Item Search

NameAudit NamePluginCategory
1.8.11 Ensure overriding the screensaver lock-delay setting is preventedCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

ACCESS CONTROL

1.8.12 Ensure session idle-delay settings is enforcedCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

ACCESS CONTROL

1.8.14 Ensure the screensaver idle-activation-enabled settingCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

ACCESS CONTROL

1.9 CISC-RT-000150CIS Cisco NX OS Switch RTR STIG v1.1.0 CAT IICisco

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.10.11 Ensure 'logging trap severity level' is greater than or equal to '5'CIS Cisco Firewall v8.x L1 v4.2.0Cisco

AUDIT AND ACCOUNTABILITY

2.3.7.2 (L1) Ensure 'Interactive logon: Do not require CTRL+ALT+DEL' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 WorkstationUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.4.1.5 Ensure inactive password lock is configuredCIS Debian Linux 13 v1.1.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

5.21 (L2) Ensure 'Remote Registry (RemoteRegistry)' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L2Windows

CONFIGURATION MANAGEMENT

5.21 Ensure 'Remote Registry (RemoteRegistry)' is set to 'Disabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT

5.21 Ensure 'Remote Registry (RemoteRegistry)' is set to 'Disabled'CIS Windows 7 Workstation Level 2 v3.2.0Windows

CONFIGURATION MANAGEMENT

7.1 Set Password Expiration Parameters on Active AccountsCIS Oracle Solaris 11.4 L1 v1.1.0Unix

ACCESS CONTROL

8.3.25 Set 'Use SmartScreen Filter' to 'Enabled:Enable'CIS IE 11 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

8.4.2 Set 'Use SmartScreen Filter' to 'Enabled:Enable'CIS IE 11 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

8.6.1 Set 'Use SmartScreen Filter' to 'Enabled:Enable'CIS IE 11 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

8.8.1 Set 'Use SmartScreen Filter' to 'Enabled:Enable'CIS IE 9 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

8.9.2 Set 'Use SmartScreen Filter' to 'Enabled:Enable'CIS IE 11 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

8.10.2 Set 'Use SmartScreen Filter' to 'Enabled:Enable'CIS IE 11 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

18.9.11.2.10 (BL) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for operating system drives' is set to 'Enabled: True'CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

ACCESS CONTROL, CONTINGENCY PLANNING

18.9.31.2 (L1) Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled'CIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1Windows

SYSTEM AND INFORMATION INTEGRITY

18.10.29.3 Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled'CIS Microsoft Windows Server 2019 v5.0.0 L1 DCWindows

SYSTEM AND INFORMATION INTEGRITY

18.10.29.3 Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled'CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MSWindows

SYSTEM AND INFORMATION INTEGRITY

18.10.29.3 Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

SYSTEM AND INFORMATION INTEGRITY

CD12-00-008000 - PostgreSQL must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to generate and validate cryptographic hashes.DISA STIG Crunchy Data PostgreSQL OS v3r1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000150 - The Cisco switch must be configured to have Gratuitous ARP disabled on all external interfaces.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

DISA_F5_BIG-IP_AFM_v2r2.audit from DISA F5 BIG-IP Advanced Firewall Manager v2r2 STIGDISA F5 BIG-IP Advanced Firewall Manager STIG v2r2F5
DISA_F5_BIG-IP_APM_v2r4.audit from DISA F5 BIG-IP Access Policy Manager v2r4 STIGDISA F5 BIG-IP Access Policy Manager STIG v2r4F5
DISA_F5_BIG-IP_LTM_v2r4.audit from DISA F5 BIG-IP Local Traffic Manager v2r4 STIGDISA F5 BIG-IP Local Traffic Manager STIG v2r4F5
DISA_STIG_Docker_Enterprise_2.x_Linux_Unix_UCP_v2r2.audit from DISA Docker Enterprise 2.x Linux/UNIX v2r2 STIGDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2Unix
DISA_STIG_VMware_vSphere_8.0_vCenter_Appliance_Lookup_Service_v2r2.audit from DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r2DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r2Unix
F5BI-DN-300013 - An authoritative name server must be configured to enable DNSSEC Resource Records.DISA F5 BIG-IP TMOS DNS STIG v1r1F5

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-DN-300030 - The validity period for the RRSIGs covering the DS RR for a zones delegated children must be no less than two days and no more than one week.DISA F5 BIG-IP TMOS DNS STIG v1r1F5

SYSTEM AND COMMUNICATIONS PROTECTION

KNOX-07-001200 - The Samsung Android 7 with Knox must be configured to enforce an application installation policy. Disable unknown sources.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-002400 - Disable all Bluetooth profiles except for HSP, HFP, and SPP - Disable Bluetooth Desktop ConnectivityAirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-002400 - Disable all Bluetooth profiles except for HSP, HFP, and SPP - Disable Bluetooth DiscoverableAirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-002400 - Disable all Bluetooth profiles except for HSP, HFP, and SPP - HSP, HFP, and SPP profilesMobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-002400 - Disable all Bluetooth profiles except for HSP, HFP, and SPP - HSP, HFP, and SPP profilesAirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-002600 - The Samsung must be configured to not display the following notifications when the device is locked: All notifications.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

KNOX-07-004900 - The Samsung must be configured to not allow backup to remote systems: Deselect Allow Google Backup.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

ACCESS CONTROL

KNOX-07-004900 - The Samsung must be configured to not allow backup to remote systems: Deselect Allow Google Backup.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

ACCESS CONTROL

KNOX-07-005900 - The Samsung must be configured to disable automatic transfer of diagnostic data. Disable Report Diagnostic Info.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-005900 - The Samsung must be configured to disable automatic transfer of diagnostic data. Disable Report Diagnostic Info.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-013900 - The Samsung Android 7 with Knox must implement the management setting: Disable Move Files from Container to Personal.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

OL07-00-040110 - The Oracle Linux 7 operating system must implement DoD-approved encryption to protect the confidentiality of SSH connections.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

PGS9-00-008000 - PostgreSQL must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to generate and validate cryptographic hashes.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

PGS9-00-008200 - PostgreSQL must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owners requirements.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

Server-supplied privilege levelArubaOS Switch 16.x Hardening Guide v1.0.0ArubaOS

IDENTIFICATION AND AUTHENTICATION

TCAT-AS-000630 - TLS must be enabled on JMX.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

TCAT-AS-000780 - Access to JMX management interface must be restricted.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION