Item Search

NameAudit NamePluginCategory
1.10 CISC-ND-000530CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT IICisco

IDENTIFICATION AND AUTHENTICATION

1.35 EX19-ED-000125CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

1.38 CISC-RT-000398CIS Cisco IOS Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.85 CISC-RT-000830CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IIICisco

ACCESS CONTROL

1.85 CISC-RT-000840CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IIICisco

ACCESS CONTROL

1.86 CISC-RT-000840CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IIICisco

ACCESS CONTROL

1.198 RHEL-09-254020CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.440 OL09-00-006042CIS Oracle Linux 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.1.1.1.2 Set the 'ip domain-name'CIS Cisco IOS 15 L1 v4.1.1Cisco

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Disable the IP Unreachable FunctionTenable ZTE ROSNG Best PracticesZTE_ROSNG
3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Rocky Linux 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Rocky Linux 8 v3.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.10 Ensure inbound firewall filter is set for Loopback interfaceCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

3.104 - The system is configured to detect and configure default gateway addresses.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AMLS-L2-000110 - The Arista Multilayer Switch must enforce approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies.DISA STIG Arista MLS DCS-7000 Series L2S v1r3Arista

ACCESS CONTROL

AMLS-L3-000260 - The Arista Multilayer Switch must ensure all Exterior Border Gateway Protocol (eBGP) routers are configured to use Generalized TTL Security Mechanism (GTSM) or are configured to meet RFC3682.DISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000480 - The PE router providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

IDENTIFICATION AND AUTHENTICATION

BGP: Authenticate peersTNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice AuditAlcatel

ACCESS CONTROL

CISC-ND-001200 - The Cisco router must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

MAINTENANCE

CISC-RT-000600 - The Cisco MPLS router must be configured to synchronize IGP and LDP to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000660 - The Cisco PE router providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-RT-000910 - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to authenticate all received MSDP packets.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

IDENTIFICATION AND AUTHENTICATION

DG0127-ORACLE11 - DBMS account passwords should not be set to easily guessed words or values - 'name'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

IDENTIFICATION AND AUTHENTICATION

GEN003600 - The system must not forward IPv4 source-routed packets - dladm show-linkDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN007920 - The system must not forward IPv6 source-routed packets - dladm show-linkDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

JUEX-L2-000060 - The Juniper EX switch must be configured to permit authorized users to remotely view, in real time, all content related to an established user session from a component separate from the layer 2 switch.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-L2-000120 - The Juniper EX switch must be configured to enable DHCP snooping for all user VLANs with active access interfaces to validate DHCP messages from untrusted sources.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000140 - The Juniper EX switch must be configured to enable Dynamic Address Resolution Protocol (ARP) Inspection (DAI) on all user VLANs with active access interfaces.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-NM-000090 - The Juniper EX switch must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

ACCESS CONTROL

JUEX-NM-000170 - The Juniper EX switch must be configured to generate audit records containing information that establishes the identity of any individual or process associated with the event.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000190 - The Juniper EX switch must be configured to protect audit information from unauthorized modification.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000200 - The Juniper EX switch must be configured to protect audit information from unauthorized deletion.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000260 - The Juniper EX switch must be configured to implement replay-resistant authentication mechanisms for network access to privileged accounts.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-NM-000270 - The Juniper EX switch must be configured to enforce a minimum 15-character password length.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-NM-000290 - The Juniper EX switch must be configured to enforce password complexity by requiring that at least one lowercase character be used.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-NM-000330 - The Juniper EX switch must be configured to only store cryptographic representations of passwords.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-NM-000370 - The Juniper device must be configured to only allow authorized administrators to view or change the device configuration, system files, and other files stored either in the device or on removable media (such as a flash drive).DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-NM-000410 - The Juniper EX switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000440 - The Juniper EX switch must be configured to record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000450 - The Juniper EX switch must be configured to prohibit installation of software without explicit privileged status.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-NM-000460 - The Juniper EX switch must be configured to enforce access restrictions associated with changes to device configuration.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-NM-000480 - The Juniper EX switch must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-NM-000520 - The Juniper EX switch must be configured to implement cryptographic mechanisms using a FIPS 140-2/140-3 approved algorithm to protect the confidentiality of remote maintenance sessions.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

MAINTENANCE

JUEX-NM-000570 - The Juniper EX switch must be configured to generate audit records for privileged activities or other system-level access.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000600 - The Juniper EX switch must be configured to off-load audit records onto a different system than the system being audited.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-NM-000620 - The Juniper EX switch must be configured to generate log records for a locally developed list of auditable events.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

JUEX-NM-000630 - The Juniper EX switch must be configured to enforce access restrictions associated with changes to the system components.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-NM-000680 - The Juniper EX switch must be configured with an operating system release that is currently supported by the vendor.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-NM-000910 - The Juniper EX switch must change credentials for account of last resort when administrators who know the credential leave the organization.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

ACCESS CONTROL

PHTN-67-000032 - The Photon operating system must only allow installation of packages signed by VMware.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

CONFIGURATION MANAGEMENT