Item Search

NameAudit NamePluginCategory
1.2 Use the updated Linux KernelCIS Docker 1.11.0 v1.0.0 L1 LinuxUnix

SYSTEM AND INFORMATION INTEGRITY

1.2 Use the updated Linux KernelCIS Docker 1.6 v1.0.0 L1 LinuxUnix

SYSTEM AND INFORMATION INTEGRITY

1.27 RHEL-10-200530CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.28 RHEL-10-200531CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.141 WN19-CC-000480CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIWindows

MAINTENANCE

1.144 WN19-CC-000510CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIWindows

MAINTENANCE

1.144 WN22-CC-000510CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IIWindows

MAINTENANCE

1.145 WN19-CC-000520CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIWindows

IDENTIFICATION AND AUTHENTICATION

1.145 WN19-CC-000520CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIWindows

IDENTIFICATION AND AUTHENTICATION

1.145 WN22-CC-000520CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IIWindows

IDENTIFICATION AND AUTHENTICATION

1.145 WN22-CC-000520CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IIWindows

IDENTIFICATION AND AUTHENTICATION

1.169 SOL-11.1-070160CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.171 SOL-11.1-070160CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.4 Ensure Passwords are Not Stored in the service fileCIS PostgreSQL 13 v1.3.0 L1 Database UnixUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.4 Ensure Passwords are Not Stored in the service fileCIS PostgreSQL 18 v1.0.0 L1 Database UnixUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.8 Ensure the set_user extension is installedCIS PostgreSQL 14 DB v 1.3.0PostgreSQLDB

ACCESS CONTROL

8.3 Ensure miscellaneous configuration settings are correctCIS PostgreSQL 12 DB v1.1.0PostgreSQLDB

CONFIGURATION MANAGEMENT

8.3 Ensure miscellaneous configuration settings are correctCIS PostgreSQL 14 DB v 1.3.0PostgreSQLDB

CONFIGURATION MANAGEMENT

8.4 Ensure miscellaneous configuration settings are correctCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT

CD12-00-005500 - PostgreSQL must be able to generate audit records when privileges/permissions are retrieved.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-005800 - PostgreSQL must generate audit records for all privileged activities or other system-level access.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-006100 - PostgreSQL must generate audit records when privileges/permissions are deleted.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-006400 - PostgreSQL must generate audit records when privileges/permissions are modified.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD16-00-000200 - PostgreSQL must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

ACCESS CONTROL

CD16-00-008600 - PostgreSQL must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

CD16-00-009400 - PostgreSQL must be able to generate audit records when security objects are accessed.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD16-00-009600 - PostgreSQL must generate audit records when categories of information (e.g., classification levels/security levels) are accessed.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD16-00-009800 - PostgreSQL must generate audit records when privileges/permissions are added.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD16-00-010000 - PostgreSQL must generate audit records when privileges/permissions are modified.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD16-00-010600 - PostgreSQL must generate audit records when privileges/permissions are deleted.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

AUDIT AND ACCOUNTABILITY

PGS9-00-000400 - The audit information produced by PostgreSQL must be protected from unauthorized modification - log filesDISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-000700 - Privileges to change PostgreSQL software modules must be limited.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

CONFIGURATION MANAGEMENT

PGS9-00-000800 - If passwords are used for authentication, PostgreSQL must transmit only encrypted representations of passwords.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

IDENTIFICATION AND AUTHENTICATION

PGS9-00-001300 - The role(s)/group(s) used to modify database structure (including but not necessarily limited to tables, indexes, storage, etc.) and logic modules (functions, trigger procedures, links to software external to PostgreSQL, etc.) must be restricted to authorized users - s used to modify database structure and logic modules must be restricted to authorized users.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

CONFIGURATION MANAGEMENT

PGS9-00-002100 - PostgreSQL must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-002300 - The audit information produced by PostgreSQL must be protected from unauthorized deletion - log directoryDISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-002300 - The audit information produced by PostgreSQL must be protected from unauthorized deletion - log filesDISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-002300 - The audit information produced by PostgreSQL must be protected from unauthorized deletion - log_file_modeDISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-002500 - PostgreSQL must reveal detailed error messages only to the ISSO, ISSM, SA and DBA.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND INFORMATION INTEGRITY

PGS9-00-003100 - Database objects (including but not limited to tables, indexes, storage, trigger procedures, functions, links to software external to PostgreSQL, etc.) must be owned by database/DBMS principals authorized for ownership.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

CONFIGURATION MANAGEMENT

PGS9-00-008000 - PostgreSQL must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to generate and validate cryptographic hashes.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

PGS9-00-008200 - PostgreSQL must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the data owners requirements.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

PGS9-00-008400 - PostgreSQL must prohibit user installation of logic modules (functions, trigger procedures, views, etc.) without explicit privileged status.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

CONFIGURATION MANAGEMENT

PGS9-00-010700 - PostgreSQL must protect its audit features from unauthorized access - LogsDISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-010700 - PostgreSQL must protect its audit features from unauthorized access - roles.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-010700 - PostgreSQL must protect its audit features from unauthorized access.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-011500 - PostgreSQL must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

IDENTIFICATION AND AUTHENTICATION

PGS9-00-012000 - Access to database files must be limited to relevant processes and to authorized, administrative users.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

PGS9-00-012900 - PostgreSQL products must be a version supported by the vendor.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND SERVICES ACQUISITION

SOL-11.1-070160 - User .netrc files must not exist.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT