Item Search

NameAudit NamePluginCategory
ARST-ND-000690 - The Arista network devices must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA Arista MLS EOS 4.X NDM STIG v2r2Arista

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

ARST-ND-000690 - The Arista network devices must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA STIG Arista MLS EOS 4.2x NDM v2r1Arista

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

CISC-ND-001200 - The Cisco switch must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA Cisco NX OS Switch NDM STIG v3r6Cisco

MAINTENANCE

CISC-ND-001210 - The Cisco router must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA Cisco IOS Router NDM STIG v3r8Cisco

MAINTENANCE

CISC-ND-001210 - The Cisco router must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA Cisco IOS XR Router NDM STIG v3r6Cisco

MAINTENANCE

CISC-ND-001210 - The Cisco switch must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA Cisco IOS XE Switch NDM STIG v3r6Cisco

MAINTENANCE

CISC-ND-001370 - The Cisco router must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.DISA Cisco IOS Router NDM STIG v3r8Cisco

CONFIGURATION MANAGEMENT

CISC-ND-001370 - The Cisco router must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.DISA Cisco IOS XE Router NDM STIG v3r7Cisco

CONFIGURATION MANAGEMENT

CISC-ND-001450 - The Cisco router must be configured to send log data to at least two syslog servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).DISA Cisco IOS XR Router NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001450 - The Cisco router must be configured to send log data to at least two syslog servers for the purpose of forwarding alerts to the administrators and the ISSO.DISA Cisco IOS Router NDM STIG v3r8Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001450 - The Cisco switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).DISA Cisco IOS XE Switch NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-RT-000240 - The Cisco perimeter router must be configured to deny network traffic by default and allow network traffic by exception.DISA Cisco IOS Router RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000240 - The Cisco perimeter router must be configured to deny network traffic by default and allow network traffic by exception.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000310 - The Cisco perimeter switch must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA Cisco NX OS Switch RTR STIG v3r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

EP11-00-000700 - The EDB Postgres Advanced Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

ACCESS CONTROL

IBMW-LS-000770 - Application security must be enabled on the WebSphere Liberty Server.DISA IBM WebSphere Liberty Server STIG v2r4Unix

ACCESS CONTROL

IIST-SI-000242 - The IIS 10.0 private website must employ cryptographic mechanisms (TLS) and require client certificates.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000242 - The IIS 10.0 private website must employ cryptographic mechanisms (TLS) and require client certificates.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-VN-000019 - The Juniper SRX Services Gateway VPN must use multifactor authentication (e.g., DoD PKI) for network access to non-privileged accounts.DISA Juniper SRX Services Gateway VPN v3r2Juniper

IDENTIFICATION AND AUTHENTICATION

MD3X-00-000010 - MongoDB must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA STIG MongoDB Enterprise Advanced 3.x v2r3 OSUnix

ACCESS CONTROL

O121-C1-019700 - The DBMS must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures.DISA Oracle Database 12c STIG v3r5 WindowsWindows

SYSTEM AND COMMUNICATIONS PROTECTION

O365-CO-000002 - Document metadata for rights managed Office Open XML files must be protected.DISA Microsoft Office 365 ProPlus STIG v3r5Windows

SYSTEM AND COMMUNICATIONS PROTECTION

OH12-1X-000008 - OHS must have the SSLFIPS directive enabled to encrypt remote connections in accordance with the categorization of data hosted by the web server.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OH12-1X-000011 - OHS must have the LoadModule ossl_module directive enabled to protect the integrity of remote sessions in accordance with the categorization of data hosted by the web server.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OH12-1X-000014 - OHS must have the SSLCipherSuite directive enabled to protect the integrity of remote sessions in accordance with the categorization of data hosted by the web server.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

ACCESS CONTROL

OL6-00-000216 - The rexecd service must not be running - CHKCONFIGDISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000216 - The rexecd service must not be running - PROCESS_CHECKDISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

OL6-00-000239 - The SSH daemon must not allow authentication using an empty password.DISA STIG Oracle Linux 6 v2r7Unix

IDENTIFICATION AND AUTHENTICATION

OS10-NDM-000510 - The Dell OS10 Switch must use FIPS 140-2 approved algorithms for authentication to a cryptographic module.DISA Dell OS10 Switch NDM STIG v1r1Dell_OS10

IDENTIFICATION AND AUTHENTICATION

PPS9-00-000700 - The EDB Postgres Advanced Server must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.EDB PostgreSQL Advanced Server OS Linux Audit v2r3Unix

ACCESS CONTROL

PPS9-00-003300 - The EDB Postgres Advanced Server software installation account must be restricted to authorized users.EDB PostgreSQL Advanced Server DB Audit v2r3PostgreSQLDB

CONFIGURATION MANAGEMENT

RHEL-07-020050 - The Red Hat Enterprise Linux operating system must prevent the installation of software, patches, service packs, device drivers, or operating system components from a repository without verification they have been digitally signed using a certificate that is issued by a Certificate Authority (CA) that is recognized and approved by the organization.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

CONFIGURATION MANAGEMENT

RHEL-10-200090 - RHEL 10 must not have a File Transfer Protocol (FTP) server package installed.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SLEM-05-611080 - SLEM 5 must employ FIPS 140-2/140-3-approved cryptographic hashing algorithms for system authentication.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010180 - The SUSE operating system must not have the telnet-server package installed.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SLES-15-010180 - The SUSE operating system must not have the telnet-server package installed.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

SP13-00-000065 - SharePoint must prevent the execution of prohibited mobile code.DISA Microsoft SharePoint 2013 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

SP13-00-000120 - SharePoint must maintain the confidentiality of information during aggregation, packaging, and transformation in preparation for transmission. When transmitting data, applications need to leverage transmission protection mechanisms such as TLS, SSL VPNs, or IPSec.DISA Microsoft SharePoint 2013 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-05-000153 - Oracle WebLogic must authenticate users individually prior to using a group authenticator.Oracle WebLogic Server 12c Linux v2r2Unix

IDENTIFICATION AND AUTHENTICATION

WBLC-05-000153 - Oracle WebLogic must authenticate users individually prior to using a group authenticator.Oracle WebLogic Server 12c Windows v2r2Windows

IDENTIFICATION AND AUTHENTICATION

WBLC-05-000153 - Oracle WebLogic must authenticate users individually prior to using a group authenticator.Oracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WDNS-SC-000025 - The Windows 2012 DNS Server must not contain zone records that have not been validated in over a year.DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN10-CC-000180 - Autoplay must be turned off for non-volume devices.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT

WN10-UR-000065 - The Debug programs user right must only be assigned to the Administrators group.DISA Microsoft Windows 10 STIG v3r6Windows

ACCESS CONTROL

WN12-CC-000074 - Autoplay must be disabled for all drives.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-RG-000002 - Standard user accounts must only have Read permissions to the Active Setup\Installed Components registry key - compatabilityDISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

ACCESS CONTROL

WN16-CC-000270 - AutoPlay must be disabled for all drives.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN16-MS-000010 - Only administrators responsible for the member server or standalone or nondomain-joined system must have Administrator rights on the system.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL

WN16-UR-000090 - The Create a token object user right must not be assigned to any groups or accounts.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL

WN19-DC-000080 - Windows Server 2019 Active Directory SYSVOL directory must have the proper access control permissions.DISA Microsoft Windows Server 2019 STIG v3r8Windows

ACCESS CONTROL