Item Search

NameAudit NamePluginCategory
1.9 SSL Strong Algorithm - d) renegotiateTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.12 (L2) Host integrated hardware management controller must deactivate internal networkingCIS VMware ESXi 8.0 v1.3.0 L2VMware

CONFIGURATION MANAGEMENT

1.19 CISC-RT-000250CIS Cisco IOS Switch RTR STIG v1.1.0 CAT IICisco

ACCESS CONTROL

1.34 CISC-RT-000394CIS Cisco IOS Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.34 EX19-ED-000124CIS Microsoft Exchange 2019 Edge Server STIG v1.0.0 CAT IIWindows

SYSTEM AND INFORMATION INTEGRITY

1.35 CISC-RT-000395CIS Cisco IOS Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.35 CISC-RT-000395CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.36 CISC-RT-000396CIS Cisco IOS Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.37 CISC-RT-000397CIS Cisco IOS Switch RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.42 CISC-ND-001450CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

AUDIT AND ACCOUNTABILITY

2.4.2 Disable Internet SharingCIS Apple macOS 10.12 L1 v1.2.0Unix

CONFIGURATION MANAGEMENT

2.4.2 Disable Internet SharingCIS Apple macOS 10.13 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.4.2 Ensure Internet Sharing Is DisabledCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny 0.0.0.0'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny 127.0.0.0'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny 172.16.0.0'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

6.6.4 Ensure Custom Login Classes have Permissions DefinedCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

ARST-RT-000050 - The Arista BGP router must be configured to reject outbound route advertisements for any prefixes that do not belong to any customers or the local autonomous system (AS).DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

ACCESS CONTROL

ARST-RT-000350 - The Arista router must be configured to drop all fragmented Internet Control Message Protocol (ICMP) packets destined to itself.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000420 - The out-of-band management (OOBM) Arista gateway router must be configured to forward only authorized management traffic to the Network Operations Center (NOC).DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000480 - The PE router providing MPLS Layer 2 Virtual Private Network (L2VPN) services must be configured to authenticate targeted Label Distribution Protocol (LDP) sessions used to exchange virtual circuit (VC) information using a FIPS-approved message authentication code algorithm.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

IDENTIFICATION AND AUTHENTICATION

CISC-ND-000010 - The Cisco router must be configured to limit the number of concurrent management sessions to an organization-defined number.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

ACCESS CONTROL

CISC-ND-000090 - The Cisco router must be configured to automatically audit account creation.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

ACCESS CONTROL

CISC-ND-000470 - The Cisco router must be configured to prohibit the use of all unnecessary and nonsecure functions and services.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT

CISC-ND-000880 - The Cisco router must be configured to automatically audit account enabling actions.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

ACCESS CONTROL

CISC-ND-001140 - The Cisco router must be configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

ACCESS CONTROL

CISC-ND-001270 - The Cisco router must be configured to generate log records for privileged activities.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001370 - The Cisco router must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT

CISC-ND-001410 - The Cisco router must be configured to back up the configuration when changes occur.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

CISC-ND-001450 - The Cisco router must be configured to send log data to at least two syslog servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).DISA Cisco IOS XR Router NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000010 - The Cisco router must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000180 - The Cisco router must be configured to have Internet Control Message Protocol (ICMP) mask reply messages disabled on all external interfaces.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000190 - The Cisco router must be configured to have Internet Control Message Protocol (ICMP) redirect messages disabled on all external interfaces.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000520 - The Cisco BGP router must be configured to reject outbound route advertisements for any prefixes that do not belong to any customers or the local autonomous system (AS).DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000560 - The Cisco BGP router must be configured to use the maximum prefixes feature to protect against route table flooding and prefix de-aggregation attacks.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000680 - The Cisco PE router providing Virtual Private LAN Services (VPLS) must be configured to have all attachment circuits defined to the virtual forwarding instance (VFI) with the globally unique VPN ID assigned for each customer VLAN.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000690 - The Cisco PE router must be configured to enforce the split-horizon rule for all pseudowires within a Virtual Private LAN Services (VPLS) bridge domain.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000710 - The Cisco PE router must be configured to implement Internet Group Management Protocol (IGMP) or Multicast Listener Discovery (MLD) snooping for each Virtual Private LAN Services (VPLS) bridge domain.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000780 - The Cisco PE router must be configured to enforce a Quality-of-Service (QoS) policy to limit the effects of packet flooding denial-of-service (DoS) attacks.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000810 - The Cisco multicast edge switch must be configured to establish boundaries for administratively scoped multicast traffic.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

ACCESS CONTROL

CISC-RT-000830 - The Cisco multicast Rendezvous Point (RP) router must be configured to filter Protocol Independent Multicast (PIM) Register messages received from the Designated Router (DR) for any undesirable multicast groups and sources.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000840 - The Cisco multicast Rendezvous Point (RP) router must be configured to filter Protocol Independent Multicast (PIM) Join messages received from the Designated Router (DR) for any undesirable multicast groups.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000920 - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to filter received source-active multicast advertisements for any undesirable multicast groups and sources.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

EX13-EG-000205 - The Exchange Spam Evaluation filter must be enabled.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX16-ED-000410 - The Exchange Spam Evaluation filter must be enabled.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-ED-000131 - The Exchange Spam Evaluation filter must be enabled.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

GEN003607 - The system must not accept source-routed IPv4 packets - dladm show-linkDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN003607 - The system must not accept source-routed IPv4 packets - dladm show-linkDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

RHEL-10-800100 - RHEL 10 must not forward Internet Protocol version 4 (IPv4) source-routed packets.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800280 - RHEL 10 must not forward Internet Protocol version 6 (IPv6) source-routed packets by default.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION