Item Search

NameAudit NamePluginCategory
1.001 - Physical security of the Automated Information System (AIS) does not meet DISA requirements.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

1.1 Ensure packages are obtained from authorized repositoriesCIS PostgreSQL 10 OS v1.0.0Unix

CONFIGURATION MANAGEMENT

1.3 Ensure Installation of Community PackagesCIS PostgreSQL 11 OS v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.15 Audit Docker files and directories - /usr/bin/docker-runcCIS Docker 1.12.0 v1.0.0 L1 LinuxUnix

AUDIT AND ACCOUNTABILITY

2.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterMobileIron - CIS Apple iOS 26 v1.0.0 L1 End User OwnedMDM

IDENTIFICATION AND AUTHENTICATION

2.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterAirWatch - CIS Apple iPadOS 26 v1.0.0 L1 End User OwnedMDM

IDENTIFICATION AND AUTHENTICATION

2.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterAirWatch - CIS Apple iOS 17 Benchmark v1.1.0 End User Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

2.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterMobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

2.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterMobileIron - CIS Apple iOS 18 v2.0.0 L1 End User OwnedMDM

IDENTIFICATION AND AUTHENTICATION

2.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterMobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

2.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterMobileIron - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

IDENTIFICATION AND AUTHENTICATION

2.17 Set Sticky Bit on All World-Writable DirectoriesCIS Debian Linux 7 L1 v1.0.0Unix

ACCESS CONTROL

3.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterAirWatch - CIS Apple iOS 17 Institution Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

3.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterAirWatch - CIS Apple iOS 26 v1.0.0 L1 Institution OwnedMDM

IDENTIFICATION AND AUTHENTICATION

3.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterMobileIron - CIS Apple iOS 26 v1.0.0 L1 Institution OwnedMDM

IDENTIFICATION AND AUTHENTICATION

3.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterAirWatch - CIS Apple iOS 18 v2.0.0 L1 Institution OwnedMDM

IDENTIFICATION AND AUTHENTICATION

3.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterMobileIron - CIS Apple iPadOS 18 v2.0.0 L1 Institution OwnedMDM

IDENTIFICATION AND AUTHENTICATION

3.6 Ensure Relational Database Service Instances have Auto Minor Version Upgrade EnabledCIS Amazon Web Services Three-tier Web Architecture L1 1.0.0amazon_aws

SYSTEM AND INFORMATION INTEGRITY

5.1 Ensure that WildFire file size upload limits are maximizedCIS Palo Alto Firewall 10 v1.3.0 L1Palo_Alto

SYSTEM AND INFORMATION INTEGRITY

CISC-L2-000250 - The Cisco switch must have all user-facing or untrusted ports configured as access switch ports.DISA Cisco IOS XE Switch L2S STIG v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000250 - The Cisco switch must have all user-facing or untrusted ports configured as access switch ports.DISA Cisco IOS Switch L2S STIG v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001280 - The Cisco switch must generate audit records showing starting and ending time for administrator access to the system.DISA Cisco NX OS Switch NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001310 - The Cisco switch must be configured to off-load log records onto a different system than the system being audited.DISA Cisco NX OS Switch NDM STIG v3r6Cisco

AUDIT AND ACCOUNTABILITY

DG0071-ORACLE11 - New passwords must be required to differ from old passwords by more than four characters - 'PASSWORD_VERIFY_FUNCTION is not set to NULL or DEFAULT'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB
F5BI-AP-300041 - The F5 BIG-IP appliance that provides intermediary services for SMTP must inspect inbound and outbound SMTP and Extended SMTP communications traffic for protocol compliance and protocol anomalies.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-AP-300042 - The F5 BIG-IP appliance that intermediary services for FTP must inspect inbound and outbound FTP communications traffic for protocol compliance and protocol anomalies.DISA F5 BIG-IP TMOS ALG STIG v1r2F5

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

PHTN-30-000087 - The Photon operating system must configure sshd to ignore user-specific 'known_host' files.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000102 - The Photon operating system must not send IPv4 Internet Control Message Protocol (ICMP) redirects.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000105 - The Photon operating system must not perform multicast packet forwarding.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000111 - The Photon operating system must protect all boot configuration files from unauthorized modification.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000115 - The Photon operating system must configure sshd to disallow HostbasedAuthentication.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

PHTN-30-000119 - The Photon operating system must configure sshd to restrict AllowTcpForwarding.DISA STIG VMware vSphere 7.0 Photon OS v1r4Unix

CONFIGURATION MANAGEMENT

VCST-67-000013 - The Security Token Service must have mappings set for Java servlet pages.DISA STIG VMware vSphere 6.7 STS Tomcat v1r3Unix

CONFIGURATION MANAGEMENT

VCST-70-000013 - The Security Token Service must have mappings set for Java servlet pages.DISA STIG VMware vSphere 7.0 STS Tomcat v1r2Unix

CONFIGURATION MANAGEMENT

VMCH-70-000001 - Copy operations must be disabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000008 - Unauthorized floppy devices must be disconnected on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000009 - Unauthorized CD/DVD devices must be disconnected on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000015 - Informational messages from the virtual machine to the VMX file must be limited on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

VMCH-70-000029 - Encryption must be enabled for Fault Tolerance on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r4VMware

CONFIGURATION MANAGEMENT

WBLC-02-000083 - Oracle WebLogic must provide a real-time alert when organization-defined audit failure events occur - Module-HealthStateOracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-02-000083 - Oracle WebLogic must provide a real-time alert when organization-defined audit failure events occur - SMTP NotificationOracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-02-000083 - Oracle WebLogic must provide a real-time alert when organization-defined audit failure events occur - SMTP NotificationOracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000084 - Oracle WebLogic must alert designated individual organizational officials in the event of an audit processing failure - SMTP NotificationOracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000086 - Oracle WebLogic must notify administrative personnel as a group in the event of audit processing failure - Module-HealthStateOracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBLC-02-000086 - Oracle WebLogic must notify administrative personnel as a group in the event of audit processing failure - Module-HealthStateOracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-02-000086 - Oracle WebLogic must notify administrative personnel as a group in the event of audit processing failure - Module-HealthStateOracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-09-000257 - Oracle WebLogic must provide system notifications to a list of response personnel who are identified by name and/or role - Module HealthStateOracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY

WBLC-09-000257 - Oracle WebLogic must provide system notifications to a list of response personnel who are identified by name and/or role - SMTP NotificationOracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

AUDIT AND ACCOUNTABILITY

WBLC-09-000257 - Oracle WebLogic must provide system notifications to a list of response personnel who are identified by name and/or role - SMTP NotificationOracle WebLogic Server 12c Windows v2r2Windows

AUDIT AND ACCOUNTABILITY

WBLC-09-000257 - Oracle WebLogic must provide system notifications to a list of response personnel who are identified by name and/or role - SMTP NotificationOracle WebLogic Server 12c Linux v2r2Unix

AUDIT AND ACCOUNTABILITY