Item Search

NameAudit NamePluginCategory
1.8 Ensure 'Attachment Filtering Agent' is configuredCIS Microsoft Exchange Server 2019 L1 Edge v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.5 Disable client facing Stack TracesCIS Apache Tomcat 11 v1.0.0 L1Unix

CONFIGURATION MANAGEMENT

2.5 Disable client facing Stack TracesCIS Apache Tomcat 10 L1 v1.1.0 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

2.5 Disable client facing Stack TracesCIS Apache Tomcat 10 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.5 Disable client facing Stack TracesCIS Apache Tomcat 10.1 v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.5 Disable client facing Stack Traces - check for defined exception typeCIS Apache Tomcat 9 L1 v1.2.0Unix

CONFIGURATION MANAGEMENT

2.5 Disable client facing Stack Traces - check for defined exception typeCIS Apache Tomcat 8 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.5 Disable client facing Stack Traces - check for defined exception typeCIS Apache Tomcat 8 L1 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

2.5 Disable client facing Stack Traces - check for defined exception typeCIS Apache Tomcat 9 L1 v1.2.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

3.1 Ensure the Apache Web Server Runs As a Non-Root UserCIS Apache HTTP Server 2.4 v2.3.0 L1Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'apache account is configured'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'apache account is configured'CIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'apache account is configured'CIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd services are running as apache user'CIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd services are running as apache user'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd.conf Group = apache'CIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd.conf Group = apache'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd.conf Group = apache'CIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd.conf User = apache'CIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd.conf User = apache'CIS Apache HTTP Server 2.2 L1 v3.6.0Unix

ACCESS CONTROL

3.1 Ensure the Apache Web Server Runs As a Non-Root User - 'httpd.conf User = apache'CIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

ACCESS CONTROL

3.12 Ensure Group Write Access for the Document Root Directories and Files Is Properly RestrictedCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

ACCESS CONTROL

9.1 Starting Tomcat with Security ManagerCIS Apache Tomcat 7 L1 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

9.1 Starting Tomcat with Security ManagerCIS Apache Tomcat 7 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

10.1 Ensure the LimitRequestLine directive is Set to 512 or lessCIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

10.1 Ensure the LimitRequestLine directive is Set to 512 or lessCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

CONFIGURATION MANAGEMENT

10.1 Ensure the LimitRequestLine directive is Set to 8190 or less but not 0CIS Apache HTTP Server 2.4 v2.3.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND INFORMATION INTEGRITY

AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.DISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

AS24-U2-000650 - The Apache web server must set an absolute timeout for sessions.DISA STIG Apache Server 2.4 Unix Site v2r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U2-000650 - The Apache web server must set an absolute timeout for sessions.DISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000640 - The Apache web server must set an absolute timeout for sessions.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL

DISA_F5_BIG-IP_ASM_v2r2.audit from DISA F5 BIG-IP Application Security Manager v2r2 STIGDISA F5 BIG-IP Application Security Manager STIG v2r2F5
DISA_IIS_6.0_Web_Server_v6r16.audit from DISA Microsoft IIS 6.0 Server v6r16 STIGDISA STIG IIS 6.0 Server v6r16Windows
DISA_STIG_BIND_9.x_v3r2.audit from DISA BIND 9.x STIG v3r2DISA BIND 9.x STIG v3r2Unix
DISA_STIG_Cloud_Linux_AlmaLinux_OS_9_v1r7.audit from DISA Cloud Linux AlmaLinux OS 9 STIG v1r7DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix
DISA_STIG_EnterpriseDB_Postgres_Advanced_Server_v2r1_OS_Linux.audit from DISA EnterpriseDB Postgres Advanced Server (EPAS) v2r1 STIGEnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix
DISA_STIG_IBM_WebSphere_Liberty_Server_v2r4.audit from DISA IBM WebSphere Liberty Server STIG v2r4DISA IBM WebSphere Liberty Server STIG v2r4Unix
DISA_STIG_IIS_10.0_Web_Server_v2r10.audit from DISA Microsoft IIS 10.0 Server v2r10 STIGDISA IIS 10.0 Server v2r10Windows
DISA_STIG_JBoss_EAP_6.3_v2r6.audit from DISA JBoss Enterprise Application Platform 6.3 v2r6 STIGDISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix
DISA_STIG_Microsoft_IIS_10.0_Server_v3r7.audit from DISA Microsoft IIS 10.0 Server STIG v3r7DISA Microsoft IIS 10.0 Server STIG v3r7Windows
DISA_STIG_Microsoft_Internet_Explorer_9_v1r15.audit from DISA Microsoft Internet Explorer 9 v1r15 STIGDISA STIG Microsoft Internet Explorer 9 v1r15Windows
DISA_STIG_Microsoft_Windows_Server_2016_v2r10.audit from DISA Microsoft Windows Server 2016 STIG v2r10DISA Microsoft Windows Server 2016 STIG v2r10Windows
DISA_STIG_Microsoft_Windows_Server_2025_v1r1.audit from DISA Microsoft Windows Server 2025 STIG v1r1DISA Microsoft Windows Server 2025 STIG v1r1Windows
DISA_STIG_Oracle_HTTP_Server_12.1.3_v2r3.audit from DISA Oracle HTTP Server 12.1.3 v2r3 STIGDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix
DISA_STIG_Oracle_WebLogic_Server_12c_Linux_v2r2_Middleware.audit from DISA Oracle WebLogic Server 12c v2r2 STIGOracle WebLogic Server 12c Linux v2r2 MiddlewareUnix
DISA_STIG_Oracle_WebLogic_Server_12c_Linux_v2r2.audit from DISA Oracle WebLogic Server 12c v2r2 STIGOracle WebLogic Server 12c Linux v2r2Unix
DISA_STIG_Oracle_WebLogic_Server_12c_Windows_v2r2.audit from DISA Oracle WebLogic Server 12c v2r2 STIGOracle WebLogic Server 12c Windows v2r2Windows
DISA_STIG_Red_Hat_Enterprise_Linux_9_v2r9.audit from DISA Red Hat Enterprise Linux 9 STIG v2r9DISA Red Hat Enterprise Linux 9 STIG v2r9Unix
F5BI-AP-000235 - The F5 BIG-IP appliance APM Access Policies that grant access to web application resources must allow only client certificates that have the User Persona Name (UPN) value in the User Persona Client Certificates.DISA F5 BIG-IP Access Policy Manager STIG v2r4F5

SYSTEM AND COMMUNICATIONS PROTECTION