Item Search

NameAudit NamePluginCategory
1.001 - Physical security of the Automated Information System (AIS) does not meet DISA requirements.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

1.5 CISC-RT-000130CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT ICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.64 CISC-RT-000620CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

CONFIGURATION MANAGEMENT

1.84 CISC-RT-000830CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IIICisco

ACCESS CONTROL

2.2.2 Set 'ip address' for 'ntp server'CIS Cisco IOS XR 7.x v1.0.1 L1Cisco

AUDIT AND ACCOUNTABILITY

2.3.2 Set 'ip address' for 'ntp server'CIS Cisco IOS XE 16.x v2.2.0 L1Cisco

AUDIT AND ACCOUNTABILITY

2.3.2 Set 'ip address' for 'ntp server'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

AUDIT AND ACCOUNTABILITY

3.1.2 ISIS Interface and Instance AuthenticationCIS Arista EOS benchmark v1.0.0 L2Arista

IDENTIFICATION AND AUTHENTICATION

3.3.1.9 Ensure net.ipv4.conf.default.accept_redirects is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.9 Ensure net.ipv4.conf.default.accept_redirects is configuredCIS Rocky Linux 8 v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.9 Ensure net.ipv4.conf.default.accept_redirects is configuredCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.9 Ensure net.ipv4.conf.default.accept_redirects is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Red Hat Enterprise Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Red Hat Enterprise Linux 10 v1.0.1 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Rocky Linux 8 v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS AlmaLinux OS 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Rocky Linux 8 v3.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Oracle Linux 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Rocky Linux 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

ALMA-09-020260 - Alma Linux OS 9 must not accept IPv4 source-routed packets by default.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

CONFIGURATION MANAGEMENT

CISC-RT-000660 - The Cisco PE router providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

IDENTIFICATION AND AUTHENTICATION

F5BI-FW-300020 - The F5 BIG-IP appliance must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).DISA F5 BIG-IP TMOS Firewall STIG v1r1F5

SYSTEM AND COMMUNICATIONS PROTECTION

GEN003600 - The system must not forward IPv4 source-routed packets - dladm show-linkDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN007920 - The system must not forward IPv6 source-routed packets - dladm show-linkDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

JUEX-L2-000030 - The Juniper layer 2 switch must be configured to disable all dynamic VLAN registration protocols.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-L2-000050 - The Juniper EX switch must be configured to permit authorized users to select a user session to capture.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-L2-000070 - The Juniper EX switch must be configured to authenticate all network-connected endpoint devices before establishing any connection.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-L2-000090 - The Juniper EX switch must be configured to enable BPDU Protection on all user-facing or untrusted access switch ports.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000130 - The Juniper EX switch must be configured to enable IP Source Guard on all user-facing or untrusted access VLANs with active access interfaces.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000170 - If STP is used, the Juniper EX switch must be configured to implement Rapid STP, or Multiple STP, where VLANs span multiple switches with redundant links.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-L2-000190 - The Juniper EX switch must be configured to assign all explicitly disabled access interfaces to an unused VLAN.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000210 - The Juniper EX switch must be configured to prune the default VLAN from all trunked interfaces that do not require it.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-L2-000250 - The Juniper EX switch must not have any access interfaces assigned to a VLAN configured as native for any trunked interface.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-NM-000020 - The Juniper EX switch must be configured to automatically audit account creation.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

ACCESS CONTROL

JUEX-NM-000070 - The Juniper EX switch must be configured to enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

ACCESS CONTROL

JUEX-NM-000210 - The Juniper EX switch must be configured to protect audit tools from unauthorized access.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000280 - The Juniper EX switch must be configured to enforce password complexity by requiring that at least one uppercase character be used.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-NM-000300 - The Juniper EX switch must be configured to enforce password complexity by requiring that at least one numeric character be used.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-NM-000390 - The Juniper EX switch must be configured to enforce organization-defined role-based access control policies over defined subjects and objects.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

ACCESS CONTROL, CONFIGURATION MANAGEMENT

JUEX-NM-000510 - The Juniper EX switches must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

MAINTENANCE

JUEX-NM-000580 - The Juniper EX switch must be configured to generate audit records showing starting and ending time for administrator access to the system.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000590 - The Juniper EX switch must be configured to generate audit records when concurrent logons from different workstations occur.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUSX-VN-000018 - The Juniper SRX Services Gateway VPN must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).DISA Juniper SRX Services Gateway VPN v3r2Juniper

IDENTIFICATION AND AUTHENTICATION

JUSX-VN-000025 - The Juniper SRX Services Gateway VPN must configure Internet Key Exchange (IKE) with SHA1 or greater to protect the authenticity of communications sessions.DISA Juniper SRX Services Gateway VPN v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-VN-000027 - The Juniper SRX Services Gateway VPN must only allow incoming VPN communications from organization-defined authorized sources routed to organization-defined authorized destinations.DISA Juniper SRX Services Gateway VPN v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

WN16-MS-000010 - Only administrators responsible for the member server or standalone or nondomain-joined system must have Administrator rights on the system.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL

WN25-MS-000010 - Windows Server 2025 must only allow administrators responsible for the member server or stand-alone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL

WN25-MS-000010 - Windows Server 2025 must only allow administrators responsible for the member server or stand-alone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2025 STIG v1r3Windows

ACCESS CONTROL