Item Search

NameAudit NamePluginCategory
1.78 SQLI-22-018100CIS Microsoft SQL Server 2022 Instance STIG v1.0.0 CAT I MS_SQLDBMS_SQLDB

IDENTIFICATION AND AUTHENTICATION

2.1.1 Ensure 'SECURE_CONTROL_' Is Set In 'listener.ora'CIS Oracle Server 18c Windows v1.1.0Windows

IDENTIFICATION AND AUTHENTICATION

2.1.1 Ensure 'SECURE_CONTROL_' Is Set In 'listener.ora'CIS Oracle Server 18c Linux v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

2.3 Ensure 'Cross DB Ownership Chaining' Server Configuration Option is set to '0'CIS SQL Server 2008 R2 DB Engine L1 v1.7.0MS_SQLDB

ACCESS CONTROL

2.4 Ensure 'Database Mail XPs' Server Configuration Option is set to '0'CIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

SYSTEM AND INFORMATION INTEGRITY

2.4 Ensure 'Database Mail XPs' Server Configuration Option is set to '0'CIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

SYSTEM AND INFORMATION INTEGRITY

2.9 Ensure 'Trustworthy' Database Property is set to 'Off'CIS SQL Server 2017 Database L1 DB v1.3.0MS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

2.9 Ensure 'Trustworthy' Database Property is set to 'Off'CIS SQL Server 2016 Database L1 DB v1.4.0MS_SQLDB

ACCESS CONTROL, MEDIA PROTECTION

2.15 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databasesCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.15 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databasesCIS Microsoft SQL Server 2019 v1.6.0 L1 AWS RDS MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT, MAINTENANCE

2.15 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databasesCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT, MAINTENANCE

2.15 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databasesCIS Microsoft SQL Server 2022 v1.3.0 L1 AWS RDS MS_SQLDBMS_SQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.16 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databasesCIS SQL Server 2012 Database L1 DB v1.6.0MS_SQLDB

CONFIGURATION MANAGEMENT

2.16 Ensure 'AUTO_CLOSE' is set to 'OFF' on contained databasesCIS SQL Server 2012 Database L1 AWS RDS v1.6.0MS_SQLDB

CONFIGURATION MANAGEMENT

3.2 Ensure CONNECT permissions on the 'guest user' is Revoked within all SQL Server databases excluding the master, msdb and tempdbCIS SQL Server 2014 Database L1 AWS RDS v1.5.0MS_SQLDB

ACCESS CONTROL

3.24 .htaccess - 'Verify and set permissions'CIS v1.1.0 Oracle 11g OS L1Unix
4.01 init.ora - '_trace_file_public = FALSE'CIS v1.1.0 Oracle 11g OS Windows Level 1Windows

ACCESS CONTROL

4.1.10 Set Archive Log Failover Retry Limit (NUMARCHRETRY)CIS IBM DB2 12.1 v1.0.0 Windows OS Level 1Windows

AUDIT AND ACCOUNTABILITY

6.1.16 Secure QUIESCECONNECT AuthorityCIS IBM DB2 11 v1.2.0 Database Level 1IBM_DB2DB

ACCESS CONTROL, MEDIA PROTECTION

6.2 Set EEPROM Security Mode and Log Failed Access (SPARC)CIS Oracle Solaris 11.4 L1 v1.1.0Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

6.2.2 Review RolesCIS IBM DB2 11 v1.2.0 Database Level 1IBM_DB2DB

ACCESS CONTROL, MEDIA PROTECTION

6.5 Ensure The 'test' database is not installedCIS MongoDB 3.2 Database Audit L2 v1.0.0MongoDB

CONFIGURATION MANAGEMENT

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-#badlogins = 0CIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-#badlogins = 0CIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-#badlogins = 0CIS Solaris 11 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-mode = commandCIS Solaris 11.2 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-mode = commandCIS Solaris 11.1 L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

6.16 Set EEPROM Security Mode and Log Failed Access (SPARC) - eeprom security-mode = commandCIS Solaris 11 L1 v1.1.0Unix

SYSTEM AND INFORMATION INTEGRITY

8.5 Remove default databasesCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS LinuxUnix

CONFIGURATION MANAGEMENT

8.5 Remove default databasesCIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS WindowsWindows

CONFIGURATION MANAGEMENT

CD16-00-005600 - Access to database files must be limited to relevant processes and to authorized, administrative users.DISA Crunchy Data Postgres 16 STIG v1r3 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

DG0009-ORACLE11 - Access to DBMS software files and directories should not be granted to unauthorized users - '%ORACLE_HOME% permissions are configured correctly'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

CONFIGURATION MANAGEMENT

DG0009-ORACLE11 - Access to DBMS software files and directories should not be granted to unauthorized users - 'umask < 0022'DISA STIG Oracle 11 Installation v9r1 LinuxUnix

ACCESS CONTROL

DG0191-ORACLE11 - Credentials used to access remote databases should be protected by encryption and restricted to authorized users.DISA STIG Oracle 11 Installation v9r1 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

EPAS-00-003800 - Unused database components, EDB Postgres Advanced Server software, and database objects must be removed.EnterpriseDB PostgreSQL Advanced Server OS Linux v2r1Unix

CONFIGURATION MANAGEMENT

MADB-10-003100 - Default demonstration and sample databases, database objects, and applications must be removed.DISA MariaDB Enterprise 10.x STIG v2r5 MySQLDBMySQLDB

CONFIGURATION MANAGEMENT

MD3X-00-000310 - MongoDB must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).DISA STIG MongoDB Enterprise Advanced 3.x v2r3 DBMongoDB

IDENTIFICATION AND AUTHENTICATION

MD4X-00-000700 - MongoDB must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).DISA STIG MongoDB Enterprise Advanced 4.x v1r4 DBMongoDB

SYSTEM AND COMMUNICATIONS PROTECTION

MD7X-00-004600 - MongoDB must separate user functionality (including user interface services) from database management functionality.DISA MongoDB Enterprise Advanced 7.x STIG v1r2 MongoDBMongoDB

SYSTEM AND COMMUNICATIONS PROTECTION

MD7X-00-004600 MongoDB must separate user functionality (including user interface services) from database management functionality.DISA MongoDB Enterprise Advanced 7.x STIG v1r1MongoDB

SYSTEM AND COMMUNICATIONS PROTECTION

MD8X-00-002700 - MongoDB database objects (including but not limited to tables, indexes, storage, stored procedures, functions, triggers, links to software external to MongoDB, etc.) must be owned by database/DBMS principals authorized for ownership.DISA MongoDB Enterprise Advanced 8.x STIG v1r1 MongoDBMongoDB

CONFIGURATION MANAGEMENT

MYS8-00-004600 - The MySQL Database Server 8.0 must generate audit records for all direct access to the database(s).DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

AUDIT AND ACCOUNTABILITY

MYS8-00-009200 - The MySQL Database Server 8.0 must enforce access restrictions associated with changes to the configuration of the MySQL Database Server 8.0 or database(s).DISA Oracle MySQL 8.0 v2r2 OS LinuxUnix

CONFIGURATION MANAGEMENT

PGS9-00-012000 - Access to database files must be limited to relevant processes and to authorized, administrative users.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

PPS9-00-003800 - Unused database components, EDB Postgres Advanced Server software, and database objects must be removed.EDB PostgreSQL Advanced Server OS Linux Audit v2r3Unix

CONFIGURATION MANAGEMENT

SQL4-00-030700 - The role(s)/group(s) used to modify database structure (including but not necessarily limited to tables, indexes, storage, etc.) and logic modules (stored procedures, functions, triggers, links to software external to SQL Server, etc.) must be restricted to authorized users - s used to modify database structure and logic modules must be restricted to authorized users.DISA STIG SQL Server 2014 Instance DB Audit v2r4MS_SQLDB

CONFIGURATION MANAGEMENT

TCAT-AS-000470 - Stack tracing must be disabled.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG610 A22 - Web sites must utilize ports, protocols, and services according to PPSM guidelines.DISA STIG Apache Site 2.2 Unix v1r11Unix
WG610 A22 - Web sites must utilize ports, protocols, and services according to PPSM guidelines.DISA STIG Apache Site 2.2 Unix v1r11 MiddlewareUnix
WN10-CC-000063 - Windows 10 systems must use either Group Policy or an approved Mobile Device Management (MDM) product to enforce STIG compliance.DISA Microsoft Windows 10 STIG v3r6Windows

CONFIGURATION MANAGEMENT