Item Search

NameAudit NamePluginCategory
5.1.2 Ensure System Integrity Protection Status (SIP) Is EnabledCIS Apple macOS 10.15 Catalina v3.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

5.19 System Integrity Protection statusCIS Apple macOS 10.13 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

8.2 Disable JAR from Opening Unsafe File TypesCIS Mozilla Firefox 38 ESR Linux L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

8.7 Secure the permissions of the IBMLDAPSecurity.ini fileCIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS WindowsWindows
9.7 Secure the permission of the SSLconfig.ini fileCIS IBM DB2 v10 v1.1.0 Windows OS Level 1Windows
RHEL-10-000500 - RHEL 10 must enable FIPS mode.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-200020 - RHEL 10 must not have the "telnet-server" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200030 - RHEL 10 must not have the "gssproxy" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200040 - RHEL 10 must not have the tuned package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200050 - RHEL 10 must not have a Trivial File Transfer Protocol (TFTP) server package installed unless it is required by the mission, and if required, the TFTP daemon must be configured to operate in secure mode.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200530 - RHEL 10 must have the "firewalld" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200560 - RHEL 10 must have the USBGuard package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200632 - RHEL 10 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-200634 - RHEL 10 must be configured so that the file integrity tool verifies Access Control Lists (ACLs).DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-200640 - RHEL 10 must have the "rsyslog" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200647 - RHEL 10 must monitor all remote access methods.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-200650 - RHEL 10 must have the packages required for encrypting off-loaded audit logs installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-200691 - RHEL 10 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) of an audit processing failure.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200700 - RHEL 10 must have the "cronie" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200720 - RHEL 10 must have a Secure Shell (SSH) server installed for all networked systems.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-200722 - RHEL 10 must have the "openssh-clients" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-200740 - RHEL 10 must have the "gnutls-utils" package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-300050 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE

RHEL-10-300060 - RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE

RHEL-10-300080 - RHEL 10 must implement DOD-approved encryption in the bind package.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-400030 - RHEL 10 must be configured so that the "/etc/gshadow-" file is owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400040 - RHEL 10 must be configured so that the "/etc/passwd" file is owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-400050 - RHEL 10 must be configured so that the "/etc/passwd-" file is owned by "root".DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700185 - RHEL 10 must mount "/var/tmp" with the "nodev" option.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-700500 - RHEL 10 must be configured so that Secure Shell (SSH) public host key files have mode "0644" or less permissive.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-700700 - RHEL 10 must prevent a user from overriding the disabling of the graphical user interface automount function.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-700790 - RHEL 10 must conceal, via the session lock, information previously visible on the display with a publicly viewable image.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700870 - RHEL 10 must disable wireless network adapters.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-700930 - RHEL 10 must be configured with a timeout interval for the Secure Shell (SSH) daemon.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-700950 - RHEL 10 must disable the systemd Ctrl-Alt-Delete burst key sequence.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-700960 - RHEL 10 must disable the x86 Ctrl-Alt-Delete key sequence.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-701020 - RHEL 10 must enable mitigations against processor-based vulnerabilities.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

RHEL-10-701080 - RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL

RHEL-10-701130 - RHEL 10 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-701150 - RHEL 10 must disable core dump backtraces.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-701170 - RHEL 10 must disable core dumps for all users.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT

RHEL-10-701190 - RHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

RHEL-10-701220 - RHEL 10 must enable certificate-based smart card authentication.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-10-800030 - RHEL 10 must disable access to the network bpf system call from nonprivileged processes.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800040 - RHEL 10 must securely compare internal information system clocks at least every 24 hours.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-800080 - RHEL 10 must be configured to use Transmission Control Protocol (TCP) syncookies.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800090 - RHEL 10 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800260 - RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces by default.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-800270 - RHEL 10 must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

RHEL-10-900000 - RHEL 10 must enforce mode "0640" or less for the "/etc/audit/auditd.conf" file to prevent unauthorized access.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY