Item Search

NameAudit NamePluginCategory
1.33 CISC-ND-001200CIS Cisco IOS Router NDM STIG v1.1.0 CAT ICisco

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

AIX7-00-001137 - AIX must be able to control the ability of remote login for users.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AOSX-15-002063 - The macOS system must enforce access restrictions.DISA STIG Apple Mac OSX 10.15 v1r10Unix

CONFIGURATION MANAGEMENT

APPL-11-003001 - The macOS system must issue or obtain public key certificates under an appropriate certificate policy from an approved service provider.DISA STIG Apple macOS 11 v1r8Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-14-002038 - The macOS system must disable Trivial File Transfer Protocol service.DISA Apple macOS 14 Sonoma STIG v2r4Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

APPL-26-002038 - The macOS system must disable Trivial File Transfer Protocol (TFTP) service.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

CISC-ND-001210 - The Cisco switch must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA Cisco NX OS Switch NDM STIG v3r6Cisco

MAINTENANCE

CISC-ND-001210 - The Cisco switch must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA Cisco IOS Switch NDM STIG v3r8Cisco

MAINTENANCE

CISC-ND-001450 - The Cisco switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).DISA Cisco NX OS Switch NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001450 - The Cisco switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).DISA Cisco IOS Switch NDM STIG v3r8Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000310 - The Cisco perimeter switch must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

DB2X-00-007000 - DB2 must prevent non-privileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasuresDISA STIG IBM DB2 v10.5 LUW v2r1 DatabaseIBM_DB2DB

ACCESS CONTROL

EP11-00-003300 - The EDB Postgres Advanced Server software installation account must be restricted to authorized users.EDB PostgreSQL Advanced Server v11 DB Audit v2r4PostgreSQLDB

CONFIGURATION MANAGEMENT

ESXI-65-000047 - The ESXi Image Profile and VIB Acceptance Levels must be verified.DISA STIG VMware vSphere ESXi OS 6.5 v2r4Unix

CONFIGURATION MANAGEMENT

EX16-MB-000530 - Exchange servers must have an approved DoD email-aware virus protection software installed.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

JUSX-AG-000145 - The Juniper SRX Services Gateway Firewall must continuously monitor outbound communications traffic for unusual/unauthorized activities or conditions.DISA Juniper SRX Services Gateway ALG v3r3Juniper

SYSTEM AND INFORMATION INTEGRITY

JUSX-DM-000147 - The Juniper SRX Services Gateway must securely configure SSHv2 FIPS 140-2/140-3 validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of maintenance and diagnostic communications for nonlocal maintenance sessions - MAC algorithms to protect the integrity of maintenance and diagnostic communications.DISA Juniper SRX Services Gateway NDM v3r3Juniper

MAINTENANCE

O121-C1-011100 - Oracle software must be evaluated and patched against newly found vulnerabilities.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-C1-019700 - The DBMS must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures.DISA Oracle Database 12c STIG v3r5 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

O121-OS-004600 - Use of the DBMS software installation account must be restricted.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

O121-P2-010800 - The DBMS software installation account must be restricted to authorized users.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

OH12-1X-000007 - OHS must have the LoadModule ossl_module directive enabled to encrypt remote connections in accordance with the categorization of data hosted by the web server.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OH12-1X-000012 - OHS must have the SSLFIPS directive enabled to protect the integrity of remote sessions in accordance with the categorization of data hosted by the web server.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OH12-1X-000013 - OHS must have the SSLEngine, SSLProtocol, and SSLWallet directives enabled and configured to protect the integrity of remote sessions in accordance with the categorization of data hosted by the web server - SSLEngineDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OH12-1X-000013 - OHS must have the SSLEngine, SSLProtocol, and SSLWallet directives enabled and configured to protect the integrity of remote sessions in accordance with the categorization of data hosted by the web server - SSLProtocolDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OH12-1X-000013 - OHS must have the SSLEngine, SSLProtocol, and SSLWallet directives enabled and configured to protect the integrity of remote sessions in accordance with the categorization of data hosted by the web server - SSLWalletDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OL6-00-000214 - The rshd service must not be running - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL07-00-010300 - The Oracle Linux operating system must be configured so that the SSH daemon does not allow authentication using an empty password.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-06-000227 - The SSH daemon must be configured to use only the SSHv2 protocol.DISA Red Hat Enterprise Linux 6 STIG v2r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-07-010300 - The Red Hat Enterprise Linux operating system must be configured so that the SSH daemon does not allow authentication using an empty password.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-07-020060 - The Red Hat Enterprise Linux operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components of local packages without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

SLEM-05-215015 - SLEM 5 must not have the telnet-server package installed.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SLES-15-010030 - The SUSE operating system must not have the vsftpd package installed if not required for operational support.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SOL-11.1-010380 - The audit system must alert the System Administrator (SA) if there is any type of audit failure.DISA Solaris 11 X86 STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-060150 - The operating system must employ cryptographic mechanisms to protect information in storage.DISA Solaris 11 X86 STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SQL6-D0-000100 - SQL Server databases must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA MS SQL Server 2016 Database STIG v3r5MS_SQLDB

ACCESS CONTROL

SQL6-D0-006700 - SQL Server software installation account must be restricted to authorized users.DISA MS SQL Server 2016 Instance STIG v3r6 WindowsWindows

CONFIGURATION MANAGEMENT

WN10-UR-000015 - The Act as part of the operating system user right must not be assigned to any groups or accounts.DISA Microsoft Windows 10 STIG v3r6Windows

ACCESS CONTROL

WN12-CC-000073 - The default Autorun behavior must be configured to prevent Autorun commands.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-CC-000116 - The Windows Installer Always install with elevated privileges option must be disabled.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-CC-000116 - The Windows Installer Always install with elevated privileges option must be disabled.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-RG-000004 - Anonymous access to the registry must be restrictedDISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

ACCESS CONTROL

WN12-RG-000004 - Anonymous access to the registry must be restrictedDISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

ACCESS CONTROL

WN12-UR-000003 - The Act as part of the operating system user right must not be assigned to any groups or accounts.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

ACCESS CONTROL

WN12-UR-000012 - The Create a token object user right must not be assigned to any groups or accounts.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

ACCESS CONTROL

WN16-DC-000010 - Only administrators responsible for the domain controller must have Administrator rights on the system.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL

WN16-UR-000130 - The Debug programs user right must only be assigned to the Administrators group.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL

WN19-DC-000010 - Windows Server 2019 must only allow administrators responsible for the domain controller to have Administrator rights on the system.DISA Microsoft Windows Server 2019 STIG v3r8Windows

ACCESS CONTROL

WN19-DC-000070 - Windows Server 2019 permissions on the Active Directory data files must only allow System and Administrators access.DISA Microsoft Windows Server 2019 STIG v3r8Windows

ACCESS CONTROL

WN19-DC-000090 - Windows Server 2019 Active Directory Group Policy objects must have proper access control permissions.DISA Microsoft Windows Server 2019 STIG v3r8Windows

ACCESS CONTROL