2.3.17.4 Ensure 'User Account Control: Detect application installations and prompt for elevation' is set to 'Enabled' | CIS Microsoft Windows 8.1 v2.4.1 L1 | Windows | CONFIGURATION MANAGEMENT |
3. OpenStack Compute - Policy.json - 'os_compute_api:os-assisted-volume-snapshots:create' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
6. OpenStack Compute - Policy.json - 'os_compute_api:os-aggregates:delete' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
10. OpenStack Compute - Policy.json - 'os_compute_api:os-console-auth-tokens' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
11. OpenStack Compute - Policy.json - 'os_compute_api:os-lock-server:unlock' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
12. OpenStack Identity - Policy.json - 'identity:delete_identity_provider' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
18. OpenStack Compute - Policy.json - 'compute_extension:flavor_access:removeTenantAccess' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
26. OpenStack Compute - Policy.json - 'compute_extension:admin_actions' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
30. OpenStack Compute - Policy.json - 'os_compute_api:os-pci:detail' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
32. OpenStack Compute - Policy.json - 'os_compute_api:os-cells:create' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
36. OpenStack Compute - Policy.json - 'os_compute_api:os-admin-actions:reset_network' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
42. OpenStack Compute - Policy.json - 'os_compute_api:os-cells:update' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
43. OpenStack Compute - Policy.json - 'os_compute_api:os-hypervisors' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
52. OpenStack Compute - Policy.json - 'os_compute_api:ips:show' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
65. OpenStack Compute - Policy.json - 'os_compute_api:os-quota-sets:delete' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
66. OpenStack Compute - Policy.json - 'os_compute_api:os-pci:show' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
67. OpenStack Compute - Policy.json - 'os_compute_api:os-pause-server:pause' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
69. OpenStack Compute - Policy.json - 'os_compute_api:os-hide-server-addresses' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
85. OpenStack Compute - Policy.json - 'compute_extension:console_auth_tokens' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
88. OpenStack Compute - Policy.json - 'compute_extension:cloudpipe' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
89. OpenStack Compute - Policy.json - 'os_compute_api:servers:start' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
100. OpenStack Identity - Policy.json - 'identity:list_policies' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
102. OpenStack Identity - Policy.json - 'identity:list_endpoints_associated_with_endpoint_group' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
105. OpenStack Compute - Policy.json - 'os_compute_api:os-flavor-extra-specs:delete' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
108. OpenStack Compute - Policy.json - 'admin_or_owner' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
111. OpenStack Compute - Policy.json - 'os_compute_api:os-aggregates:add_host' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
111. OpenStack Identity - Policy.json - 'owner' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
117. OpenStack Compute - Policy.json - 'compute_extension:floating_ips_bulk' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
119. OpenStack Identity - Policy.json - 'identity:revocation_list' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
121. OpenStack Identity - Policy.json - 'identity:delete_service_provider' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
122. OpenStack Compute - Policy.json - 'compute_extension:admin_actions:resume' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
125. OpenStack Identity - Policy.json - 'identity:get_domain_config' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
126. OpenStack Identity - Policy.json - 'identity:update_group' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
127. OpenStack Compute - Policy.json - 'compute_extension:admin_actions:createBackup' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
129. OpenStack Identity - Policy.json - 'identity:create_service' | TNS OpenStack Keystone/Identity Security Guide | Unix | ACCESS CONTROL |
145. OpenStack Compute - Policy.json - 'os_compute_api:server-metadata:update_all' | TNS OpenStack Nova/Compute Security Guide | Unix | ACCESS CONTROL |
ACLs: Filter for RFC 3330 addresses (192.0.2.0/24) | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | SYSTEM AND COMMUNICATIONS PROTECTION |
ACLs: Filter for RFC 3330 addresses (240.0.0.0/4) | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | SYSTEM AND COMMUNICATIONS PROTECTION |
Authentication: local authentication is available as a last resort | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | IDENTIFICATION AND AUTHENTICATION |
BGP: Disable Capability Negotiation | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | SYSTEM AND COMMUNICATIONS PROTECTION |
CPM Filtering: Filter for ICMP - echo-reply | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | SYSTEM AND COMMUNICATIONS PROTECTION |
EX16-ED-002400 - The application must update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy and procedures. | DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6 | Windows | SYSTEM AND INFORMATION INTEGRITY |
GEN006560 - The system vulnerability assessment tool, host-based intrusion detection tool, and file integrity tool must notify the SA and the IAO of a security breach or a suspected security breach. | DISA STIG Solaris 10 X86 v2r4 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
ICMP: Do not return Proxy ARP requests | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | SYSTEM AND COMMUNICATIONS PROTECTION |
PANW-IP-000033 - To protect against unauthorized data mining, the Palo Alto Networks security platform must detect and prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code. | DISA STIG Palo Alto IDPS v3r2 | Palo_Alto | ACCESS CONTROL |
Password Complexity: Require a minimum length of 8 characters | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | IDENTIFICATION AND AUTHENTICATION |
SNMP: Use SNMPv3 only | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | IDENTIFICATION AND AUTHENTICATION |
Time: System has a primary NTP server set | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | AUDIT AND ACCOUNTABILITY |
TiMOS/SR-OS : OS Version is up to date | TNS Alcatel-Lucent TiMOS/Nokia SR-OS Best Practice Audit | Alcatel | CONFIGURATION MANAGEMENT |
TNS_IBM_HTTP_Server_Linux_Best_Practice.audit | TNS IBM HTTP Server Best Practice | Unix | |