Item Search

NameAudit NamePluginCategory
5.4.2 Ensure system accounts are securedCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.2.6 Ensure users' dot files are not group or world writableCIS Debian Family Server L1 v1.0.0Unix

ACCESS CONTROL

6.2.6 Ensure users' dot files are not group or world writableCIS Debian Family Workstation L1 v1.0.0Unix

ACCESS CONTROL

6.2.8 Ensure no users have .netrc filesCIS Ubuntu Linux 16.04 LTS Workstation L1 v2.0.0Unix

ACCESS CONTROL

6.2.9 Ensure no users have .rhosts filesCIS Debian Family Server L1 v1.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.10 Ensure no users have .rhosts filesCIS Ubuntu Linux 16.04 LTS Server L1 v2.0.0Unix

IDENTIFICATION AND AUTHENTICATION

6.2.12 Ensure no users have .forward filesCIS Oracle Linux 6 Workstation L1 v2.0.0Unix

CONFIGURATION MANAGEMENT

6.2.13 Ensure users' .netrc Files are not group or world accessibleCIS CentOS Linux 8 Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.2.13 Ensure users' .netrc Files are not group or world accessibleCIS Fedora 28 Family Linux Server L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.2.13 Ensure users' .netrc Files are not group or world accessibleCIS Fedora 28 Family Linux Workstation L1 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

6.2.17 Ensure no users have .rhosts filesCIS Amazon Linux 2 STIG v2.0.1 L1 ServerUnix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

9.3.8 (L1) Ensure 'Windows Firewall: Public: Logging: Size limit (KB)' is set to '16,384 KB or greater'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

AUDIT AND ACCOUNTABILITY

9.7 Secure the permission of the SSLconfig.ini fileCIS IBM DB2 v10 v1.1.0 Linux OS Level 1Unix
9.7 Secure the permission of the SSLconfig.ini fileCIS IBM DB2 v10 v1.1.0 Linux OS Level 2Unix
18.8.48.11.1 (L2) Ensure 'Enable/Disable PerfTrack' is set to 'Disabled'CIS Microsoft Windows Server 2008 R2 Domain Controller Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.8.48.11.1 (L2) Ensure 'Enable/Disable PerfTrack' is set to 'Disabled'CIS Microsoft Windows Server 2008 Member Server Level 2 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.9.11.3.10 Ensure 'Configure use of passwords for removable data drives' is set to 'Disabled'CIS Windows 7 Workstation Level 2 + Bitlocker v3.2.0Windows

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

18.9.19.1 (L1) Ensure 'Turn off desktop gadgets' is set to 'Enabled'CIS Microsoft Windows Server 2008 R2 Domain Controller Level 1 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.9.19.1 (L1) Ensure 'Turn off desktop gadgets' is set to 'Enabled'CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

CONFIGURATION MANAGEMENT

18.9.47.11.1 (L2) Ensure 'Enable/Disable PerfTrack' is set to 'Disabled'CIS Microsoft Windows Server 2016 v4.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.9.49.11.1 Ensure 'Enable/Disable PerfTrack' is set to 'Disabled'CIS Microsoft Windows Server 2019 Stand-alone v4.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.9.49.11.1 Ensure 'Enable/Disable PerfTrack' is set to 'Disabled'CIS Microsoft Windows Server 2022 Stand-alone v2.0.0 L2 MSWindows

CONFIGURATION MANAGEMENT

18.10.9.3.5 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION

18.10.9.3.9 (L1) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for removable data drives' is set to 'Enabled: False'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

MEDIA PROTECTION

18.10.10.1.4 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Recovery Password' is set to 'Enabled: Allow 48-digit recovery password' or higherCIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.1.5 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Recovery Key' is set to 'Enabled: Allow 256-bit recovery key' or higherCIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.1.5 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Recovery Key' is set to 'Enabled: Allow 256-bit recovery key' or higherCIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.1.9 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives' is set to 'Enabled: False'CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.1.9 Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives' is set to 'Enabled: False'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.3.9 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for removable data drives' is set to 'Enabled: False'CIS Microsoft Windows 11 Enterprise v5.1.0 BLWindows

MEDIA PROTECTION

18.10.10.3.9 Ensure 'Choose how BitLocker-protected removable drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for removable data drives' is set to 'Enabled: False'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

MEDIA PROTECTION

F5BI-FW-300020 - The F5 BIG-IP appliance must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).DISA F5 BIG-IP TMOS Firewall STIG v1r1F5

SYSTEM AND COMMUNICATIONS PROTECTION

OL07-00-030560 - The Oracle Linux operating system must audit all uses of the semanage command.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL07-00-030580 - The Oracle Linux operating system must audit all uses of the chcon command.DISA Oracle Linux 7 STIG v3r5Unix

MAINTENANCE

OL07-00-030610 - The Oracle Linux operating system must generate audit records for all unsuccessful account access events.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL07-00-030640 - The Oracle Linux operating system must audit all uses of the unix_chkpwd command.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030710 - The Oracle Linux operating system must audit all uses of the newgrp command.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030800 - The Oracle Linux operating system must audit all uses of the crontab command.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030820 - The Oracle Linux operating system must audit all uses of the init_module and finit_module syscalls.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY

OL07-00-030910 - The Oracle Linux operating system must audit all uses of the unlink, unlinkat, rename, renameat, and rmdir syscalls.DISA Oracle Linux 7 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

OL07-00-040310 - The Oracle Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.DISA Oracle Linux 7 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL07-00-040340 - The Oracle Linux operating system must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive.DISA Oracle Linux 7 STIG v3r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

OL07-00-040410 - The Oracle Linux operating system must be configured so that the SSH public host key files have mode 0644 or less permissive.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040420 - The Oracle Linux operating system must be configured so the SSH private host key files have mode 0640 or less permissive.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040470 - The Oracle Linux operating system must be configured so that the SSH daemon does not allow compression or only allows compression after successful authentication.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040520 - The Oracle Linux operating system must enable an application firewall, if available.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040611 - The Oracle Linux operating system must use a reverse-path filter for IPv4 network traffic when possible on all interfaces.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-040700 - The Oracle Linux operating system must not have the Trivial File Transfer Protocol (TFTP) server package installed if not required for operational support - TFTP server package installed if not required for operational support.DISA Oracle Linux 7 STIG v3r5Unix

CONFIGURATION MANAGEMENT

OL07-00-041001 - The Oracle Linux operating system must have the required packages for multifactor authentication installed.DISA Oracle Linux 7 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-090100 - The operating system must prevent the execution of prohibited mobile code.DISA Solaris 11 X86 STIG v3r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION