Item Search

NameAudit NamePluginCategory
1.4 CISC-RT-000040CIS Cisco NX OS Switch RTR STIG v1.1.0 CAT IICisco

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.4.7 Set 'logging source interface'CIS Cisco IOS XR 7.x v1.0.1 L1Cisco

AUDIT AND ACCOUNTABILITY

1.15 APPL-14-000033CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.15 APPL-15-000033CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.15 CISC-ND-000460CIS Cisco IOS Router NDM STIG v1.1.0 CAT IICisco

CONFIGURATION MANAGEMENT

1.16 CISC-RT-000236CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT IIICisco

CONFIGURATION MANAGEMENT

1.16 CISC-RT-000236CIS Cisco IOS Switch RTR STIG v1.1.0 CAT IIICisco

CONFIGURATION MANAGEMENT

1.50 CISC-RT-000580CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT IIICisco

CONFIGURATION MANAGEMENT

1.52 CISC-RT-000510CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

ACCESS CONTROL

1.70 CISC-RT-000690CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IIICisco

CONFIGURATION MANAGEMENT

1.90 CISC-RT-000890CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.3 Set 'no ip bootp server'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.7 Set 'logging source interface'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

AUDIT AND ACCOUNTABILITY

3.1.1.1 OSPF Passive InterfacesCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security RecommendationsArubaOS

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.1.2 Ensure access profile is set to use CHAPCIS Juniper OS Benchmark v2.1.0 L1Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Default deny configured'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny 192.168.0.0'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny 224.0.0.0'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks - 'Deny host 255.255.255.255'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1 Set 'ip access-list extended' to Forbid Private Source Addresses from External Networks -'External interface has ACL applied'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.2.2 Set inbound 'ip access-group' on the External InterfaceCIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1.9 Ensure net.ipv4.conf.default.accept_redirects is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Debian Linux 13 v1.1.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.3 Ensure net.ipv6.conf.all.accept_redirects is configuredCIS Debian Linux 13 v1.1.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.2.4 Ensure net.ipv6.conf.default.accept_redirects is configuredCIS Ubuntu Linux 26.04 LTS v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

5.2 Ensure SNMPv1/2 are set to Read OnlyCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.21 Ensure ICMP Redirects are Disabled for IPv4CIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

AOSX-14-003025 - The macOS system must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.DISA STIG Apple Mac OSX 10.14 v2r6Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple macOS 11 v1r5Unix

ACCESS CONTROL

APPL-11-001060 - The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities to verify the establishment of protected sessions.DISA STIG Apple macOS 11 v1r5Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-001060 - The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions - PIV credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities to verify the establishment of protected sessions.DISA STIG Apple macOS 12 v1r9Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-14-001060 - The macOS system must set smart card certificate trust to moderate.DISA Apple macOS 14 Sonoma STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-15-000033 - The macOS system must disable FileVault automatic login.DISA Apple macOS 15 Sequoia STIG v1r7Unix

ACCESS CONTROL

APPL-15-001060 - The macOS system must set smart card certificate trust to moderate.DISA Apple macOS 15 Sequoia STIG v1r7Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000040 - The Cisco switch must be configured to use encryption for routing protocol authentication.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

IDENTIFICATION AND AUTHENTICATION

CISC-RT-000236 - The Cisco switch must be configured to advertise a hop limit of at least 32 in Switch Advertisement messages for IPv6 stateless auto-configuration deployments.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

IIST-SV-000142 - The IIS 10.0 web server must restrict inbound connections from non-secure zones.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

ACCESS CONTROL

IIST-SV-000142 - The IIS 10.0 web server must restrict inbound connections from non-secure zones.DISA IIS 10.0 Server v2r10Windows

ACCESS CONTROL

MD3X-00-001100 - MongoDB must be configured in accordance with the security configuration settings based on DoD security configuration and implementation guidance, including STIGs, NSA configuration guides, CTOs, DTMs, and IAVMs.DISA STIG MongoDB Enterprise Advanced 3.x v2r3 OSUnix

CONFIGURATION MANAGEMENT

SPLK-CL-000235 - Splunk Enterprise must notify analysts of applicable events for Tier 2 CSSP and JRSS only.DISA STIG Splunk Enterprise 7.x for Windows v3r2 REST APISplunk

ACCESS CONTROL

TCAT-AS-000970 - Idle timeout for the management application must be set to 10 minutes.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

TCAT-AS-001680 - ALLOW_BACKSLASH must be set to false.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG040 A22 - Public web server resources must not be shared with private assets.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG040 A22 - Public web server resources must not be shared with private assets.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix