Item Search

NameAudit NamePluginCategory
1.5.3 Ensure 'Join Microsoft MAPS' is set to 'Enabled: Advanced'CIS Microsoft Defender Antivirus v1.0.0 L1 ServerWindows

CONFIGURATION MANAGEMENT

1.10 VMCH-80-000199CIS VMware vSphere 8.0 Virtual Machine STIG v1.0.0 CAT IIIVMware

CONFIGURATION MANAGEMENT

4.2 Ensure Federal Information Processing Standard (FIPS) is enabledCIS MongoDB 3.6 L2 Unix Audit v1.1.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.2.4 Enable AI /heuristic based malware detectionCIS FortiGate 7.4.x v1.0.1 L2FortiGate

SYSTEM AND INFORMATION INTEGRITY

4.4 Ensure Federal Information Processing Standard (FIPS) is enabledCIS MongoDB 7 v1.2.0 L2 WindowsWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

4.4 Ensure Federal Information Processing Standard (FIPS) is enabledCIS MongoDB 8 v1.0.0 L2 UnixUnix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Out of Scope SupplementalNIST macOS Catalina v1.5.0 - All ProfilesUnix

CONFIGURATION MANAGEMENT

GEN000000-AIX00040 - The securetcpip command must be usedDISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000000-AIX00060 - A baseline of AIX files with the TCB bit set must be checked weekly.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000241 - The system clock must be synchronized continuously, or at least daily - 'NTP daemon is running'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000242 - The system must use at least two time sources for clock synchronization - 'at least 2 servers are configured'DISA AIX 5.3 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

GEN000252 - The time synchronization configuration file (such as /etc/ntp.conf) must have mode 0640 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN000253 - The time synchronization configuration file (such as /etc/ntp.conf) must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000290 - The system must not have unnecessary accounts - 'ftp does not exsit'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000360 - Group Identifiers (GIDs) reserved for system accounts must not be assigned to non-system groups.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000380 - All Group Identifiers (GIDs) referenced in the /etc/passwd file must be defined in the /etc/group file.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000410 - The FTPS/FTP service on the system must be configured with the DoD login banner - '/etc/ftpaccess.ctl contains herald'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000452 - The system must display the date and time of the last successful account login upon login.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000500 - Graphical desktop environments provided by the system must automatically lock after 15 minutes of inactivity.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000510 - The system must display a publicly-viewable pattern during a graphical desktop environment session lock.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN000595 - Password hashes must have been generated using a FIPS 140-2 hashing algorithm - 'Verify no password hashes in /etc/passwd'DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000680 - The system must require passwords to contain no more than three consecutive repeating characters.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN000920 - The root account's home directory (other than /) must have mode 0700 - Not ApplicableDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001180 - All network services daemon files must have mode 0755 or less permissive - '/usr/sbin/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001210 - All system command files must not have extended ACLs - '/sbin/*'DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001240 - System files, programs, and directories must be group-owned by a system group - '/sbin/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001240 - System files, programs, and directories must be group-owned by a system group - '/usr/sbin/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001260 - System log files must have mode 0640 or less permissive - '/var/log/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001270 - System log files must not have extended ACLs, except as needed to support authorized software.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001360 - The NIS/NIS+/yp files must have mode 0755 or less permissive - '/var/yp/*'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001364 - The /etc/resolv.conf file must have mode 0644 or less permissive.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001367 - The /etc/hosts file must be group-owned by bin, sys, or system.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN001373 - The /etc/nsswitch.conf file must have mode 0644 or less permissive - Not ApplicableDISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001378 - The /etc/passwd file must be owned by root.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001379 - The /etc/passwd file must be group-owned by bin, security, sys, or system.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001394 - The /etc/group file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001420 - The /etc/security/passwd file must have mode 0400.DISA AIX 5.3 STIG v1r2Unix

IDENTIFICATION AND AUTHENTICATION

GEN001430 - The /etc/security/passwd file must not have an extended ACL.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN001490 - User home directories must not have extended ACLs.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN007850 - The DHCP client must not send dynamic DNS updates - 'updateDNS exists in /etc/dhcpc.opt'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN008050 - The /etc/ldap.conf file (or equivalent) must not contain passwords - 'bindpwd: is not unencrypted'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN008180 - The TLS certificate authority file must have mode 0644 (0755 for directories) or less permissiveDISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN008420 - The system must use available memory address randomization techniques.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN008460 - The system must have USB disabled unless needed - 'lsdev'DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN008620 - System BIOS or system controllers supporting password protection must have administrator accounts/passwords configured.DISA AIX 5.3 STIG v1r2Unix

ACCESS CONTROL

GEN009140 - The system must not have the chargen service active.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN009270 - The system must not have the netstat service active on the inetd process.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

GEN009290 - The system must not have the systat service active.DISA AIX 5.3 STIG v1r2Unix

CONFIGURATION MANAGEMENT

JUSX-VN-000004 - The Juniper SRX Services Gateway VPN device also fulfills the role of IDPS in the architecture, the device must inspect the VPN traffic in compliance with DoD IDPS requirements.DISA Juniper SRX Services Gateway VPN v3r2Juniper

ACCESS CONTROL

Monterey - Out of Scope SupplementalNIST macOS Monterey v1.0.0 - All ProfilesUnix

CONFIGURATION MANAGEMENT