Item Search

NameAudit NamePluginCategory
1.1 CISC-ND-000010CIS Cisco IOS XR Router NDM STIG v1.0.0 CAT IICisco

ACCESS CONTROL

1.1.2.1 vty line authenticationCIS Cisco NX-OS v1.2.0 L1Cisco

ACCESS CONTROL

1.1.2.2 vty line authenticationCIS Cisco IOS XR 7.x v1.0.1 L1Cisco

ACCESS CONTROL

1.2 EX19-MB-000007CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.2.4 Create 'access-list' for use with 'line vty'CIS Cisco IOS XE 17.x v2.2.1 L1Cisco

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.34 VCSA-80-000270CIS VMware vSphere 8.0 vCenter STIG v1.0.0 CAT IIVMware

CONFIGURATION MANAGEMENT

1.48 CISC-RT-000470CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IIICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.72 SLES-15-020040CIS SUSE Linux Enterprise Server 15 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.87 CISC-RT-000850CIS Cisco IOS XE Router RTR STIG v1.1.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.96 WN16-CC-000030CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IIWindows

CONFIGURATION MANAGEMENT

1.96 WN16-CC-000030CIS Microsoft Windows Server 2016 STIG v4.0.0 DC CAT IIWindows

CONFIGURATION MANAGEMENT

1.96 WN19-CC-000020CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIWindows

CONFIGURATION MANAGEMENT

1.96 WN19-CC-000020CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIWindows

CONFIGURATION MANAGEMENT

3.1.1.2 Configure EIGRP Passive interfaces for interfaces that do not have peersCIS Cisco NX-OS v1.2.0 L1Cisco

ACCESS CONTROL, CONFIGURATION MANAGEMENT

3.3.3 IGMP Snooping ACLCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security RecommendationsArubaOS

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

3.3.7 Multicast Boundary ACLCIS HPE Aruba Networking CX Switch v1.0.1 Optional Security RecommendationsArubaOS

ACCESS CONTROL, MEDIA PROTECTION

3.8 Ensure Plugin Directory Has Appropriate PermissionsCIS MariaDB 10.6 on Linux L1 v1.1.0Unix

ACCESS CONTROL, MEDIA PROTECTION

5.3.1.1 Ensure latest version of pam is installedCIS Debian Linux 12 v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION

7.2 Ensure the vSwitch MAC Address Change policy is set to rejectCIS VMware ESXi 6.5 v1.0.0 Level 1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-U1-000670 - The Apache web server must restrict inbound connections from nonsecure zones.DISA STIG Apache Server 2.4 Unix Server v3r2 MiddlewareUnix

ACCESS CONTROL

AS24-U2-000680 - The Apache web server must restrict inbound connections from nonsecure zones.DISA STIG Apache Server 2.4 Unix Site v2r6 MiddlewareUnix

ACCESS CONTROL

CISC-RT-000300 - The Cisco perimeter router must be configured to not redistribute static routes to an alternate gateway service provider into BGP or an Interior Gateway Protocol (IGP) peering with the NIPRNet or to other autonomous systems.DISA Cisco IOS XE Router RTR STIG v3r5Cisco

ACCESS CONTROL

CISC-RT-000310 - The Cisco perimeter router must be configured to restrict it from accepting outbound IP packets that contain an illegitimate address in the source address field via egress filter or by enabling Unicast Reverse Path Forwarding (uRPF).DISA Cisco IOS XE Router RTR STIG v3r5Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-80-000198 - The ESXi host must protect the confidentiality and integrity of transmitted information by isolating ESXi management traffic.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI5-VMNET-000013 - The system must ensure that the virtual switch Forged Transmits policy is set to reject.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

EX16-ED-000420 - The Exchange Block List service provider must be identified.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

IIST-SI-000239 - The IIS 10.0 websites must use ports, protocols, and services according to Ports, Protocols, and Services Management (PPSM) guidelines.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

CONFIGURATION MANAGEMENT

IIST-SI-000239 - The IIS 10.0 websites must use ports, protocols, and services according to Ports, Protocols, and Services Management (PPSM) guidelines.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

JUEX-L2-000060 - The Juniper EX switch must be configured to permit authorized users to remotely view, in real time, all content related to an established user session from a component separate from the layer 2 switch.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

AUDIT AND ACCOUNTABILITY

JUEX-L2-000070 - The Juniper EX switch must be configured to authenticate all network-connected endpoint devices before establishing any connection.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

IDENTIFICATION AND AUTHENTICATION

JUEX-L2-000120 - The Juniper EX switch must be configured to enable DHCP snooping for all user VLANs with active access interfaces to validate DHCP messages from untrusted sources.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000130 - The Juniper EX switch must be configured to enable IP Source Guard on all user-facing or untrusted access VLANs with active access interfaces.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000160 - The Juniper EX switch must be configured to enable IGMP or MLD Snooping on all VLANs.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-L2-000170 - If STP is used, the Juniper EX switch must be configured to implement Rapid STP, or Multiple STP, where VLANs span multiple switches with redundant links.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-L2-000190 - The Juniper EX switch must be configured to assign all explicitly disabled access interfaces to an unused VLAN.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000200 - The Juniper EX switch must not be configured with VLANs used for L2 control traffic assigned to any host-facing access interface.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

JUEX-L2-000240 - The Juniper EX switch must not have a native VLAN ID assigned, or have a unique native VLAN ID, for all 802.1q trunk links.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-L2-000250 - The Juniper EX switch must not have any access interfaces assigned to a VLAN configured as native for any trunked interface.DISA Juniper EX Series Switches Layer 2 Switch STIG v2r5Juniper

CONFIGURATION MANAGEMENT

JUEX-RT-000740 - The Juniper perimeter router must be configured to block inbound packets with source Bogon IP address prefixes.DISA Juniper EX Series Switches Router STIG v2r1Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

MYS8-00-002400 - The MySQL Database Server 8.0 must generate audit records when privileges/permissions are added.DISA Oracle MySQL 8.0 v2r2 DBMySQLDB

AUDIT AND ACCOUNTABILITY

Network Security - Ensure IP directed broadcast has not been configuredJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

SQL4-00-014000 - SQL Server and/or the operating system must protect its audit configuration from unauthorized modification.DISA STIG SQL Server 2014 Instance OS Audit v2r4Windows

AUDIT AND ACCOUNTABILITY

SQL4-00-014100 - SQL Server and the operating system must protect SQL Server audit features from unauthorized removal.DISA STIG SQL Server 2014 Instance OS Audit v2r4Windows

AUDIT AND ACCOUNTABILITY

TCAT-AS-000450 - Tomcat user UMASK must be set to 0027.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

CONFIGURATION MANAGEMENT

vCenter: vcenter-8.network-restrict-discovery-protocolVMware vSphere Security Configuration and Hardening GuideVMware

CONFIGURATION MANAGEMENT

VCFL-67-000008 - vSphere Client must be configured to use the HTTPS scheme.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

ACCESS CONTROL

WA00520 A22 - The web server must not be configured as a proxy server.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00520 A22 - The web server must not be configured as a proxy server.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WN12-SO-000039 - The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000039 - The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT