Item Search

NameAudit NamePluginCategory
1.10 CISC-ND-000280CIS Cisco IOS Router NDM STIG v1.1.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.124 APPL-26-003030CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.126 APPL-15-003020CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

2.1.2 Set 'no cdp run'CIS Cisco IOS 15 L1 v4.1.1Cisco

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny 10.0.0.0'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny 169.254.0.0'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny 192.0.2.0'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny internal networks'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Amazon Linux 2 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Debian Linux 12 v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

AOSX-14-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple Mac OSX 10.14 v2r6Unix

ACCESS CONTROL

AOSX-14-001060 - The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.DISA STIG Apple Mac OSX 10.14 v2r6Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AOSX-15-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple Mac OSX 10.15 v1r10Unix

ACCESS CONTROL

APPL-11-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.DISA STIG Apple macOS 11 v1r8Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.DISA STIG Apple macOS 11 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

APPL-12-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-14-003020 - The macOS system must enforce smart card authentication.DISA Apple macOS 14 Sonoma STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION

APPL-26-003020 - The macOS system must enforce smart card authentication.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

ARST-RT-000040 - The Arista BGP router must be configured to reject inbound route advertisements from a customer edge (CE) router for prefixes that are not allocated to that customer.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

ACCESS CONTROL

ARST-RT-000320 - The PE router must be configured to enforce a Quality-of-Service (QoS) policy in accordance with the QoS GIG Technical Profile.DISA STIG Arista MLS EOS 4.2x Router v2r1Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000760 - The PE router providing MPLS Virtual Private Wire Service (VPWS) must be configured to have the appropriate virtual circuit identification (VC ID) for each attachment circuit.DISA Arista MLS EOS 4.X Router STIG v2r2Arista

CONTINGENCY PLANNING

CISC-ND-000720 - The Cisco router must be configured to terminate all network connections associated with device management after five minutes of inactivity.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001030 - The Cisco router must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001040 - The Cisco router must record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001310 - The Cisco router must be configured to off-load log records onto a different system than the system being audited.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001410 - The Cisco router must be configured to back up the configuration when changes occur.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING

CISC-ND-001450 - The Cisco router must be configured to send log data to at least two syslog servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).DISA Cisco IOS XE Router NDM STIG v3r7Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000010 - The Cisco router must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

ACCESS CONTROL

CISC-RT-000140 - The Cisco router must be configured to drop all fragmented Internet Control Message Protocol (ICMP) packets destined to itself.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000170 - The Cisco router must be configured to have Internet Control Message Protocol (ICMP) unreachable messages disabled on all external interfaces.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000200 - The Cisco router must be configured to log all packets that have been dropped at interfaces via ACL.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000220 - The Cisco router must be configured to produce audit records containing information to establish the source of the events.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000236 - The Cisco switch must be configured to advertise a hop limit of at least 32 in Switch Advertisement messages for IPv6 stateless auto-configuration deployments.DISA Cisco IOS Switch RTR STIG v3r3Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000300 - The Cisco perimeter router must be configured to not redistribute static routes to an alternate gateway service provider into BGP or an IGP peering with the NIPRNet or to other autonomous systems.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000410 - The Cisco out-of-band management (OOBM) gateway router must be configured to forward only authorized management traffic to the Network Operations Center (NOC).DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000430 - The Cisco out-of-band management (OOBM) gateway router must be configured to not redistribute routes between the management network routing domain and the managed network routing domain.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

ACCESS CONTROL

CISC-RT-000490 - The Cisco BGP router must be configured to reject inbound route advertisements for any Bogon prefixes.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000550 - The Cisco BGP router must be configured to reject route advertisements from CE routers with an originating AS in the AS_PATH attribute that does not belong to that customer.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000640 - The Cisco PE router must be configured to have each Virtual Routing and Forwarding (VRF) instance with the appropriate Route Target (RT).DISA Cisco IOS XE Router RTR STIG v3r5Cisco

CONTINGENCY PLANNING

CISC-RT-000650 - The Cisco PE router must be configured to have each VRF with the appropriate Route Distinguisher (RD).DISA Cisco IOS XR Router RTR STIG v3r3Cisco

CONTINGENCY PLANNING

CISC-RT-000700 - The Cisco PE router providing Virtual Private LAN Services (VPLS) must be configured to have traffic storm control thresholds on CE-facing interfaces.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000720 - The Cisco PE router must be configured to limit the number of MAC addresses it can learn for each Virtual Private LAN Services (VPLS) bridge domain.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000850 - The Cisco multicast Rendezvous Point (RP) must be configured to rate limit the number of Protocol Independent Multicast (PIM) Register messages.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000860 - The Cisco multicast Designated Router (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join only multicast groups that have been approved by the organization.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000870 - The Cisco multicast Designated Router (DR) must be configured to filter the Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) Report messages to allow hosts to join a multicast group only from sources that have been approved by the organization.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000930 - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to filter source-active multicast advertisements to external MSDP peers to avoid global visibility of local-only multicast sources and groups.DISA Cisco IOS XR Router RTR STIG v3r3Cisco

ACCESS CONTROL