Item Search

NameAudit NamePluginCategory
1.2 Disable Unused ConnectorsCIS Apache Tomcat 7 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

1.12 UBTU-24-100310CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.28 AZLX-23-001045CIS Amazon Linux 2023 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.166 SOL-11.1-070130CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.175 SOL-11.1-070200CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.3.3 Familiarize users with screen lock tools or corner to Start Screen SaverCIS Apple macOS 10.13 L1 v1.1.0Unix

ACCESS CONTROL

3.1.2.1 Configure BGP to Log Neighbor ChangesCIS Cisco NX-OS v1.2.0 L1Cisco

CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iOS 10 v2.0.0 End User Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.2 Ensure 'Software Update' returns 'Your software is up to date.'AirWatch - CIS Apple iOS 10 v2.0.0 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.2 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iOS 11 v1.0.0 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.2 Ensure 'Software Update' returns 'Your software is up to date.'AirWatch - CIS Apple iOS 12 v1.0.0 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.2 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iOS 13 and iPadOS 13 v1.0.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT

4.2 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iOS 11 v1.0.0 End User Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'AirWatch - CIS Apple iPadOS 26 v1.0.0 L1 End User OwnedMDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally OwnedMDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iPadOS 18 v2.0.0 L1 Institution OwnedMDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'AirWatch - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally OwnedMDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'AirWatch - CIS Apple iOS 17 Institution Owned L1MDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iOS 18 v2.0.0 L1 End User OwnedMDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'AirWatch - CIS Apple iOS 26 Benchmark v1.0.0 L1 End User OwnedMDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iPadOS 17 Institutionally Owned L1MDM

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

5.17 Ensure HTTP Header Referrer-Policy is set appropriatelyCIS Apache HTTP Server 2.4 v2.3.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.2.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.9 Ensure events that modify /etc/NetworkManager directory are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.2.3.15 Ensure events that modify /etc/pam.d/ information are collectedCIS SUSE Linux Enterprise 16 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.16 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Debian Linux 13 v1.1.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.16 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Ubuntu Linux 26.04 LTS v1.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.3.3.2 Ensure actions as another user are always loggedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.3.3.2 Ensure actions as another user are always loggedCIS Rocky Linux 10 v1.0.0 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.3.3.2 Ensure actions as another user are always loggedCIS AlmaLinux OS 10 v1.0.0 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS AlmaLinux OS 10 v1.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 ServerUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.3.3.5 Ensure events that modify sethostname and setdomainname are collectedCIS Red Hat Enterprise Linux 10 v1.0.1 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

6.5.1 Ensure modern authentication for Exchange Online is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

CNTR-K8-002000 - The Kubernetes API server must have the ValidatingAdmissionWebhook enabled.DISA Kubernetes STIG v2r6Unix

ACCESS CONTROL

DTAM136 - McAfee VirusScan Unwanted Programs Policies must be configured to detect adware.DISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-MB-000147 - The Exchange malware scanning agent must be configured for automatic updates.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

JBOS-AS-000050 - Silent Authentication must be removed from the Default Management Security Realm.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

JUEX-NM-000590 - The Juniper EX switch must be configured to generate audit records when concurrent logons from different workstations occur.DISA Juniper EX Series Switches Network Device Management STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUSX-DM-000019 - For local accounts, the Juniper SRX Services Gateway must generate an alert message to the management console and generate a log event record that can be forwarded to the ISSO and designated system administrators when local accounts are created.DISA Juniper SRX Services Gateway NDM v3r3Juniper

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

JUSX-DM-000106 - The Juniper SRX Services Gateway must generate an alarm or send an alert message to the management console when a component failure is detected.DISA Juniper SRX Services Gateway NDM v3r3Juniper

CONFIGURATION MANAGEMENT

JUSX-IP-000018 - The Juniper Networks SRX Series Gateway IDPS must protect against or limit the effects of known and unknown types of Denial of Service (DoS) attacks by employing anomaly-based detection.DISA Juniper SRX Services Gateway IDPS v2r1Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-VN-000028 - The Juniper SRX Services Gateway VPN must disable split-tunneling for remote clients VPNs.DISA Juniper SRX Services Gateway VPN v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

O112-C2-019600 - The DBMS must verify there have not been unauthorized changes to the DBMS software and information.DISA STIG Oracle 11.2g v2r5 DatabaseOracleDB

CONFIGURATION MANAGEMENT

SOL-11.1-070130 - Reserved UIDs 0-99 must only be used by system accounts.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-090280 - The operating system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.DISA Solaris 11 X86 STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SOL-11.1-090280 - The operating system must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.DISA Solaris 11 SPARC STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-000960 - The WebSphere Application Server must be run as a non-admin user.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

CONFIGURATION MANAGEMENT