Item Search

NameAudit NamePluginCategory
1.202 SOL-11.1-090100CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.203 SOL-11.1-090100CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

SYSTEM AND COMMUNICATIONS PROTECTION

3.3.5 Secure the JDK 32-bit runtime libraryCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS WindowsWindows

CONFIGURATION MANAGEMENT

JBOS-AS-000295 - The JBoss Password Vault must be used for storing passwords or other sensitive configuration information.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010019 - The Oracle Linux operating system must ensure cryptographic verification of vendor software packages.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-010040 - The Oracle Linux operating system must display the approved Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a graphical user logon.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL07-00-010061 - The Oracle Linux operating system must uniquely identify and must authenticate users using multifactor authentication via a graphical user logon.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010070 - The Oracle Linux operating system must initiate a screensaver after a 15-minute period of inactivity for graphical user interfaces.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL07-00-010130 - The Oracle Linux operating system must be configured so that when passwords are changed or new passwords are established, the new password must contain at least one lower-case character.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010170 - The Oracle Linux operating system must be configured so that when passwords are changed a minimum of four character classes must be changed.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010200 - The Oracle Linux operating system must be configured so that the PAM system service is configured to store only encrypted representations of passwords.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010260 - The Oracle Linux operating system must be configured so that existing passwords are restricted to a 60-day maximum lifetime.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010300 - The Oracle Linux operating system must be configured so that the SSH daemon does not allow authentication using an empty password.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010339 - The Oracle Linux operating system must specify the default 'include' directory for the /etc/sudoers file - include directory for the /etc/sudoers file.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-010341 - The Oracle Linux operating system must restrict privilege elevation to authorized personnel.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-010344 - The Oracle Linux operating system must not be configured to bypass password requirements for privilege escalation.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010350 - The Oracle Linux operating system must be configured so users must re-authenticate for privilege escalation.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-010430 - The Oracle Linux operating system must be configured so that the delay between logon prompts following a failed console logon attempt is at least four seconds.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-010440 - The Oracle Linux operating system must not allow an unattended or automatic logon to the system via a graphical user interface.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-010450 - The Oracle Linux operating system must not allow an unrestricted logon to the system.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020010 - The Oracle Linux operating system must not have the ypserv package installed.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020028 - The Oracle Linux operating system must be configured to allow sending email notifications of unauthorized configuration changes to designated personnel.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020030 - The Oracle Linux operating system must be configured so that a file integrity tool verifies the baseline operating system configuration at least weekly.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

OL07-00-020040 - The Oracle Linux operating system must be configured so that designated personnel are notified if baseline configurations are changed in an unauthorized manner.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020200 - The Oracle Linux operating system must remove all software components after updated versions have been installed.DISA Oracle Linux 7 STIG v3r5Unix

SYSTEM AND INFORMATION INTEGRITY

OL07-00-020260 - The Oracle Linux operating system security patches and updates must be installed and up to date.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020310 - The Oracle Linux operating system must be configured so that the root account must be the only account having unrestricted access to the system.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020330 - The Oracle Linux operating system must be configured so that all files and directories have a valid group owner.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020680 - The Oracle Linux operating system must be configured so that all files and directories contained in local interactive user home directories have a mode of 0750 or less permissive.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-020900 - The Oracle Linux operating system must be configured so that all system device files are correctly labeled to prevent unauthorized modification.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-021110 - The Oracle Linux operating system must be configured so that the cron.allow file, if it exists, is owned by root.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-021330 - The Oracle Linux operating system must use a separate file system for the system audit data path large enough to hold at least one week of audit data.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-021700 - The Oracle Linux operating system must not allow removable media to be used as the boot loader unless approved.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-030010 - The Oracle Linux operating system must shut down upon audit processing failure, unless availability is an overriding concern. If availability is a concern, the system must alert the designated staff (System Administrator [SA] and Information System Security Officer [ISSO] at a minimum) in the event of an audit processing failure - System Administrator [SA] and Information System Security Officer [ISSO] at a minimum in the event of an audit processing failure.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030320 - The Oracle Linux operating system must be configured so that the audit system takes appropriate action when the audit storage volume is full.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030321 - The Oracle Linux operating system must be configured so that the audit system takes appropriate action when there is an error sending audit records to a remote system.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030620 - The Oracle Linux operating system must generate audit records for all successful account access events.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL07-00-030630 - The Oracle Linux operating system must audit all uses of the passwd command.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030650 - The Oracle Linux operating system must audit all uses of the gpasswd command.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030750 - The Oracle Linux operating system must audit all uses of the umount command.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030871 - The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL07-00-030872 - The Oracle Linux operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL07-00-031000 - The Oracle Linux operating system must send rsyslog output to a log aggregation server.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040100 - The Oracle Linux operating system must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Component Local Service Assessment (PPSM CLSA) and vulnerability assessments - PPSM CLSA and vulnerability assessments.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

OL07-00-040160 - The Oracle Linux operating system must be configured so that all network connections associated with a communication session are terminated at the end of the session or after 15 minutes of inactivity from the user at a command prompt, except to fulfill documented and validated mission requirements.DISA Oracle Linux 7 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL07-00-040300 - The Oracle Linux operating system must be configured so that all networked systems have SSH installed.DISA Oracle Linux 7 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL07-00-040360 - The Oracle Linux operating system must display the date and time of the last successful account logon upon an SSH logon.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL

OL07-00-040370 - The Oracle Linux operating system must not permit direct logons to the root account using remote access via SSH.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040390 - The Oracle Linux operating system must be configured so that the SSH daemon is configured to only use the SSHv2 protocol.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

OL07-00-040400 - The Oracle Linux operating system must be configured so that the SSH daemon is configured to only use Message Authentication Codes (MACs) employing FIPS 140-2 approved cryptographic hash algorithms - MACs employing FIPS 140-2 approved cryptographic hash algorithms.DISA Oracle Linux 7 STIG v3r5Unix

ACCESS CONTROL