Item Search

NameAudit NamePluginCategory
1.2 EX19-MB-000007CIS Microsoft Exchange 2019 Mailbox Server STIG v1.0.0 CAT IIWindows

ACCESS CONTROL

1.3 CISC-RT-000060CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IIICisco

ACCESS CONTROL

1.40 CISC-RT-000470CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT IIICisco

SYSTEM AND COMMUNICATIONS PROTECTION

1.73 CISC-RT-000720CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

SYSTEM AND COMMUNICATIONS PROTECTION

4.1.2 Ensure peer authentication is set to IPSEC SACIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

4.12.1 Ensure LLDP is Disabled if not RequiredCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

4.12.2 Ensure LLDP-MED is Disabled if not RequiredCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.5.3 Ensure ICMP Source-Quench is Set to DisabledCIS Juniper OS Benchmark v2.1.0 L1Juniper

CONFIGURATION MANAGEMENT

6.6.6 Ensure Predefined Login Classes are not usedCIS Juniper OS Benchmark v2.1.0 L1Juniper

ACCESS CONTROL

6.7.7 Ensure Strong Authentication Methods are used for NTP AuthenticationCIS Juniper OS Benchmark v2.1.0 L2Juniper

AUDIT AND ACCOUNTABILITY

6.10.1.7 Ensure Only Suite B Ciphers are set for SSH - ciphers restrictionCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.1.12 Ensure Only Suite B Based Key Signing Algorithms are set for SSH - ECDSA KeyCIS Juniper OS Benchmark v2.1.0 L2Juniper

IDENTIFICATION AND AUTHENTICATION

6.10.2.7 Ensure Web-Management Interface Restriction is set to OOB ManagementCIS Juniper OS Benchmark v2.1.0 L2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

6.11.4 Ensure Console Port is Set as InsecureCIS Juniper OS Benchmark v2.1.0 L2Juniper

ACCESS CONTROL

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - J-Web over HTTPJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - tftp-serverJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - J-Web - Use HTTPS with a valid certificate signed by a trusted CA - trusted CAJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Access Security - SSH - Use SSH version 2Juniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

ARST-L2-000220 - The Arista MLS layer 2 switch must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.DISA Arista MLS EOS 4.X L2S STIG v2r3Arista

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-001210 - The Cisco switch must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA Cisco NX OS Switch NDM STIG v3r6Cisco

MAINTENANCE

EX16-ED-000420 - The Exchange Block List service provider must be identified.DISA Microsoft Exchange 2016 Edge Transport Server STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

Firewall Filter - Order terms with time sensitive protocols at the topJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000239 - The IIS 10.0 websites must use ports, protocols, and services according to Ports, Protocols, and Services Management (PPSM) guidelines.DISA Microsoft IIS 10.0 Site STIG v2r16Windows

CONFIGURATION MANAGEMENT

IIST-SI-000239 - The IIS 10.0 websites must use ports, protocols, and services according to Ports, Protocols, and Services Management (PPSM) guidelines.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

Management Services Security - Allow SNMP queries and/or send traps to more than one trusted server - clients restrictJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Management Services Security - Configure automated secure configuration backups to more than one trusted server - archive-sitesJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONTINGENCY PLANNING

Management Services Security - Configure NTP with authentication with more than one trusted server - authentication valueJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Management Services Security - Configure NTP with authentication with more than one trusted server - trusted-keyJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Management Services Security - Configure read-only access; use read-write only when required - communityJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Management Services Security - Configure read-only access; use read-write only when required - usmJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Management Services Security - Configure SNMP using the most secure method with more than one trusted serverJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

Network Security - Disable ICMP Source Quench - no-source-quenchJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Network Security - Set the source address for all route engine generated traffic - syslogJuniper Hardening JunOS 12 Devices ChecklistJuniper

AUDIT AND ACCOUNTABILITY

Network Security - Use the Out-of-Band (OOB) interface for all management related trafficJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Physical Security - Console Port - Configure the logout-on-disconnect featureJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Routing Protocol Security - Select the strongest algorithm that is supported by your equipment and your neighbors - ISISJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

SQL4-00-014000 - SQL Server and/or the operating system must protect its audit configuration from unauthorized modification.DISA STIG SQL Server 2014 Instance OS Audit v2r4Windows

AUDIT AND ACCOUNTABILITY

SQL4-00-014100 - SQL Server and the operating system must protect SQL Server audit features from unauthorized removal.DISA STIG SQL Server 2014 Instance OS Audit v2r4Windows

AUDIT AND ACCOUNTABILITY

TCAT-AS-000450 - Tomcat user UMASK must be set to 0027.DISA STIG Apache Tomcat Application Server 9 v3r4 MiddlewareUnix

CONFIGURATION MANAGEMENT

User Authentication Security - Centralized authentication - Use a strong shared secret that complies with your organization's policyJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Configure a password complexity policy - Numeric charactersJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Configure custom login classes to support engineers with different access levels using least privilegeJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

User Authentication Security - Configure login security options to hinder password guessing attacks - lockout-periodJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

User Authentication Security - Ensure the root account has been configured with a strong passwordJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

User Authentication Security - Restrict commands by job functionJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

VCFL-67-000008 - vSphere Client must be configured to use the HTTPS scheme.DISA STIG VMware vSphere 6.7 Virgo Client v1r2Unix

ACCESS CONTROL

WA00520 A22 - The web server must not be configured as a proxy server.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00520 A22 - The web server must not be configured as a proxy server.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WN12-SO-000039 - The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.DISA Windows Server 2012 and 2012 R2 DC STIG v3r7Windows

CONFIGURATION MANAGEMENT

WN12-SO-000039 - The system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.DISA Windows Server 2012 and 2012 R2 MS STIG v3r7Windows

CONFIGURATION MANAGEMENT