Item Search

NameAudit NamePluginCategory
1.79 APPL-14-002038CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT IUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

1.81 RHEL-10-300040CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, MAINTENANCE

1.85 RHEL-10-300080CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-003070 - The ntalk daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AS24-U1-000940 - The account used to run the Apache web server must not have a valid login shell and password defined.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

CONFIGURATION MANAGEMENT

CISC-ND-000470 - The Cisco router must be configured to be configured to prohibit the use of all unnecessary and nonsecure functions and services.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

CONFIGURATION MANAGEMENT

CISC-ND-000470 - The Cisco switch must be configured to prohibit the use of all unnecessary and nonsecure functions and services.DISA Cisco IOS XE Switch NDM STIG v3r6Cisco

CONFIGURATION MANAGEMENT

CISC-ND-000720 - The Cisco switch must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA Cisco NX OS Switch NDM STIG v3r6Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000720 - The Cisco switch must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA Cisco IOS Switch NDM STIG v3r8Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000290 - The Cisco perimeter router must be configured to not be a Border Gateway Protocol (BGP) peer to an alternate gateway service provider.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000630 - The Cisco PE switch must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000640 - The Cisco PE switch must be configured to have each Virtual Routing and Forwarding (VRF) instance with the appropriate Route Target (RT).DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000730 - The Cisco PE switch must be configured to block any traffic that is destined to the IP core infrastructure.DISA Cisco IOS Switch RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000730 - The Cisco PE switch must be configured to block any traffic that is destined to the IP core infrastructure.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-65-000072 - The ESXi host must have all security patches and updates installed.DISA STIG VMware vSphere ESXi 6.5 v2r4VMware

CONFIGURATION MANAGEMENT

F5BI-LT-000221 - The BIG-IP Core implementation must be configured to protect against or limit the effects of known and unknown types of Denial of Service (DoS) attacks by employing pattern recognition pre-processors when providing content filtering to virtual servers.DISA F5 BIG-IP Local Traffic Manager STIG v2r4F5

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000221 - Anonymous IIS 10.0 website access accounts must be restricted.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000131 - IIS 10.0 Web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000153 - An IIS 10.0 web server must maintain the confidentiality of controlled information during transmission through the use of an approved Transport Layer Security (TLS) version.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SV-000120 - All IIS 8.5 web server sample code, example applications, and tutorials must be removed from a production IIS 8.5 server.DISA IIS 8.5 Server v2r7Windows

CONFIGURATION MANAGEMENT

IISW-SV-000131 - IIS 8.5 Web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.DISA IIS 8.5 Server v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

OL09-00-002421 - OL 9 must implement DOD-approved encryption in the bind package.DISA Oracle Linux 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-12-010380 - The SUSE operating system must not allow unattended or automatic logon via the graphical user interface.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010400 - There must be no .shosts files on the SUSE operating system.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010410 - There must be no shosts.equiv files on the SUSE operating system.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SOL-11.1-010390 - The operating system must alert designated organizational officials in the event of an audit processing failure.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020130 - The FTP daemon must not be installed unless required.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020150 - The telnet service daemon must not be installed unless required.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040480 - The operating system must not allow logins for users with blank passwords.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-080160 - SNMP default community strings and passphrases must be changed from vendor defaults.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SQL6-D0-003200 - SQL Server must use NSA-approved cryptography to protect classified information in accordance with the data owners requirements.DISA MS SQL Server 2016 Database STIG v3r5MS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-16-010000 - The Ubuntu operating system must be a vendor supported release.DISA STIG Ubuntu 16.04 LTS v2r3Unix

SYSTEM AND INFORMATION INTEGRITY

UBTU-16-010370 - The Ubuntu operating system must implement NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA STIG Ubuntu 16.04 LTS v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-16-030010 - The Network Information Service (NIS) package must not be installed.DISA STIG Ubuntu 16.04 LTS v2r3Unix

CONFIGURATION MANAGEMENT

UBTU-18-010019 - The Ubuntu operating system must not have the rsh-server package installed.DISA STIG Ubuntu 18.04 LTS v2r15Unix

CONFIGURATION MANAGEMENT

UBTU-18-010150 - The Ubuntu Operating system must disable the x86 Ctrl-Alt-Delete key sequence if a graphical user interface is installed.DISA STIG Ubuntu 18.04 LTS v2r15Unix

CONFIGURATION MANAGEMENT

UBTU-18-010424 - The Ubuntu operating system must not allow unattended or automatic login via ssh.DISA STIG Ubuntu 18.04 LTS v2r15Unix

CONFIGURATION MANAGEMENT

VCWN-65-000014 - The vCenter Server for Windows must set the distributed port group MAC Address Change policy to reject.DISA VMware vSphere 6.5 vCenter Server for Windows STIG v2r3VMware

CONFIGURATION MANAGEMENT

WBSP-AS-000212 - The WebSphere Application Server Java 2 security must not be bypassed.DISA IBM WebSphere Traditional 9 Windows STIG v2r1Windows

ACCESS CONTROL

WN10-00-000150 - Structured Exception Handling Overwrite Protection (SEHOP) must be enabled.DISA Microsoft Windows 10 STIG v3r6Windows

SYSTEM AND INFORMATION INTEGRITY

WN10-SO-000150 - Anonymous enumeration of shares must be restricted.DISA Microsoft Windows 10 STIG v3r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN10-SO-000165 - Anonymous access to Named Pipes and Shares must be restricted.DISA Microsoft Windows 10 STIG v3r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN16-SO-000260 - Anonymous enumeration of Security Account Manager (SAM) accounts must not be allowed.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN16-SO-000270 - Anonymous enumeration of shares must not be allowed.DISA Microsoft Windows Server 2016 STIG v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN19-00-000100 - Windows Server 2019 must be maintained at a supported servicing level.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN19-00-000130 - Windows Server 2019 local volumes must use a format that supports NTFS attributes.DISA Microsoft Windows Server 2019 STIG v3r8Windows

ACCESS CONTROL

WN19-CC-000500 - Windows Server 2019 Windows Remote Management (WinRM) service must not use Basic authentication.DISA Microsoft Windows Server 2019 STIG v3r8Windows

MAINTENANCE

WN19-SO-000020 - Windows Server 2019 must prevent local accounts with blank passwords from being used from the network.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN19-SO-000210 - Windows Server 2019 must not allow anonymous SID/Name translation.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT

WN19-SO-000220 - Windows Server 2019 must not allow anonymous enumeration of Security Account Manager (SAM) accounts.DISA Microsoft Windows Server 2019 STIG v3r8Windows

CONFIGURATION MANAGEMENT