Item Search

NameAudit NamePluginCategory
1.4 APPL-15-000005CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix

ACCESS CONTROL

1.6 CISC-ND-000280CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT IICisco

AUDIT AND ACCOUNTABILITY

1.8 SSH Strong Algorithm - b) Disable encryption 3des-cbcTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - e) Disable encryption aes256-cbcTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - f) Disable encryption blowfish-cbcTenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - i) Disable diffie-hellman group-exchange-sha1Tenable ZTE ROSNG Best PracticesZTE_ROSNG
1.8 SSH Strong Algorithm - k) Disable hmac sha1Tenable ZTE ROSNG Best PracticesZTE_ROSNG
1.51 APPL-14-001060CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.51 APPL-26-001060CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.52 APPL-15-001060CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.71 CISC-RT-000690CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IIICisco

CONFIGURATION MANAGEMENT

1.156 ALMA-09-020260CIS Cloud Linux AlmaLinux OS 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.184 RHEL-09-253020CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.348 OL08-00-040261CIS Oracle Linux 8 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.426 OL09-00-006021CIS Oracle Linux 9 STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.1.7 Set 'no service pad'CIS Cisco IOS XE 16.x v2.2.0 L1Cisco

CONFIGURATION MANAGEMENT

2.1.7 Set 'no service pad'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.2.2 Ensure authentication-type is set to MD5CIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS Red Hat Enterprise Linux 8 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS Rocky Linux 8 v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS Oracle Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Ubuntu Linux 22.04 LTS v3.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Oracle Linux 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Rocky Linux 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Oracle Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Red Hat Enterprise Linux 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Red Hat Enterprise Linux 8 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Rocky Linux 10 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS AlmaLinux OS 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS AlmaLinux OS 8 v4.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

AOSX-14-003005 - The macOS system must map the authenticated identity to the user or group account for PKI-based authentication.DISA STIG Apple Mac OSX 10.14 v2r6Unix

IDENTIFICATION AND AUTHENTICATION

APPL-13-001060 - The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DOD PKI-established certificate authorities for verification of the establishment of protected sessions.DISA STIG Apple macOS 13 v1r5Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-13-003001 - The macOS system must issue or obtain public key certificates under an appropriate certificate policy from an approved service provider.DISA STIG Apple macOS 13 v1r5Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-26-000005 - The macOS system must configure user session lock when a smart token is removed.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-001060 - The macOS system must set smart card certificate trust to moderate.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000580 - The Cisco BGP switch must be configured to use its loopback address as the source address for iBGP peering sessions.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

Ensure IP forwarding is disabled - /etc/sysctlTenable Cisco Firepower Management Center OS Best Practices AuditUnix

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure IP forwarding is disabled - sysctlTenable Cisco Firepower Management Center OS Best Practices AuditUnix

SYSTEM AND COMMUNICATIONS PROTECTION

EX19-MB-000007 - Exchange must use encryption for Outlook Web App (OWA) access.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r3Windows

ACCESS CONTROL

GEN005600 - IP forwarding for IPv4 must not be enabled, unless the system is a router.DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN005600 - IP forwarding for IPv4 must not be enabled, unless the system is a router.DISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN005610 - The system must not have IP forwarding for IPv6 enabled unless the system is an IPv6 router - 'net.ipv6.conf.all.forwarding'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

CONFIGURATION MANAGEMENT

GEN005610 - The system must not have IP forwarding for IPv6 enabled, unless the system is an IPv6 router - 'net.ipv6.conf.default.forwarding'DISA STIG for Oracle Linux 5 v2r1Unix

CONFIGURATION MANAGEMENT

GEN005610 - The system must not have IP forwarding for IPv6 enabled, unless the system is an IPv6 router.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

PANW-NM-000110 - The Palo Alto Networks security platform must accept and verify Personal Identity Verification (PIV) credentials - PIV credentialsDISA Palo Alto Networks NDM STIG v3r4Palo_Alto

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

PHTN-67-000129 - The Photon operating system must be configured to offload audit logs to a syslog server.DISA STIG VMware vSphere 6.7 Photon OS v1r6Unix

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

WPAW-00-001000 - The Windows PAW must be configured so that all non-administrative-related applications and functions are blocked or removed from the PAW platform, including but not limited to email, Internet browsing, and line-of-business applications.DISA Microsoft Windows PAW STIG v3r2Windows

CONFIGURATION MANAGEMENT