Item Search

NameAudit NamePluginCategory
2.1.1 Ensure 'Mailbox quotas: Issue warning at' is set to ''CIS Microsoft Exchange Server 2019 L1 Mailbox v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.3 Ensure 'Mailbox quotas: Prohibit send and receive at' is set to ''CIS Microsoft Exchange Server 2019 L1 Mailbox v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.4 Ensure 'Mailbox quotas: Prohibit send at' is set to ''CIS Microsoft Exchange Server 2019 L1 Mailbox v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.3.1 Ensure 'Enable non-delivery reports to remote domains' is set to 'False'CIS Microsoft Exchange Server 2019 L2 Mailbox v1.0.0Windows

CONFIGURATION MANAGEMENT

2.3.4 Ensure 'Enable automatic forwards to remote domains' is set to 'False'CIS Microsoft Exchange Server 2019 L1 Mailbox v1.0.0Windows

CONFIGURATION MANAGEMENT

2.4.5 Ensure 'SMTP automated banner response' is set to '220 SMTP Server Ready'CIS Microsoft Exchange Server 2019 L1 Mailbox v1.0.0Windows

CONFIGURATION MANAGEMENT

3.1.2 - AirWatch - Enable 'Require alphanumeric value'AirWatch - CIS Apple iOS 9 v1.0.0 L2MDM

IDENTIFICATION AND AUTHENTICATION

3.1.2 - AirWatch - Enable 'Require alphanumeric value'AirWatch - CIS Apple iOS 8 v1.0.0 L2MDM

IDENTIFICATION AND AUTHENTICATION

3.1.2 - MobileIron - Enable 'Require alphanumeric value'MobileIron - CIS Apple iOS 8 v1.0.0 L2MDM

IDENTIFICATION AND AUTHENTICATION

3.1.2 - MobileIron - Enable 'Require alphanumeric value'MobileIron - CIS Apple iOS 9 v1.0.0 L2MDM

IDENTIFICATION AND AUTHENTICATION

3.1.3 - MobileIron - Set the 'minimum password length'MobileIron - CIS Apple iOS 9 v1.0.0 L1MDM

IDENTIFICATION AND AUTHENTICATION

3.2.3 Ensure rds kernel module is not availableCIS Oracle Linux 7 v4.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

3.2.3 Ensure rds kernel module is not availableCIS Ubuntu Linux 18.04 LTS v2.2.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

3.2.3 Ensure rds kernel module is not availableCIS Red Hat Enterprise Linux 7 v4.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

3.2.3 Ensure rds kernel module is not availableCIS CentOS Linux 7 v4.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

3.2.3 Ensure rds kernel module is not availableCIS Debian Linux 11 v2.0.0 L2 ServerUnix

CONFIGURATION MANAGEMENT

3.2.3 Ensure rds kernel module is not availableCIS Red Hat EL8 Workstation L2 v3.0.0Unix

CONFIGURATION MANAGEMENT

3.4 Ensure 'Minimum password length' is set to '4' or moreCIS Microsoft Exchange Server 2019 L1 MDM v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

3.4.3 Ensure RDS is disabled - lsmodCIS Debian 9 Server L1 v1.0.1Unix

CONFIGURATION MANAGEMENT

3.4.3 Ensure RDS is disabled - lsmodCIS Ubuntu Linux 16.04 LTS Server L2 v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.4.3 Ensure RDS is disabled - modprobeCIS Aliyun Linux 2 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

3.4.3 Ensure RDS is disabled - modprobeCIS Distribution Independent Linux Server L2 v2.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.5.3 Ensure RDS is disabledCIS SUSE Linux Enterprise Server 11 L1 v2.1.1Unix

CONFIGURATION MANAGEMENT

3.5.3 Ensure RDS is disabled - lsmodCIS Debian Family Workstation L2 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

3.5.3 Ensure RDS is disabled (lsmod)CIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

3.5.3 Ensure RDS is disabled (modprobe)CIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

CONFIGURATION MANAGEMENT

3.6 Ensure 'Password expiration' is set to '365' or lessCIS Microsoft Exchange Server 2019 L1 MDM v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

3.8 Ensure 'Require alphanumeric password' is set to 'True'CIS Microsoft Exchange Server 2019 L1 MDM v1.0.0Windows

IDENTIFICATION AND AUTHENTICATION

3.11 Ensure 'Time without user input before password must be re-entered' is set to '15'CIS Microsoft Exchange Server 2019 L1 MDM v1.0.0Windows

ACCESS CONTROL

6.5 Ensure SSL Protocol is set to TLS for Secure Connectors - verify sslProtocol is set to TLSCIS Apache Tomcat 8 L1 v1.1.0 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.10 Ensure Weak SSL/TLS Ciphers Are DisabledCIS PostgreSQL 14 OS v 1.2.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

7.5.3 Disable RDSCIS Debian Linux 7 L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

AIX7-00-003088 - If Stream Control Transmission Protocol (SCTP) must be disabled on AIX.DISA STIG AIX 7.x v3r1Unix

CONFIGURATION MANAGEMENT

EX13-CA-000035 - Exchange ActiveSync (EAS) must only use certificate-based authentication to access email - WindowsAuthEnabledDISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

ACCESS CONTROL

EX13-CA-000075 - Exchange must have Audit data protected against unauthorized modification.DISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

EX13-MB-000155 - Exchange Mail quota settings must not restrict receiving mail.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX13-MB-000275 - The Exchange Receive connector timeout must be limited.DISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

ACCESS CONTROL

EX16-MB-000310 - Exchange Mail quota settings must not restrict receiving mail.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-MB-000540 - The Exchange Global Recipient Count Limit must be set.DISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

EX19-MB-000142 - The Exchange Global Recipient Count Limit must be set.DISA Microsoft Exchange 2019 Mailbox Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

GEN007020 - The Stream Control Transmission Protocol (SCTP) must be disabled unless required.DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

HONW-09-009800 - Honeywell Mobility Edge Android Pie devices work profile must be configured to disable automatic completion of workspace internet browser text input.MobileIron - DISA Honeywell Android 9.x COBO v1r2MDM

CONFIGURATION MANAGEMENT

HTTP vs. HTTPS - plaintextArubaOS Switch 16.x Hardening Guide v1.0.0ArubaOS

CONFIGURATION MANAGEMENT

JUNI-RT-000800 - The Juniper multicast edge router must be configured to establish boundaries for administratively scoped multicast traffic.DISA STIG Juniper Router RTR v3r2Juniper

ACCESS CONTROL

JUSX-VN-000031 - The Juniper SRX Services Gateway VPN must use anti-replay mechanisms for security associations.DISA Juniper SRX Services Gateway VPN v3r1Juniper

IDENTIFICATION AND AUTHENTICATION

MADB-10-004900 - MariaDB must maintain the authenticity of communications sessions by guarding against man-in-the-middle attacks that guess at Session ID values.DISA MariaDB Enterprise 10.x v2r3 DBMySQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

MSFT-11-005400 - Microsoft Android 11 must allow the Administrator (EMM) to perform the following management function: Wipe Enterprise data.MobileIron - DISA Microsoft Android 11 COBO v1r2MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

SPLK-CL-000020 - Splunk Enterprise must notify the system administrator (SA) and information system security officer (ISSO) when account events are received (creation, deletion, modification, or disabling) - creation, deletion, modification, or disabling.DISA STIG Splunk Enterprise 8.x for Linux v2r2 STIG REST APISplunk

ACCESS CONTROL

WN12-PK-000001 - The DoD Root CA certificates must be installed in the Trusted Root StoreDISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

WN12-PK-000001 - The DoD Root CA certificates must be installed in the Trusted Root StoreDISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION