISC-ND-001470 - The Cisco router must be running an IOS release that is currently supported by Cisco Systems.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000290 - The Cisco perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an alternate gateway service provider.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

ACCESS CONTROL

CISC-RT-000290 - The Cisco perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an approved gateway service provider.DISA Cisco IOS Router RTR STIG v3r4Cisco

ACCESS CONTROL

CISC-RT-000640 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance with the appropriate Route Target (RT).DISA Cisco IOS Router RTR STIG v3r4Cisco

CONTINGENCY PLANNING

CISC-RT-000670 - The Cisco PE router providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate pseudowire ID for each attachment circuit.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

CISC-RT-000670 - The Cisco PE router providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.DISA Cisco IOS Router RTR STIG v3r4Cisco

CONTINGENCY PLANNING

CISC-RT-000680 - The Cisco PE router providing Virtual Private LAN Services (VPLS) must be configured to have all attachment circuits defined to the virtual forwarding instance (VFI) with the globally unique VPN ID assigned for each customer VLAN.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000680 - The Cisco PE switch providing Virtual Private LAN Services (VPLS) must be configured to have all attachment circuits defined to the virtual forwarding instance (VFI) with the globally unique VPN ID assigned for each customer VLAN.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

CONTINGENCY PLANNING

CISC-RT-000730 - The Cisco PE switch must be configured to block any traffic that is destined to the IP core infrastructure.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

DKER-EE-002150 - Docker Enterprise privileged ports must not be mapped within containers.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005210 - Docker Enterprise /etc/docker directory ownership must be set to root:root - CentOS/RHELDISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005320 - Docker Enterprise socket file permissions must be set to 660 or more restrictive.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005360 - Docker Enterprise /etc/default/docker file permissions must be set to 644 or more restrictive.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

F5BI-AF-000007 - The BIG-IP AFM module must be configured to restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.DISA F5 BIG-IP Advanced Firewall Manager STIG v2r2F5

ACCESS CONTROL

F5BI-LT-000029 - The BIG-IP Core implementation must be configured to limit the number of concurrent sessions to an organization-defined number for virtual servers.DISA F5 BIG-IP Local Traffic Manager STIG v2r4F5

ACCESS CONTROL

F5BI-LT-000215 - The BIG-IP Core implementation must be configured to protect against known and unknown types of Denial of Service (DoS) attacks by employing rate-based attack prevention behavior analysis when providing content filtering to virtual servers.DISA F5 BIG-IP Local Traffic Manager STIG v2r4F5

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-LT-000217 - The BIG-IP Core implementation must be configured to implement load balancing to limit the effects of known and unknown types of Denial of Service (DoS) attacks to virtual servers.DISA F5 BIG-IP Local Traffic Manager STIG v2r4F5

SYSTEM AND COMMUNICATIONS PROTECTION

O19C-00-001000 - Oracle Database must enforce approved authorizations for logical access to the system in accordance with applicable policy.DISA Oracle Database 19c STIG v1r5 OracleDBOracleDB

ACCESS CONTROL

SLES-12-030611 - The SUSE operating system must use a virus scan program.DISA SLES 12 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

SQL6-D0-009500 - SQL Server must protect the confidentiality and integrity of all information at rest.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-000211 - The WebSphere Application Server Java 2 security must be enabled.DISA IBM WebSphere Traditional 9 Windows STIG v2r1Windows

ACCESS CONTROL

WBSP-AS-000212 - The WebSphere Application Server Java 2 security must not be bypassed.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL

WN10-00-000045 - The Windows 10 system must use an anti-virus program.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN10-00-000050 - Local volumes must be formatted using NTFS.DISA Microsoft Windows 10 STIG v3r6Windows

ACCESS CONTROL

WN10-00-000100 - Internet Information System (IIS) or its subcomponents must not be installed on a workstation.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN10-00-000240 - Administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN10-CC-000075 - Credential Guard must be running on Windows 10 domain-joined systems.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN10-CC-000330 - The Windows Remote Management (WinRM) client must not use Basic authentication.DISA Microsoft Windows 10 STIG v3r6Windows

MAINTENANCE

WN10-SO-000140 - Anonymous SID/Name translation must not be allowed.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN16-CC-000500 - The Windows Remote Management (WinRM) client must not use Basic authentication.DISA Microsoft Windows Server 2016 STIG v2r10Windows

MAINTENANCE

WN16-CC-000530 - The Windows Remote Management (WinRM) service must not use Basic authentication.DISA Microsoft Windows Server 2016 STIG v2r10Windows

MAINTENANCE

WN16-SO-000020 - Local accounts with blank passwords must be restricted to prevent access from the network.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN16-SO-000250 - Anonymous SID/Name translation must not be allowed.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN16-SO-000300 - Anonymous access to Named Pipes and Shares must be restricted.DISA Microsoft Windows Server 2016 STIG v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN19-SO-000230 - Windows Server 2019 must not allow anonymous enumeration of shares.DISA Microsoft Windows Server 2019 STIG v3r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000029 - Microsoft Defender AV virus definition age must not exceed 7 days.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY