| 5.1.2 Ensure System Integrity Protection Status (SIP) Is Enabled | CIS Apple macOS 10.15 Catalina v3.0.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 5.19 System Integrity Protection status | CIS Apple macOS 10.13 L1 v1.1.0 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 8.2 Disable JAR from Opening Unsafe File Types | CIS Mozilla Firefox 38 ESR Linux L1 v1.0.0 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-000500 - RHEL 10 must enable FIPS mode. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200020 - RHEL 10 must not have the "telnet-server" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200030 - RHEL 10 must not have the "gssproxy" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200040 - RHEL 10 must not have the tuned package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200050 - RHEL 10 must not have a Trivial File Transfer Protocol (TFTP) server package installed unless it is required by the mission, and if required, the TFTP daemon must be configured to operate in secure mode. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200530 - RHEL 10 must have the "firewalld" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200560 - RHEL 10 must have the USBGuard package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-200632 - RHEL 10 must use a file integrity tool that is configured to use FIPS 140-3-approved cryptographic hashes for validating file contents and directories. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200634 - RHEL 10 must be configured so that the file integrity tool verifies Access Control Lists (ACLs). | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200640 - RHEL 10 must have the "rsyslog" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-200647 - RHEL 10 must monitor all remote access methods. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-200650 - RHEL 10 must have the packages required for encrypting off-loaded audit logs installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-200691 - RHEL 10 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) of an audit processing failure. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-200700 - RHEL 10 must have the "cronie" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200720 - RHEL 10 must have a Secure Shell (SSH) server installed for all networked systems. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-200722 - RHEL 10 must have the "openssh-clients" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-200740 - RHEL 10 must have the "gnutls-utils" package installed. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-300050 - RHEL 10 must be configured so that Secure Shell (SSH) clients use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, MAINTENANCE |
| RHEL-10-300060 - RHEL 10 must be configured so that Secure Shell (SSH) servers use only DOD-approved Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL, MAINTENANCE |
| RHEL-10-300080 - RHEL 10 must implement DOD-approved encryption in the bind package. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-400030 - RHEL 10 must be configured so that the "/etc/gshadow-" file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400040 - RHEL 10 must be configured so that the "/etc/passwd" file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400050 - RHEL 10 must be configured so that the "/etc/passwd-" file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400060 - RHEL 10 must be configured so that the "/etc/shadow" file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400070 - RHEL 10 must be configured so that the "/etc/shadow-" file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400095 - RHEL 10 must be configured so that the "/var/log/messages" file is group-owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-400115 - RHEL 10 must be configured so that library files are group-owned by "root" or a system account. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-400130 - RHEL 10 must be configured so that cron configuration file directories are owned by root. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-400155 - RHEL 10 must be configured so that the Secure Shell (SSH) server configuration file is owned by "root". | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400220 - RHEL 10 must enforce mode "0755" or less permissive for the "/var/log" directory. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-400230 - RHEL 10 must be configured to prohibit modification of permissions for cron configuration files and directories from the operating system defaults. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-400245 - RHEL 10 must enforce mode "0644" or less permissive for the "/etc/group" file to prevent unauthorized access. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400275 - RHEL 10 must enforce mode "0000" or less permissive for "/etc/shadow-" file to prevent unauthorized access. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-400290 - RHEL 10 must be configured so that all local files and directories must have a valid owner. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-701080 - RHEL 10 must enable kernel parameters to enforce discretionary access control (DAC) on symlinks. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | ACCESS CONTROL |
| RHEL-10-701130 - RHEL 10 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-701150 - RHEL 10 must disable core dump backtraces. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-701170 - RHEL 10 must disable core dumps for all users. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | CONFIGURATION MANAGEMENT |
| RHEL-10-701190 - RHEL 10 must implement nonexecutable data to protect its memory from unauthorized code execution. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| RHEL-10-701220 - RHEL 10 must enable certificate-based smart card authentication. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| RHEL-10-800030 - RHEL 10 must disable access to the network bpf system call from nonprivileged processes. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800040 - RHEL 10 must securely compare internal information system clocks at least every 24 hours. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |
| RHEL-10-800080 - RHEL 10 must be configured to use Transmission Control Protocol (TCP) syncookies. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800090 - RHEL 10 must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800260 - RHEL 10 must not accept router advertisements on all Internet Protocol version 6 (IPv6) interfaces by default. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-800270 - RHEL 10 must prevent Internet Protocol version 6 (IPv6) Internet Control Message Protocol (ICMP) redirect messages from being accepted. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| RHEL-10-900000 - RHEL 10 must enforce mode "0640" or less for the "/etc/audit/auditd.conf" file to prevent unauthorized access. | DISA Red Hat Enterprise Linux 10 STIG v1r2 | Unix | AUDIT AND ACCOUNTABILITY |