Item Search

NameAudit NamePluginCategory
1.3 IIST-SI-000203CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.6 IIST-SI-000208CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

AUDIT AND ACCOUNTABILITY

1.9 IIST-SI-000214CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

1.13 IIST-SI-000220CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.15 IIST-SI-000223CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.16 IIST-SI-000225CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.21 IIST-SI-000229CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

2.1 Ensure 'global authorization rule' is set to restrict accessCIS IIS 8.0 v1.5.1 Level 1Windows

ACCESS CONTROL

3.12 Ensure Server Header is removed - ApplicationsCIS IIS 10 v1.2.1 Level 2Windows

CONFIGURATION MANAGEMENT

3.12 Ensure Server Header is removed - DefaultCIS IIS 10 v1.2.1 Level 2Windows

CONFIGURATION MANAGEMENT

4.11 Ensure 'Dynamic IP Address Restrictions' is enabledCIS IIS 8.0 v1.5.1 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.11 Ensure 'Dynamic IP Address Restrictions' is enabledCIS IIS 7 L1 v1.8.0Windows
6.1 Setup Client-cert AuthenticationCIS Apache Tomcat 8 L2 v1.1.0 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

6.1 Setup Client-cert AuthenticationCIS Apache Tomcat 8 L2 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

AOSX-15-100001 - The macOS system must be a supported release.DISA STIG Apple Mac OSX 10.15 v1r10Unix

CONFIGURATION MANAGEMENT

DISA_STIG_MSSQL_2012_Instance-DB_v1r20.audit from DISA Microsoft SQL Server Instance 2012 v1r20 STIGDISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB
GEN002860 - Audit logs must be rotated daily.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN002860 - Audit logs must be rotated daily.DISA STIG AIX 6.1 v1r14Unix

CONFIGURATION MANAGEMENT

GEN002860 - Audit logs must be rotated daily.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

IIST-SI-000203 - A private IIS 10.0 website must only accept Secure Socket Layer (SSL) connections.DISA IIS 10.0 Site v2r14Windows

ACCESS CONTROL

IIST-SI-000203 - A private IIS 10.0 website must only accept Secure Socket Layer (SSL) connections.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

ACCESS CONTROL

IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.DISA IIS 10.0 Site v2r14Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000206 - Both the log file and Event Tracing for Windows (ETW) for each IIS 10.0 website must be enabled.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000208 - An IIS 10.0 website behind a load balancer or proxy server must produce log records containing the source client IP, and destination information.DISA IIS 10.0 Site v2r14Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000208 - An IIS 10.0 website behind a load balancer or proxy server must produce log records containing the source client IP, and destination information.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000214 - The IIS 10.0 website must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IIST-SI-000214 - The IIS 10.0 website must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

CONFIGURATION MANAGEMENT

IIST-SI-000220 - A private IIS 10.0 website authentication mechanism must use client certificates to transmit session identifier to assure integrity.DISA IIS 10.0 Site v2r14Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000220 - A private IIS 10.0 website authentication mechanism must use client certificates to transmit session identifier to assure integrity.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000223 - The IIS 10.0 website must generate unique session identifiers that cannot be reliably reproduced.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000223 - The IIS 10.0 website must generate unique session identifiers that cannot be reliably reproduced.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000229 - Double encoded URL requests must be prohibited by any IIS 10.0 website.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000234 - Debugging and trace information used to diagnose the IIS 10.0 website must be disabled.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SI-000234 - Debugging and trace information used to diagnose the IIS 10.0 website must be disabled.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000102 - The enhanced logging for the IIS 10.0 web server must be enabled and capture all user and web server events.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000109 - An IIS 10.0 web server behind a load balancer or proxy server must produce log records containing the source client IP and destination information.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000110 - The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server events.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000111 - The IIS 10.0 web server must produce log records containing sufficient information to establish the identity of any user/subject or process associated with an event.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000118 - The IIS 10.0 web server must only contain functions necessary for operation.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IIST-SV-000119 - The IIS 10.0 web server must not be both a website server and a proxy server.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IIST-SV-000119 - The IIS 10.0 web server must not be both a website server and a proxy server.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000124 - The IIS 10.0 web server must have Multipurpose Internet Mail Extensions (MIME) that invoke OS shell programs disabled.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IIST-SV-000134 - The IIS 10.0 web server must use cookies to track session state.DISA IIS 10.0 Server v2r10Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000134 - The IIS 10.0 web server must use cookies to track session state.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000152 - IIS 10.0 web server session IDs must be sent to the client using TLS.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SV-000158 - Unspecified file extensions on a production IIS 10.0 web server must be removed.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000158 - Unspecified file extensions on a production IIS 10.0 web server must be removed.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT

IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.DISA IIS 10.0 Server v2r10Windows

CONFIGURATION MANAGEMENT

IIST-SV-000159 - The IIS 10.0 web server must have a global authorization rule configured to restrict access.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

CONFIGURATION MANAGEMENT