Item Search

NameAudit NamePluginCategory
1.1.18 - MobileIron - Limit the 'number of messages' for 'Text message limit'MobileIron - CIS Google Android 4 v1.0.0 L2MDM

ACCESS CONTROL

8.4.1 Set 'Java permissions' to 'Enabled:Disable Java'CIS IE 10 v1.1.0Windows

CONFIGURATION MANAGEMENT

18.10.92.1.1 (L1) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'CIS Microsoft Windows 10 Stand-alone v3.0.0 L1 BL NGWindows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

18.10.92.1.1 (L1) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'CIS Microsoft Windows Server 2016 v3.0.0 L1 MSWindows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

18.10.93.1.1 (L1) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'CIS Windows Server 2012 MS L1 v3.0.0Windows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

18.10.93.1.1 (L1) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v4.0.0 L1 BLWindows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

18.10.93.1.1 (L1) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'CIS Microsoft Windows Server 2022 v4.0.0 L1 DCWindows

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

AIX7-00-001003 - AIX must enforce the limit of three consecutive invalid login attempts by a user before the user account is locked and released by an administrator.DISA STIG AIX 7.x v3r1Unix

ACCESS CONTROL

AIX7-00-001008 - All accounts on AIX system must have unique account names.DISA STIG AIX 7.x v3r1Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001030 - AIX system must prevent the root account from directly logging in except from the system console.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-001032 - AIX administrative accounts must not run a web browser, except as needed for local service administration.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-001033 - AIX default system accounts (with the exception of root) must not be listed in the cron.allow file or must be included in the cron.deny file, if cron.allow does not exist.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-001039 - The AIX root accounts home directory (other than /) must have mode 0700.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-001043 - The Department of Defense (DoD) login banner must be displayed during SSH, sftp, and scp login sessions on AIX.DISA STIG AIX 7.x v3r1Unix

ACCESS CONTROL

AIX7-00-001048 - AIX must protect the confidentiality and integrity of all information at rest.DISA STIG AIX 7.x v3r1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-001053 - AIX must provide time synchronization applications that can synchronize the system clock to external time sources at least every 24 hours.DISA STIG AIX 7.x v3r1Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-001055 - All AIX NFS anonymous UIDs and GIDs must be configured to values without permissions.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-001104 - If LDAP authentication is required on AIX, SSL must be used between LDAP clients and the LDAP servers to protect the integrity of remote access sessions.DISA STIG AIX 7.x v3r1Unix

ACCESS CONTROL

AIX7-00-001134 - The password hashes stored on AIX system must have been generated using a FIPS 140-2 approved cryptographic hashing algorithm.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-001137 - AIX must be able to control the ability of remote login for users.DISA STIG AIX 7.x v3r1Unix

ACCESS CONTROL

AIX7-00-002001 - AIX must produce audit records containing information to establish what the date, time, and type of events that occurred.DISA STIG AIX 7.x v3r1Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002017 - AIX must be configured so that the audit system takes appropriate action when the audit storage volume is full.DISA STIG AIX 7.x v3r1Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002025 - AIX audit tools must be owned by root.DISA STIG AIX 7.x v3r1Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002036 - AIX must provide a report generation function that supports on-demand audit review and analysis, on-demand reporting requirements, and after-the-fact investigations of security incidents.DISA STIG AIX 7.x v3r1Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002038 - AIX must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).DISA STIG AIX 7.x v3r1Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002064 - IP forwarding for IPv4 must not be enabled on AIX unless the system is a router.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002072 - AIX system files, programs, and directories must be group-owned by a system group.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002077 - The inetd.conf file on AIX must be owned by root.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002079 - AIX audio devices must be group-owned by root, sys, bin, or system.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002088 - AIX library files must have mode 0755 or less permissive.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002111 - AIX SSH daemon must be configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002112 - The AIX SSH daemon must be configured for IP filtering.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002113 - The AIX SSH daemon must not allow compression.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002115 - AIX must turn on SSH daemon reverse name checking.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002117 - AIX must turn off X11 forwarding for the SSH daemon.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002122 - The AIX SSH daemon must be configured to not use host-based authentication.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002123 - The AIX SSH daemon must not allow RhostsRSAAuthentication.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002131 - AIX must implement a remote syslog server that is documented using site-defined procedures.DISA STIG AIX 7.x v3r1Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

AIX7-00-002132 - The AIX syslog daemon must not accept remote messages unless it is a syslog server documented using site-defined procedures.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002133 - AIX must be configured to use syslogd to log events by TCPD.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002142 - The AIX /etc/hosts file must have a mode of 0640 or less permissive.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-002150 - The AIX cron and crontab directories must be group-owned by cron.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-003028 - AIX must remove all software components after updated versions have been installed.DISA STIG AIX 7.x v3r1Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-003041 - The AIX rlogind service must be disabled.DISA STIG AIX 7.x v3r1Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003044 - If AIX system does not support either local or remote printing, the piobe service must be disabled.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-003046 - If NFS is not required on AIX, the NFS daemon must be disabled.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-003049 - The AIX DHCP client must be disabled.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-003050 - If DHCP is not enabled in the network on AIX, the dhcprd daemon must be disabled.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

AIX7-00-003053 - If AIX server is not functioning as a multicast router, the mrouted daemon must be disabled.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

PPS9-00-012800 - The EDB Postgres Advanced Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to generate and validate cryptographic hashes.EDB PostgreSQL Advanced Server OS Linux Audit v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION