Item Search

NameAudit NamePluginCategory
1.20 ALMA-09-004320CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

1.21 ALMA-09-004310CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

1.23 ALMA-09-004420CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

1.53 AZLX-23-001225CIS Amazon Linux 2023 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

1.73 ESXI-80-000247CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT II UnixUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

1.79 RHEL-10-300010CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

1.220 RHEL-09-255090CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

1.267 OL09-00-002342CIS Oracle Linux 9 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

1.337 RHEL-10-700650CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

5.3.16 Ensure only FIPS 140-2 ciphers are used for SSHCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

ALMA-09-004310 - AlmaLinux OS 9 must use the TuxCare ESU repository.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-004320 - AlmaLinux OS 9 must use the TuxCare FIPS packages and not the default encryption packages.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-004420 - AlmaLinux OS 9 must enable FIPS mode.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-000054 - The macOS system must implement approved ciphers within the SSH server configuration to protect the confidentiality of SSH connections.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-000055 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH server configuration.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-000056 - The macOS system must implement approved Key Exchange Algorithms within the SSH server configuration.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

ARBA-VN-000220 - AOS, when used as a VPN Gateway, must be configured to use IPsec with SHA-2 at 384 bits or greater for hashing to protect the integrity of remote access sessions.DISA HPE Aruba Networking AOS VPN STIG v1r1ArubaOS

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

ARBA-VN-001090 - AOS, when used as an IPsec VPN Gateway, must use Advanced Encryption Standard (AES) encryption for the Internet Key Exchange (IKE) proposal to protect confidentiality of remote access sessions.DISA HPE Aruba Networking AOS VPN STIG v1r1ArubaOS

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-001225 - Amazon Linux 2023 must force a frequent session key renegotiation for SSH connections to the server.DISA Amazon Linux 2023 STIG v1r4Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001140 - The Cisco router must be configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm.DISA Cisco IOS Router NDM STIG v3r8Cisco

ACCESS CONTROL

CISC-ND-001140 - The Cisco switch must be configured to encrypt SNMP messages using a FIPS 140-2 approved algorithm.DISA Cisco IOS XE Switch NDM STIG v3r6Cisco

ACCESS CONTROL

ESXI-65-000010 - The ESXi host SSH daemon must use DoD-approved encryption to protect the confidentiality of remote access sessions.DISA STIG VMware vSphere ESXi OS 6.5 v2r4Unix

ACCESS CONTROL

ESXI-80-000247 - The ESXi host must use DOD-approved encryption to protect the confidentiality of network sessions.DISA VMware vSphere 8.0 ESXi STIG v2r4 UnixUnix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-AP-300003 - The F5 BIG-IP appliance providing intermediary services for remote access must use FIPS-validated cryptographic algorithms, including TLS 1.2 at a minimum.DISA F5 BIG-IP TMOS ALG STIG v1r3F5

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000203 - A private IIS 10.0 website must only accept Secure Socket Layer (SSL) connections.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

ACCESS CONTROL

JUSX-VN-000005 - The Juniper SRX Services Gateway VPN must use AES256 for the IPsec proposal to protect the confidentiality of remote access sessions.DISA Juniper SRX Services Gateway VPN v3r2Juniper

ACCESS CONTROL

JUSX-VN-000006 - The Juniper SRX Services Gateway VPN must use AES256 encryption for the Internet Key Exchange (IKE) proposal to protect the confidentiality of remote access sessions - IKE proposal to protect the confidentiality of remote access sessions.DISA Juniper SRX Services Gateway VPN v3r2Juniper

ACCESS CONTROL

JUSX-VN-000007 - The Juniper SRX Services Gateway VPN must be configured to use Diffie-Hellman (DH) group 15 or higher - DH group.DISA Juniper SRX Services Gateway VPN v3r2Juniper

ACCESS CONTROL

Monterey - Configure SSHD to Use Secure Key Exchange AlgorithmsNIST macOS Monterey v1.0.0 - All ProfilesUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

OL09-00-002342 - OL 9 must force a frequent session key renegotiation for SSH connections to the server.DISA Oracle Linux 9 STIG v1r6Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-09-255090 - RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.DISA Red Hat Enterprise Linux 9 STIG v2r9Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-300010 - RHEL 10 must implement a FIPS 140-3-compliant systemwide cryptographic policy.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-700650 - RHEL 10 must force a frequent session key renegotiation for Secure Shell (SSH) connections to the server.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

SLEM-05-255045 - SLEM 5 must implement DOD-approved encryption to protect the confidentiality of SSH remote connections.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

ACCESS CONTROL, MAINTENANCE

SP13-00-000015 - SharePoint must utilize approved cryptography to protect the confidentiality of remote access sessions.DISA Microsoft SharePoint 2013 STIG v2r4Windows

ACCESS CONTROL

SRG-OS-000033-ESXI5 - The operating system must use cryptography to protect the confidentiality of remote access sessions.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

ACCESS CONTROL

UBTU-20-010044 - The Ubuntu operating system must configure the SSH daemon to use FIPS 140-2 approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-22-255050 - Ubuntu 22.04 LTS must configure the SSH daemon to use FIPS 140-3-approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.DISA Canonical Ubuntu 22.04 LTS STIG v2r9Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-24-100820 - Ubuntu 24.04 LTS must configure the SSH daemon to use FIPS 140-3 approved ciphers to prevent the unauthorized disclosure of information and/or detect changes to information during transmission.DISA Canonical Ubuntu 24.04 LTS STIG v1r6Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

VCLD-67-000002 - VAMI must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r3Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

VCLD-70-000002 - VAMI must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.DISA STIG VMware vSphere 7.0 VAMI v1r2Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-000170 - The WebSphere Application Server global application security must be enabledDISA IBM WebSphere Traditional 9 Windows STIG v2r1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

WBSP-AS-000170 - The WebSphere Application Server global application security must be enabledDISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

WN10-CC-000290 - Remote Desktop Services must be configured with the client connection encryption set to the required level.DISA Microsoft Windows 10 STIG v3r6Windows

ACCESS CONTROL, MAINTENANCE

WN12-CC-000100 - Remote Desktop Services must be configured with the client connection encryption set to the required level.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

ACCESS CONTROL, MAINTENANCE

WN12-CC-000100 - Remote Desktop Services must be configured with the client connection encryption set to the required level.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

ACCESS CONTROL, MAINTENANCE

WN16-SO-000430 - Windows Server 2016 must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

WN19-CC-000370 - Windows Server 2019 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications.DISA Microsoft Windows Server 2019 STIG v3r9Windows

ACCESS CONTROL

WN19-CC-000380 - Windows Server 2019 Remote Desktop Services must be configured with the client connection encryption set to High Level.DISA Microsoft Windows Server 2019 STIG v3r9Windows

ACCESS CONTROL

WN25-SH-000050 - Windows Server 2025 OpenSSH must force a frequent session key renegotiation for SSH connections to the server.DISA Microsoft Windows Server 2025 STIG v1r3Windows

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION