Item Search

NameAudit NamePluginCategory
1.1.5.3.4 Set 'Windows Firewall: Public: Logging: Log dropped packets' to 'Yes'CIS Windows 8 L1 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.10 VMCH-80-000199CIS VMware vSphere 8.0 Virtual Machine STIG v1.0.0 CAT IIIVMware

CONFIGURATION MANAGEMENT

1.75 O19C-00-015500CIS Oracle Database 19c STIG v1.1.0 CAT I UnixUnix

IDENTIFICATION AND AUTHENTICATION

1.75 O19C-00-015500CIS Oracle Database 19c STIG v1.1.0 CAT I WindowsWindows

IDENTIFICATION AND AUTHENTICATION

2.2.2 Ensure X Window System is not installedCIS Amazon Linux v2.1.0 L1Unix

CONFIGURATION MANAGEMENT

3.1.5 Secure permissions for default database file pathCIS IBM DB2 v10 v1.1.0 Windows OS Level 1Windows
3.1.5 Secure permissions for default database file path (Scored)CIS IBM DB2 v10 v1.1.0 Linux OS Level 2Unix
3.1.6 Secure permissions for default database file pathCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS WindowsWindows

AUDIT AND ACCOUNTABILITY

3.1.6 Secure permissions for default database file pathCIS IBM DB2 9 Benchmark v3.0.1 Level 1 OS LinuxUnix

AUDIT AND ACCOUNTABILITY

3.1.6 Secure permissions for default database file pathCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS LinuxUnix

AUDIT AND ACCOUNTABILITY

3.121 - The system does not have a backup administrator accountDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

4.2.4 Enable AI /heuristic based malware detectionCIS FortiGate 7.4.x v1.0.1 L2FortiGate

SYSTEM AND INFORMATION INTEGRITY

5.6 Set a timeout to automatically terminate idle ESXi Shell and SSH sessionsCIS VMware ESXi 5.1 v1.0.1 Level 1VMware

ACCESS CONTROL

5.140 - The HBSS McAfee Agent is not installed. - masvcDISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

6.3 Ensure that server-side scripting is disabled if not neededCIS MongoDB 7 v1.2.0 L2 WindowsWindows

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

6.11 Remove Autologin Capabilities from the GNOME desktop - pam.confCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

6.11 Remove Autologin Capabilities from the GNOME desktop - pam.d/gdm-autologinCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

7.4 Software Inventory ConsiderationsCIS Apple macOS 10.12 L2 v1.2.0Unix

CONFIGURATION MANAGEMENT

9.18 Check for Duplicate Group NamesCIS Solaris 11.2 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

AIOS-14-011000 - Apple iOS/iPadOS must implement the management setting: disable paired Apple Watch.MobileIron - DISA Apple iOS/iPadOS 14 v1r3MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Out of Scope SupplementalNIST macOS Catalina v1.5.0 - All ProfilesUnix

CONFIGURATION MANAGEMENT

DKER-EE-001070 - FIPS mode must be enabled on all Docker Engine - Enterprise nodes - docker info .SecurityOptionsDISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

DKER-EE-001960 - Privileged Linux containers must not be used for Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002060 - The Docker Enterprise hosts UTS namespace must not be shared.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002100 - cgroup usage must be confirmed in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-002780 - PIDs cgroup limits must be used in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

DKER-EE-003460 - The Docker Enterprise log aggregation/SIEM systems must be configured to send an alert the ISSO/ISSM when unauthorized software is installed.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-003560 - Docker Enterprise network ports on all running containers must be limited to what is needed.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-003610 - Only trusted, signed images must be on Universal Control Plane (UCP) in Docker Enterprise.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

DKER-EE-005070 - Docker Enterprise Swarm manager auto-lock key must be rotated periodically.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005270 - Docker Enterprise server certificate file ownership must be set to root:root.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

DKER-EE-005300 - Docker Enterprise server certificate key file permissions must be set to 400.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

JUSX-VN-000004 - The Juniper SRX Services Gateway VPN device also fulfills the role of IDPS in the architecture, the device must inspect the VPN traffic in compliance with DoD IDPS requirements.DISA Juniper SRX Services Gateway VPN v3r2Juniper

ACCESS CONTROL

Monterey - Out of Scope SupplementalNIST macOS Monterey v1.0.0 - All ProfilesUnix

CONFIGURATION MANAGEMENT

RHEL-08-030590 - Successful/unsuccessful modifications to the faillock log file in RHEL 8 must generate an audit record.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

RHEL-08-030601 - RHEL 8 must enable auditing of processes that start prior to the audit daemon.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

SLES-12-020360 - The SUSE operating system must generate audit records for all uses of the kmod command.DISA SLES 12 STIG v3r5Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030380 - The SUSE operating system must generate audit records for all uses of the insmod command.DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SLES-15-030390 - The SUSE operating system must generate audit records for all uses of the rmmod command.DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

SQL6-D0-004300 - SQL Server must be configured to generate audit records for DoD-defined auditable events within all DBMS/database components.DISA MS SQL Server 2016 Instance STIG v3r6 MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

SQLI-22-004300 - SQL Server must be configured to generate audit records for DOD-defined auditable events within all DBMS/database components.DISA Microsoft SQL Server 2022 Instance STIG v1r4 MS_SQLDBMS_SQLDB

AUDIT AND ACCOUNTABILITY

WNFWA-000001 - Windows Defender Firewall with Advanced Security must be enabled when connected to a domain.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

ACCESS CONTROL

WNFWA-000003 - Windows Defender Firewall with Advanced Security must be enabled when connected to a public network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

ACCESS CONTROL

WNFWA-000005 - Windows Defender Firewall with Advanced Security must allow outbound connections, unless a rule explicitly blocks the connection when connected to a domain.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNFWA-000010 - Windows Defender Firewall with Advanced Security must log dropped packets when connected to a domain.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

WNFWA-000011 - Windows Defender Firewall with Advanced Security must log successful connections when connected to a domain.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

WNFWA-000019 - Windows Defender Firewall with Advanced Security must log successful connections when connected to a private network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

AUDIT AND ACCOUNTABILITY

WNFWA-000020 - Windows Defender Firewall with Advanced Security must block unsolicited inbound connections when connected to a public network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

CONFIGURATION MANAGEMENT

WNFWA-000021 - Windows Defender Firewall with Advanced Security must allow outbound connections, unless a rule explicitly blocks the connection when connected to a public network.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNFWA-000100 - Inbound exceptions to the firewall on domain workstations must only allow authorized remote management hosts.DISA Microsoft Windows Defender Firewall with Advanced Security STIG v2r2Windows

ACCESS CONTROL