Item Search

NameAudit NamePluginCategory
1.30 SLES-15-010330CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AADC-CL-001075 - Unsupported versions of Adobe Acrobat Pro DC Classic must be uninstalled.DISA STIG Adobe Acrobat Pro DC Classic Track v2r1Windows

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-001008 - All accounts on AIX system must have unique account names.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AOSX-13-000050 - The macOS system must be configured to disable rshd service.DISA STIG Apple Mac OSX 10.13 v2r5Unix

CONFIGURATION MANAGEMENT

AOSX-15-004021 - The macOS system must be configured with the sudoers file configured to authenticate users on a per -tty basis.DISA STIG Apple Mac OSX 10.15 v1r10Unix

CONFIGURATION MANAGEMENT

AS24-W1-000940 - All accounts installed with the Apache web server software and tools must have passwords assigned and default passwords changed.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

CISC-L2-000020 - The Cisco switch must uniquely identify all network-connected endpoint devices before establishing any connection.DISA Cisco NX OS Switch L2S STIG v3r4Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-ND-000720 - The Cisco switch must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA Cisco IOS XE Switch NDM STIG v3r6Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000280 - The Cisco perimeter router must be configured to protect an enclave connected to an alternate gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

ACCESS CONTROL

CISC-RT-000280 - The Cisco perimeter router must be configured to protect an enclave connected to an approved gateway by using an inbound filter that only permits packets with destination addresses within the sites address space.DISA Cisco IOS Router RTR STIG v3r4Cisco

ACCESS CONTROL

CISC-RT-000630 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

CONTINGENCY PLANNING

CISC-RT-000640 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance with the appropriate Route Target (RT).DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

CISC-RT-000640 - The Cisco PE switch must be configured to have each Virtual Routing and Forwarding (VRF) instance with the appropriate Route Target (RT).DISA Cisco NX OS Switch RTR STIG v3r4Cisco

CONTINGENCY PLANNING

CISC-RT-000670 - The Cisco PE switch providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

CONTINGENCY PLANNING

CISC-RT-000680 - The Cisco PE router providing Virtual Private LAN Services (VPLS) must be configured to have all attachment circuits defined to the virtual forwarding instance (VFI) with the globally unique VPN ID assigned for each customer VLAN.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000730 - The Cisco PE router must be configured to block any traffic that is destined to IP core infrastructure.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

DKER-EE-002030 - All Docker Enterprise containers root filesystem must be mounted as read only.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002040 - Docker Enterprise host devices must not be directly exposed to containers.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002080 - Docker Enterprise exec commands must not be used with privileged option.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002130 - The Docker Enterprise socket must not be mounted inside any containers.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

ESXI-65-000015 - The ESXi host SSH daemon must not allow authentication using an empty password.DISA STIG VMware vSphere ESXi OS 6.5 v2r4Unix

CONFIGURATION MANAGEMENT

ESXI-65-000060 - The virtual switch MAC Address Change policy must be set to reject on the ESXi host.DISA STIG VMware vSphere ESXi 6.5 v2r4VMware

CONFIGURATION MANAGEMENT

F5BI-DM-000239 - The BIG-IP appliance must be configured to protect against or limit the effects of all known types of Denial of Service (DoS) attacks on the BIG-IP appliance management network by limiting the number of concurrent sessions.DISA F5 BIG-IP Device Management STIG v2r4F5

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-LT-000219 - The BIG-IP Core implementation must be configured to protect against known types of Denial of Service (DoS) attacks by employing signatures when providing content filtering to virtual servers.DISA F5 BIG-IP Local Traffic Manager STIG v2r4F5

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000221 - Anonymous IIS 8.5 website access accounts must be restricted.DISA IIS 8.5 Site v2r9Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SV-000153 - An IIS 8.5 web server must maintain the confidentiality of controlled information during transmission through the use of an approved TLS version.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-672050 - RHEL 9 must implement DOD-approved encryption in the bind package.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-010611 - The SUSE operating system must disable the x86 Ctrl-Alt-Delete key sequence for Graphical User Interfaces.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-030040 - SuSEfirewall2 must protect against or limit the effects of Denial-of-Service (DoS) attacks on the SUSE operating system by implementing rate-limiting measures on impacted network interfaces.DISA SLES 12 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-030150 - The SUSE operating system must not allow automatic logon via SSH.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SOL-11.1-010390 - The operating system must alert designated organizational officials in the event of an audit processing failure.DISA Solaris 11 X86 STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020110 - The NIS package must not be installed.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020140 - The TFTP service daemon must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020150 - The telnet service daemon must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040370 - Login must not be permitted with empty/null passwords for SSH.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080010 - The operating system must be a supported release.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SQL6-D0-003900 - SQL Server must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

ACCESS CONTROL

SQL6-D0-008700 - SQL Server must use NIST FIPS 140-2/140-3-validated cryptographic operations for encryption, hashing, and signing.DISA MS SQL Server 2016 Instance STIG v3r6 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

SQL6-D0-018200 - Applications must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

UBTU-18-010037 - The Ubuntu operating system must be configured so that only users who need access to security functions are part of the sudo group.DISA STIG Ubuntu 18.04 LTS v2r15Unix

SYSTEM AND COMMUNICATIONS PROTECTION

VCWN-65-000027 - The vCenter Server for Windows must minimize access to the vCenter server.DISA VMware vSphere 6.5 vCenter Server for Windows STIG v2r3VMware

CONFIGURATION MANAGEMENT

WN10-CC-000155 - Solicited Remote Assistance must not be allowed.DISA Microsoft Windows 10 STIG v3r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN10-CC-000345 - The Windows Remote Management (WinRM) service must not use Basic authentication.DISA Microsoft Windows 10 STIG v3r6Windows

MAINTENANCE

WN10-SO-000145 - Anonymous enumeration of SAM accounts must not be allowed.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN16-00-000010 - Users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN16-00-000040 - Administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN16-MS-000120 - Windows Server 2016 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN19-00-000110 - Windows Server 2019 must use an anti-virus program.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN19-MS-000140 - Windows Server 2019 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WNDF-AV-000028 - Microsoft Defender AV spyware definition age must not exceed 7 days.DISA Microsoft Defender Antivirus STIG v2r9Windows

SYSTEM AND INFORMATION INTEGRITY