Item Search

NameAudit NamePluginCategory
1.1.1.1 Syslog logging should be configured - user-idCIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto

AUDIT AND ACCOUNTABILITY

1.45 CISC-RT-000430CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

ACCESS CONTROL

1.123 APPL-26-003020CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.124 APPL-14-003020CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.127 APPL-15-003030CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.197 SLES-15-040310CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

3.1.3 Forbid Dial in AccessCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

4.5.8 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)' is set to 'Disabled'CIS Microsoft Intune for Windows 10 v5.0.0 L2Windows

CONFIGURATION MANAGEMENT

6.7.6 Ensure Different Authentication Keys for each NTP ServerCIS Juniper OS Benchmark v2.1.0 L2Juniper

AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

18.4.7 (L2) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)' is set to 'Disabled'CIS Microsoft Windows Server 2008 Domain Controller Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.4.8 (L2) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L2Windows

CONFIGURATION MANAGEMENT, RISK ASSESSMENT

18.5.7 (L2) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)' is set to 'Disabled'CIS Windows Server 2012 R2 DC L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.5.7 (L2) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)' is set to 'Disabled'CIS Windows Server 2012 MS L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

18.5.7 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.5.7 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.5.7 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows Server 2019 v5.0.0 L2 DCWindows

CONFIGURATION MANAGEMENT

18.5.7 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.5.8 (L1) Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.5.8 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L2Windows

CONFIGURATION MANAGEMENT

18.5.8 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 BLWindows

CONFIGURATION MANAGEMENT

18.5.8 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L2 NGWindows

CONFIGURATION MANAGEMENT

18.5.8 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v5.0.0 L2 NGWindows

CONFIGURATION MANAGEMENT

18.5.8 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

CONFIGURATION MANAGEMENT

18.5.8 Ensure 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L2Windows

CONFIGURATION MANAGEMENT

AIX7-00-001101 - AIX CDE must conceal, via the session lock, information previously visible on the display with a publicly viewable image.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AMLS-L3-000200 - The Arista Multilayer Switch must enforce that any interface used for out-of-band management traffic is configured to be passive for the Interior Gateway Protocol that is utilized on that management interface.DISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

ACCESS CONTROL

AMLS-L3-000250 - The Arista Multilayer Switch must encrypt all methods of configured authentication for the OSPF routing protocol - ospf message-digest-keyDISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

IDENTIFICATION AND AUTHENTICATION

AOSX-14-003002 - The macOS system must enable certificate for smartcards.DISA STIG Apple Mac OSX 10.14 v2r6Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL

APPL-11-001060 - The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities to verify the establishment of protected sessions.DISA STIG Apple macOS 11 v1r8Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.DISA STIG Apple macOS 12 v1r9Unix

IDENTIFICATION AND AUTHENTICATION

APPL-14-003030 - The macOS system must allow smart card authentication.DISA Apple macOS 14 Sonoma STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION

APPL-26-003030 - The macOS system must allow smart card authentication.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

ARST-RT-000080 - The Arista Multicast Source Discovery Protocol (MSDP) router must be configured to filter source-active multicast advertisements to external MSDP peers to avoid global visibility of local-only multicast sources and groups.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

ACCESS CONTROL

CISC-ND-001440 - The Cisco switch must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.DISA Cisco NX OS Switch NDM STIG v3r6Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000210 - The Cisco router must be configured to produce audit records containing information to establish where the events occurred.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000360 - The Cisco perimeter router must be configured to have Link Layer Discovery Protocol (LLDP) disabled on all external interfaces.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000370 - The Cisco perimeter router must be configured to have Cisco Discovery Protocol (CDP) disabled on all external interfaces.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000370 - The Cisco perimeter switch must be configured to have Cisco Discovery Protocol (CDP) disabled on all external interfaces.DISA Cisco IOS Switch RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000630 - The Cisco PE switch must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

DG0175-ORACLE11 - The DBMS host platform and other dependent applications should be configured in compliance with applicable STIG requirements.DISA STIG Oracle 11 Installation v9r1 LinuxUnix
DG0175-ORACLE11 - The DBMS host platform and other dependent applications should be configured in compliance with applicable STIG requirements.DISA STIG Oracle 11 Installation v9r1 WindowsWindows
ESXI5-VMNET-000010 - All port groups must be configured to a value other than that of the native VLAN.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

CONFIGURATION MANAGEMENT

ESXI5-VMNET-000011 - All port groups must not be configured to VLAN 4095 except for Virtual Guest Tagging (VGT) - VGTDISA VMWare ESXi 5.0 Server STIG v2r1VMware

CONFIGURATION MANAGEMENT

F5BI-DM-000283 - The BIG-IP appliance must be configured to obtain its public key certificates from an appropriate certificate policy through a DoD-approved service provider.DISA F5 BIG-IP Device Management STIG v2r4F5

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-DM-300044 - The F5 BIG-IP appliance must obtain its public key certificates from an appropriate certificate policy through an approved service provider.DISA F5 BIG-IP TMOS NDM STIG v1r2F5

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

Network Security - Ensure Proxy ARP is either not configured, or is restricted to specific interfacesJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

OL09-00-006021 - OL 9 must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA Oracle Linux 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

SYMP-NM-000200 - Symantec ProxySG must obtain its public key certificates from an appropriate certificate policy through an approved service provider.DISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

SYMP-NM-000200 - Symantec ProxySG must obtain its public key certificates from an appropriate certificate policy through an approved service provider. - attribute keyringDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION