Item Search

NameAudit NamePluginCategory
1.1.19 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes 1.11 Benchmark v1.3.0 L1Unix

ACCESS CONTROL

1.1.20 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

ACCESS CONTROL

1.4.1.1 Non Default Community Names, Access Rights & ACLCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security RecommendationsArubaOS

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

1.4.1.1 Non Default Community Names, Access Rights & ACLCIS HPE Aruba Networking CX Switch v1.0.1 L1ArubaOS

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

1.6.3 Create administrative boundaries between resources using namespacesCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

ACCESS CONTROL

1.9 CISC-ND-000210CIS Cisco IOS Router NDM STIG v1.1.0 CAT IICisco

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.11 CISC-ND-000290CIS Cisco IOS Router NDM STIG v1.1.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.14.1 (L1) Ensure 'Guided Switch Enabled' is set to 'Disabled'CIS Microsoft Edge v4.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.19 CISC-ND-000570CIS Cisco IOS Router NDM STIG v1.1.0 CAT IICisco

IDENTIFICATION AND AUTHENTICATION

1.21 CISC-ND-001210CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT ICisco

MAINTENANCE

1.34 CISC-ND-001210CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

MAINTENANCE

1.39 EX19-ED-000129CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

1.62 VCSA-80-000300CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT IIVMware

CONFIGURATION MANAGEMENT

3.1.14 Ensure that the --authorization-mode argument is not set to AlwaysAllowCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

ACCESS CONTROL

4.5.1 Ensure RIP authentication is set to MD5CIS Juniper OS Benchmark v2.1.0 L1Juniper

IDENTIFICATION AND AUTHENTICATION

5.7.1 Create administrative boundaries between resources using namespacesCIS Red Hat OpenShift Container Platform v1.9.0 L1OpenShift

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

AMLS-L2-000140 - The Arista Multilayer Switch must re-authenticate all endpoint devices every 60 minutes or less - dot1x reauthenticationDISA STIG Arista MLS DCS-7000 Series L2S v1r3Arista

IDENTIFICATION AND AUTHENTICATION

CIS_Cisco_IOS_12_v4.0.0_Level_2.audit for Cisco IOS 12 from CIS Cisco IOS 12 Benchmark v4.0.0CIS Cisco IOS 12 L2 v4.0.0Cisco
CISC-ND-001000 - The Cisco router must be configured to generate an alert for all audit failure events.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001210 - The Cisco router must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

MAINTENANCE

DG0071-ORACLE11 - New passwords must be required to differ from old passwords by more than four characters - 'PASSWORD_VERIFY_FUNCTION is not set to NULL or DEFAULT'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
EX13-EG-000165 - Exchange messages with a blank sender field must be rejected.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-ED-000330 - Exchange messages with a blank sender field must be rejected.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-ED-000340 - Exchange messages with a blank sender field must be filtered.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-ED-000123 - Exchange messages with a blank sender field must be rejected.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-ED-000124 - Exchange messages with a blank sender field must be filtered.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

HP ProCurve - 'RADIUS or TACACS Authentication is configured'TNS HP ProCurveHPProCurve
JUEX-L2-000050 - The Juniper EX switch must be configured to permit authorized users to select a user session to capture.DISA Juniper EX Series Layer 2 Switch v2r4Juniper

AUDIT AND ACCOUNTABILITY

JUSX-IP-000027 - The Juniper Networks SRX Series Gateway IDPS must perform real-time monitoring of files from external sources at network entry/exit points.DISA Juniper SRX Services Gateway IDPS v2r1Juniper

SYSTEM AND INFORMATION INTEGRITY

OS10-NDM-000120 - The Dell OS10 Switch must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

ACCESS CONTROL

OS10-NDM-000340 - The Dell OS10 Switch must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

CONFIGURATION MANAGEMENT

OS10-NDM-000400 - The Dell OS10 Switch must enforce a minimum 15-character password length.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

IDENTIFICATION AND AUTHENTICATION

OS10-NDM-000430 - The Dell OS10 Switch must enforce password complexity by requiring that at least one numeric character be used.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

IDENTIFICATION AND AUTHENTICATION

OS10-NDM-000480 - The Dell OS10 Switch must be configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

IDENTIFICATION AND AUTHENTICATION

OS10-NDM-000960 - The Dell OS10 Switch must obtain its public key certificates from an appropriate certificate policy through an approved service provider.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

OS10-NDM-001070 - The Dell OS10 Switch must not have any default manufacturer passwords when deployed.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

IDENTIFICATION AND AUTHENTICATION

OS10-RTR-000050 - The Dell OS10 BGP router must be configured to reject outbound route advertisements for any prefixes that do not belong to any customers or the local autonomous system (AS).DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

ACCESS CONTROL

OS10-RTR-000220 - The Dell OS10 multicast Rendezvous Point (RP) router must be configured to filter Protocol Independent Multicast (PIM) Register messages received from the Designated Router (DR) for any undesirable multicast groups and sources.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

ACCESS CONTROL

OS10-RTR-000290 - The Dell OS10 Router must be configured to use encryption for routing protocol authentication.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

IDENTIFICATION AND AUTHENTICATION

OS10-RTR-000300 - The Dell OS10 Router must be configured to authenticate all routing protocol messages using NIST-validated FIPS 198-1 message authentication code algorithm.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

IDENTIFICATION AND AUTHENTICATION

OS10-RTR-000470 - The Dell OS10 out-of-band management (OOBM) gateway router must be configured to forward only authorized management traffic to the Network Operations Center (NOC).DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

SYSTEM AND COMMUNICATIONS PROTECTION

OS10-RTR-000600 - The Dell OS10 Router must not be configured to have any zero-touch deployment feature enabled when connected to an operational network.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

SYSTEM AND COMMUNICATIONS PROTECTION

OS10-RTR-000610 - The Dell OS10 Router must be configured to protect against or limit the effects of denial-of-service (DoS) attacks by employing control plane protection.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

SYSTEM AND COMMUNICATIONS PROTECTION

OS10-RTR-000630 - The Dell OS10 Router must be configured to have IP directed broadcast disabled on all interfaces.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

SYSTEM AND COMMUNICATIONS PROTECTION

OS10-RTR-000680 - The Dell OS10 BGP router must be configured to limit the prefix size on any inbound route advertisement to /24 or the least significant prefixes issued to the customer.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

SYSTEM AND COMMUNICATIONS PROTECTION

OS10-RTR-001020 - The Dell OS10 Router must be configured to advertise a hop limit of at least 32 in Router Advertisement messages for IPv6 stateless auto-configuration deployments.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

CONFIGURATION MANAGEMENT

OS10-RTR-001030 - The Dell OS10 Router must not be configured to use IPv6 Site Local Unicast addresses.DISA Dell OS10 Switch Router STIG v1r2Dell_OS10

CONFIGURATION MANAGEMENT

VCSA-80-000279 - The vCenter Server must protect the confidentiality and integrity of transmitted information by isolating Internet Protocol (IP)-based storage traffic.DISA VMware vSphere 8.0 vCenter STIG v2r4 VMwareVMware

CONFIGURATION MANAGEMENT

VCSA-80-000300 - The vCenter Server must remove unauthorized port mirroring sessions on distributed switches.DISA VMware vSphere 8.0 vCenter STIG v2r4 VMwareVMware

CONFIGURATION MANAGEMENT

WN22-MS-000010 - Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL