Item Search

NameAudit NamePluginCategory
2.4 Disable NIS Server Services - domainCIS Solaris 11.1 L1 v1.0.0Unix
2.6 Disable Apache ServiceCIS Oracle Solaris 11.4 L1 v1.1.0Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

2.8 Ensure the Info Module Is DisabledCIS Apache HTTP Server 2.2 L1 v3.6.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.8 Ensure the Info Module Is DisabledCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.8 Ensure the Info Module Is DisabledCIS Apache HTTP Server 2.4 v2.3.0 L1Unix

CONFIGURATION MANAGEMENT

2.8 Ensure the Info Module Is DisabledCIS Apache HTTP Server 2.2 L1 v3.6.0 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

2.10 Disable Apache ServiceCIS Solaris 11.1 L1 v1.0.0Unix
2.10 Disable Apache ServiceCIS Solaris 11 L1 v1.1.0Unix
2.10 Disable Apache ServiceCIS Solaris 11.2 L1 v1.1.0Unix
5.3 Ensure Options for Other Directories Are MinimizedCIS Apache HTTP Server 2.4 v2.3.0 L2Unix

ACCESS CONTROL

AS24-W1-000030 - The Apache web server must use encryption strength in accordance with the categorization of data hosted by the Apache web server when remote connections are provided - SSLProtocolDISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000030 - The Apache web server must use encryption strength in accordance with the categorization of data hosted by the Apache web server when remote connections are provided.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000065 - System logging must be enabled.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000070 - The Apache web server must generate, at a minimum, log records for system startup and shutdown, system access, and system authentication events.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000130 - An Apache web server, behind a load balancer or proxy server, must produce log records containing the client IP information as the source and destination and not the load balancer or proxy IP information with each event.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000160 - The Apache web server must use a logging mechanism that is configured to alert the (ISSO) and System Administrator (SA) in the event of a processing failure.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000210 - The log data and records from the Apache web server must be backed up onto a different system or media.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000250 - The Apache web server must only contain services and functions necessary for operation - SetHandler server-statusDISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000260 - The Apache web server must not be a proxy server.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000270 - The Apache web server must provide install options to exclude the installation of documentation, sample code, example applications, and tutorials.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000360 - The Apache web server must be configured to use a specified IP address and portDISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000380 - The Apache web server must perform RFC 5280-compliant certification path validation.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

IDENTIFICATION AND AUTHENTICATION

AS24-W1-000480 - The Apache web server must accept only system-generated session identifiers.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000480 - The Apache web server must accept only system-generated session identifiers.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000530 - The Apache web server must generate unique session identifiers with definable entropy - SSLRandomSeed startupDISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000590 - The Apache web server must restrict the ability of users to launch denial-of-service (DoS) attacks against other information systems or networks.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W1-000640 - The Apache web server must set an absolute timeout for sessions.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000640 - The Apache web server must set an absolute timeout for sessions.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL

AS24-W1-000670 - The Apache web server must restrict inbound connections from nonsecure zones.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL

AS24-W1-000670 - The Apache web server must restrict inbound connections from nonsecure zones.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

ACCESS CONTROL

AS24-W1-000720 - The Apache web server must not impede the ability to write specified log record content to an audit log server.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000760 - The Apache web server must generate log records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) with a minimum granularity of one second - log_config_moduleDISA STIG Apache Server 2.4 Windows Server v2r3Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000830 - The Apache web server must be tuned to handle the operational requirements of the hosted application.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000950 - The Apache web server must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W1-000960 - The Apache web server software must be a vendor-supported version.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000960 - The Apache web server software must be a vendor-supported version.DISA STIG Apache Server 2.4 Windows Server v2r3Windows

CONFIGURATION MANAGEMENT

BIND-9X-001360 - The BIND 9.x server implementation must prohibit the forwarding of queries to servers controlled by organizations outside of the U.S. government.DISA BIND 9.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

DISA_STIG_Apache_Site-2.2_Windows_v1r13.audit from DISA APACHE 2.2 Site for Windows v1r13 STIGDISA STIG Apache Site 2.2 Windows v1r13Windows
DISA_STIG_EDB_PostgreSQL_Advanced_Server_v11_Windows_v2r4_OS.audit from DISA EDB Postgres Advanced Server v11 on Windows v2r4 STIGEDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows
DISA_STIG_Microsoft_Exchange_2013_Client_Access_Server_v2r2.audit from DISA Microsoft Exchange 2013 Client Access Server v2r2 STIGDISA Microsoft Exchange 2013 Client Access Server STIG v2r2Windows

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_Microsoft_Exchange_2013_Edge_Transport_Server_v1r6.audit from DISA Microsoft Exchange 2013 Edge Transport Server v1r6 STIGDISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_Microsoft_Exchange_2013_Mailbox_Server_v2r3.audit from DISA Microsoft Exchange 2013 Mailbox Server v2r3 STIGDISA Microsoft Exchange 2013 Mailbox Server STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_Microsoft_Exchange_2016_Edge_Transport_Server_v2r6.audit from DISA Microsoft Exchange 2016 Edge Transport Server v2r6 STIGDISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_Microsoft_Exchange_2016_Mailbox_Server_v2r6.audit from DISA Microsoft Exchange 2016 Mailbox Server v2r6 STIGDISA Microsoft Exchange 2016 Mailbox Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

DISA_STIG_MSSQL_2014_Instance-OS_v2r4.audit from DISA MS SQL Server 2014 Instance v2r4 STIGDISA STIG SQL Server 2014 Instance OS Audit v2r4Windows
DISA_STIG_MSSQL_2016_Instance-OS_v3r6.audit from DISA MS SQL Server 2016 Instance v3r6 STIGDISA MS SQL Server 2016 Instance STIG v3r6 WindowsWindows
DISA_STIG_SUSE_Linux_Enterprise_Server_15_v2r8.audit from DISA SUSE Linux Enterprise Server 15 STIG v2r8DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix
EP11-00-008700 - The EDB Postgres Advanced Server must disable network functions, ports, protocols, and services deemed by the organization to be nonsecure, in accord with the Ports, Protocols, and Services Management (PPSM) guidance.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

CONFIGURATION MANAGEMENT

F5BI-AP-000235 - The F5 BIG-IP appliance APM Access Policies that grant access to web application resources must allow only client certificates that have the User Persona Name (UPN) value in the User Persona Client Certificates.DISA F5 BIG-IP Access Policy Manager STIG v2r4F5

SYSTEM AND COMMUNICATIONS PROTECTION