Item Search

NameAudit NamePluginCategory
2.11 Implement Connection Delays to Limit Failed Login Attempts - connection_control_failed_connections_thresholdCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.11 Implement Connection Delays to Limit Failed Login Attempts - CONNECTION_CONTROL_FAILED_LOGIN_ATTEMPTSCIS MySQL 5.6 Community Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.11 Implement Connection Delays to Limit Failed Login Attempts - CONNECTION_CONTROL_FAILED_LOGIN_ATTEMPTSCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.11 Implement Connection Delays to Limit Failed Login Attempts - connection_control_max_connection_delayCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.11 Implement Connection Delays to Limit Failed Login Attempts - connection_control_min_connection_delayCIS MySQL 5.6 Community Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.11 Implement Connection Delays to Limit Failed Login Attempts - connection_control_min_connection_delayCIS MySQL 5.6 Enterprise Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.15 Implement Connection Delays to Limit Failed Login Attempts - connection_control_min_connection_delayCIS MySQL 5.7 Community Database L1 v2.0.0MySQLDB

ACCESS CONTROL

2.18 Implement Connection Delays to Limit Failed Login AttemptsCIS Oracle MySQL Community Server 9.7 v1.0.0 L1 MySQL RDBMS on Linux MySQLDBMySQLDB

ACCESS CONTROL

APPL-12-000002 - The macOS system must retain the session lock until the user reestablishes access using established identification and authentication procedures.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000003 - The macOS system must initiate the session lock no more than five seconds after a screen saver is started.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000004 - The macOS system must initiate a session lock after a 15-minute period of inactivity.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000006 - The macOS system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000023 - The macOS system must display the Standard Mandatory DoD Notice and Consent Banner before granting remote access to the operating system.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000025 - The macOS system must be configured so that any connection to the system must display the Standard Mandatory DoD Notice and Consent Banner before granting GUI access to the system.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000052 - The macOS system must be configured with the SSH daemon ClientAliveCountMax option set to 1.DISA STIG Apple macOS 12 v1r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-000053 - The macOS system must be configured with the SSH daemon LoginGraceTime set to 30 or less.DISA STIG Apple macOS 12 v1r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-000056 - The macOS system must implement approved Key Exchange Algorithms within the SSH server configuration.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-000057 - The macOS system must implement approved ciphers within the SSH client configuration to protect the confidentiality of SSH connections.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-000058 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH client configuration.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-000059 - The macOS system must implement approved Key Exchange Algorithms within the SSH client configuration.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-001002 - The macOS system must monitor remote access methods and generate audit records when successful/unsuccessful attempts to access/modify privileges occur.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

APPL-12-001013 - The macOS system must be configured with audit log folders owned by root.DISA STIG Apple macOS 12 v1r9Unix

AUDIT AND ACCOUNTABILITY

APPL-12-001016 - The macOS system must be configured with audit log files set to mode 440 or less permissive.DISA STIG Apple macOS 12 v1r9Unix

AUDIT AND ACCOUNTABILITY

APPL-12-001017 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.DISA STIG Apple macOS 12 v1r9Unix

AUDIT AND ACCOUNTABILITY

APPL-12-002003 - The macOS system must be configured to disable the Network File System (NFS) daemon unless it is required.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002004 - The macOS system must be configured to disable Location Services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002009 - The macOS system must be configured to disable AirDrop.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002013 - The macOS system must be configured to disable the iCloud Reminders services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002014 - The macOS system must be configured to disable iCloud Address Book services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002015 - The macOS system must be configured to disable the Mail iCloud services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002016 - The macOS system must be configured to disable the iCloud Notes services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002017 - The macOS system must cover or disable the built-in or attached camera when not in use.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-002031 - The macOS system must be configured to disable the system preference pane for Apple ID.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002037 - The macOS system must be configured to disable the Cloud Storage Setup services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002039 - The macOS system must be configured to disable the Siri Setup services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002041 - The macOS system must disable iCloud document synchronization.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002051 - The macOS system must be configured to disable the system preference pane for TouchID.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002064 - The macOS system must have the security assessment policy subsystem enabled.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002066 - The macOS system must not allow an unattended or automatic logon to the system.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive.DISA STIG Apple macOS 12 v1r9Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-12-005051 - The macOS system must restrict the ability to utilize external writeable media devices.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

APPL-12-005058 - The macOS system must be configured to prevent activity continuation between Apple Devices.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-005060 - The macOS system must be configured to prevent password proximity sharing requests from nearby Apple Devices.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

GOOG-12-006600 - Google Android 12 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-006600 - Google Android 12 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-006600 - Google Android 12 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-010100 - The Google Android 12 Work Profile must be configured to prevent users from adding personal email accounts to the work email app.MobileIron - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-010400 - Google Android 12 work profile must be configured to disable automatic completion of work space Internet browser text input.MobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT