Item Search

NameAudit NamePluginCategory
1.2 Disable Unused ConnectorsCIS Apache Tomcat 10 L2 v1.1.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

2.0 Install & Config - 'Enable TLSv1'TNS NetApp Data ONTAP 7GNetApp

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Disable/Modify Default Accts - 'alternate admin account has been created (root)'TNS NetApp Data ONTAP 7GNetApp
2.2 Disable/Modify Default Accts - 'alternate admin account has been created (snmp)'TNS NetApp Data ONTAP 7GNetApp
2.2 Disable/Modify Default Accts - 'ndmp/ndmpcopy service account'TNS NetApp Data ONTAP 7GNetApp
2.2 Disable/Modify Default Accts - 'SNMP default community strings have been removed'TNS NetApp Data ONTAP 7GNetApp
2.2.14 Disable Local RPC Port Mapping Service - Make sure that network/rpc/bind is disabled.CIS Solaris 10 L1 v5.2Unix
2.3 Disable Unnecessary Services - 'telnet.access != legacy'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

2.3.2 Ensure rsh client is not installedCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

2.4 Password Security - 'security.passwd.lockout.numtries = 6'TNS NetApp Data ONTAP 7GNetApp

ACCESS CONTROL

2.5 Autologout - 'ssh.idle.timeout <= 300'TNS NetApp Data ONTAP 7GNetApp

ACCESS CONTROL

2.7 Network & IP Options - 'ip.match_any_ifaddr = off'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

2.8 Protocol Access Controls - 'httpd.access has been configured'TNS NetApp Data ONTAP 7GNetApp

SYSTEM AND COMMUNICATIONS PROTECTION

2.8 Protocol Access Controls - 'interface.blocked.cifs is not blank'TNS NetApp Data ONTAP 7GNetApp

SYSTEM AND COMMUNICATIONS PROTECTION

2.8 Protocol Access Controls - 'interface.blocked.ftpd has been configured'TNS NetApp Data ONTAP 7GNetApp

SYSTEM AND COMMUNICATIONS PROTECTION

3.1 Storage System (Hardware) Management - 'Change the root account password after each use'TNS NetApp Data ONTAP 7GNetApp
3.1.1.3 Configure EIGRP log-adjacency-changesCIS Cisco NX-OS v1.2.0 L1Cisco

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

3.2 Data ONTAP (Software) Mgmt - 'httpd.admin.access has been configured'TNS NetApp Data ONTAP 7GNetApp

ACCESS CONTROL

3.2 Data ONTAP (Software) Mgmt - 'Use e0M as the Data ONTAP management port'TNS NetApp Data ONTAP 7GNetApp
4.1.7 Ensure "firewalld" is installedCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.1 MultiStore - 'MultiStore protocol is disabled'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

5.2 SnapMirror - 'SnapMirror protocol is disabled'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

5.3 SnapVault - 'SnapVault protocol is disabled'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

5.4 CIFS - 'CIFS protocol is disabled'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

5.4 CIFS - 'cifs.audit.account_mgmt_events.enable = on'TNS NetApp Data ONTAP 7GNetApp

AUDIT AND ACCOUNTABILITY

5.4 CIFS - 'cifs.audit.autosave.onsize.threshold has been configured'TNS NetApp Data ONTAP 7GNetApp

AUDIT AND ACCOUNTABILITY

5.4 CIFS - 'cifs.audit.file_access_events.enable = on'TNS NetApp Data ONTAP 7GNetApp

AUDIT AND ACCOUNTABILITY

5.4 CIFS - 'cifs.smb2.client.enable = on'TNS NetApp Data ONTAP 7GNetApp

SYSTEM AND INFORMATION INTEGRITY

5.4 CIFS - 'dns.enable = on'TNS NetApp Data ONTAP 7GNetApp

SYSTEM AND COMMUNICATIONS PROTECTION

5.4 CIFS - 'dns.update.enable = on or secure'TNS NetApp Data ONTAP 7GNetApp

SYSTEM AND COMMUNICATIONS PROTECTION

5.4 CIFS - 'timed.proto = ntp'TNS NetApp Data ONTAP 7GNetApp

AUDIT AND ACCOUNTABILITY

5.5 NFS - 'nfs.v2.enable = off'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

5.5 NFS - 'nfs.v3.enable = off'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

6.7.6 Ensure Different Authentication Keys for each NTP ServerCIS Juniper OS Benchmark v2.1.0 L2Juniper

AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higherCIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

CONFIGURATION MANAGEMENT

18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higherCIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higherCIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higherCIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higherCIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

CONFIGURATION MANAGEMENT

ALMA-09-031700 - AlmaLinux OS 9 must have the firewalld package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

DO3622-ORACLE11 - Oracle roles granted using the WITH ADMIN OPTION should not be granted to unauthorized accounts.DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

ACCESS CONTROL

EX13-EG-000235 - The Exchange Recipient filter must be enabled.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-ED-000134 - The Exchange Recipient filter must be enabled.DISA Microsoft Exchange 2019 Edge Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

IBMW-LS-000380 - The WebSphere Liberty Server must use an LDAP user registry.DISA IBM WebSphere Liberty Server STIG v2r4Unix

IDENTIFICATION AND AUTHENTICATION

JUSX-AG-000019 - For User Role Firewalls, the Juniper SRX Services Gateway Firewall must employ user attribute-based security policies to enforce approved authorizations for logical access to information and system resources.DISA Juniper SRX Services Gateway ALG v3r3Juniper

ACCESS CONTROL

JUSX-IP-000025 - The IDPS must send an alert to, at a minimum, the ISSO and ISSM when DoS incidents are detected.DISA Juniper SRX Services Gateway IDPS v2r1Juniper

SYSTEM AND INFORMATION INTEGRITY

O121-BP-022300 - System privileges granted using the WITH ADMIN OPTION must not be granted to unauthorized user accounts.DISA Oracle Database 12c STIG v3r5 OracleDBOracleDB

CONFIGURATION MANAGEMENT

RHEL-10-200531 - RHEL 10 must have the "firewalld" service set to active.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

SQL2-00-023300 - SQL Server must notify appropriate individuals when accounts are modified - 'Event ID 15'DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

ACCESS CONTROL

SQL2-00-023300 - SQL Server must notify appropriate individuals when accounts are modified - 'Event ID 110'DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

ACCESS CONTROL