Item Search

NameAudit NamePluginCategory
1.1.1.1 Syslog logging should be configuredCIS Palo Alto Firewall 10 v1.3.0 L1Palo_Alto

AUDIT AND ACCOUNTABILITY

1.1.1.1 Syslog logging should be configuredCIS Palo Alto Firewall 11 v1.2.0 L1Palo_Alto

AUDIT AND ACCOUNTABILITY

1.1.1.1 Syslog logging should be configured - hostCIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto

AUDIT AND ACCOUNTABILITY

1.1.1.1 Syslog logging should be configured - systemCIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto

AUDIT AND ACCOUNTABILITY

1.5.9 Set 'priv' for each 'snmp-server group' using SNMPv3CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.013 - System information backups are not created, updated, and protected according to DISA requirements.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

1.20 CISC-ND-001200CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT ICisco

MAINTENANCE

1.21 CISC-ND-001210CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT ICisco

MAINTENANCE

1.23 CISC-RT-000300CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IIICisco

ACCESS CONTROL

1.24 CISC-RT-000310CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT ICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.44 CISC-RT-000430CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

ACCESS CONTROL

1.49 CISC-RT-000480CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.54 CISC-RT-000520CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

ACCESS CONTROL

1.197 SLES-15-040310CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Rocky Linux 8 v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS AlmaLinux OS 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS AlmaLinux OS 8 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Oracle Linux 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.8 Ensure Loopback interface address is setCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

AMLS-L3-000250 - The Arista Multilayer Switch must encrypt all methods of configured authentication for the OSPF routing protocol - ipv6 OSPF checksDISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

IDENTIFICATION AND AUTHENTICATION

AMLS-L3-000250 - The Arista Multilayer Switch must encrypt all methods of configured authentication for the OSPF routing protocol - ospf message-digestDISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

IDENTIFICATION AND AUTHENTICATION

AMLS-L3-000290 - The Arista Multilayer Switch must configure the maximum hop limit value to at least 32.DISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-L2-000160 - The Arista MLS layer 2 switch must have all trunk links enabled statically.DISA STIG Arista MLS EOS 4.2x L2S v2r1Arista

CONFIGURATION MANAGEMENT

ARST-RT-000380 - The Arista perimeter router must be configured to filter egress traffic at the internal interface on an inbound direction.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000660 - The Arista multicast Designated Router (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups that have been approved by the organization.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000530 - The Cisco router must be configured to implement replay-resistant authentication mechanisms for network access to privileged accounts.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-ND-001210 - The Cisco router must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

MAINTENANCE

CISC-RT-000310 - The Cisco perimeter router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000340 - The Cisco perimeter router must be configured to filter egress traffic at the internal interface on an inbound direction.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000360 - The Cisco perimeter router must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000360 - The Cisco perimeter switch must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000360 - The Cisco perimeter switch must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.DISA Cisco IOS Switch RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000360 - The Cisco perimeter switch must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000370 - The Cisco perimeter switch must be configured to have Cisco Discovery Protocol (CDP) disabled on all external interfaces.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000370 - The Cisco perimeter switch must be configured to have Cisco Discovery Protocol (CDP) disabled on all external interfaces.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000630 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

CONTINGENCY PLANNING

CISC-RT-000630 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

Ensure 'EIGRP authentication' is enabledTenable Cisco Firepower Best Practices AuditCisco

CONFIGURATION MANAGEMENT

Ensure 'EIGRP authentication' is enabledTenable Cisco Firepower Threat Defense Best Practices AuditCisco_Firepower

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-CA-000010 - Exchange must use Encryption for OWA access.DISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

ACCESS CONTROL

EX16-MB-002910 - Exchange must use encryption for Outlook Web App (OWA) access.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

ACCESS CONTROL

FGFW-ND-000195 - The FortiGate device must use DoD-approved Certificate Authorities (CAs) for public key certificates.DISA Fortigate Firewall NDM STIG v1r4FortiGate

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

OL09-00-006021 - OL 9 must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA Oracle Linux 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

RHEL-10-701280 - RHEL 10 must map the authenticated identity to the user or group account for public key infrastructure (PKI)-based authentication.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-800150 - RHEL 10 must not forward Internet Protocol version 4 (IPv4) source-routed packets by default.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SQL2-00-010000 - DBA OS or domain accounts must be granted only those host system privileges necessary for the administration of SQL Server.DISA STIG SQL Server 2012 Database OS Audit v1r20Windows

CONFIGURATION MANAGEMENT

SQL4-00-030300 - SQL Server authentication and identity management must be integrated with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA STIG SQL Server 2014 Instance DB Audit v2r4MS_SQLDB

ACCESS CONTROL