Item Search

NameAudit NamePluginCategory
1.2 Use the updated Linux KernelCIS Docker 1.11.0 v1.0.0 L1 LinuxUnix

SYSTEM AND INFORMATION INTEGRITY

1.2 Use the updated Linux KernelCIS Docker 1.6 v1.0.0 L1 LinuxUnix

SYSTEM AND INFORMATION INTEGRITY

1.27 RHEL-10-200530CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.28 RHEL-10-200531CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

1.74 UBTU-22-411010CIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.81 UBTU-24-400110CIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.171 SOL-11.1-070160CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.363 RHEL-09-652045CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.416 OL09-00-005020CIS Oracle Linux 9 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

2.8 Ensure Socket Peer-Credential Authentication is Used AppropriatelyCIS MySQL 5.6 Community Database L2 v2.0.0MySQLDB

CONFIGURATION MANAGEMENT

2.8 Ensure Socket Peer-Credential Authentication is Used AppropriatelyCIS MySQL 5.6 Enterprise Database L2 v2.0.0MySQLDB

CONFIGURATION MANAGEMENT

3.15 Ensure that Docker socket file ownership is set to root:dockerCIS Docker Community Edition v1.1.0 L1 DockerUnix

CONFIGURATION MANAGEMENT

4.4 Ensure excessive DML privileges are revokedCIS PostgreSQL 11 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT

4.4 Ensure excessive DML privileges are revokedCIS PostgreSQL 12 DB v1.1.0PostgreSQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.8 Ensure the set_user extension is installedCIS PostgreSQL 14 DB v 1.3.0PostgreSQLDB

ACCESS CONTROL

5.5 NFS - 'cifs.preserve_unix_security = on'TNS NetApp Data ONTAP 7GNetApp

CONFIGURATION MANAGEMENT

8.4.26 Ensure all but VGA mode on virtual machines is disabledCIS VMware ESXi 6.7 v1.3.0 Level 2VMware

CONFIGURATION MANAGEMENT

CD12-00-002400 - PostgreSQL must record time stamps, in audit records and application data that can be mapped to Coordinated Universal Time (UTC, formerly GMT).DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-004900 - PostgreSQL must generate audit records when privileges/permissions are added.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-005400 - PostgreSQL must generate audit records when unsuccessful attempts to delete privileges/permissions occur.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-005500 - PostgreSQL must be able to generate audit records when privileges/permissions are retrieved.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-005800 - PostgreSQL must generate audit records for all privileged activities or other system-level access.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-006100 - PostgreSQL must generate audit records when privileges/permissions are deleted.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD12-00-006400 - PostgreSQL must generate audit records when privileges/permissions are modified.DISA STIG Crunchy Data PostgreSQL DB v3r1PostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD16-00-000200 - PostgreSQL must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

ACCESS CONTROL

CD16-00-005600 - Access to database files must be limited to relevant processes and to authorized, administrative users.DISA Crunchy Data Postgres 16 STIG v1r3 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

CD16-00-009400 - PostgreSQL must be able to generate audit records when security objects are accessed.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD16-00-009600 - PostgreSQL must generate audit records when categories of information (e.g., classification levels/security levels) are accessed.DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

AUDIT AND ACCOUNTABILITY

CD16-00-012000 - PostgreSQL must generate audit records for all direct access to the database(s).DISA Crunchy Data Postgres 16 STIG v1r3 PostgreSQLDBPostgreSQLDB

AUDIT AND ACCOUNTABILITY

DKER-EE-005310 - Docker Enterprise socket file ownership must be set to root:docker.DISA STIG Docker Enterprise 2.x Linux/Unix v2r2Unix

CONFIGURATION MANAGEMENT

EP11-00-004000 - Access to external executables must be disabled or restricted.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

CONFIGURATION MANAGEMENT

EP11-00-004850 - The EDB Postgres Advanced Server password file must not be used.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

CONFIGURATION MANAGEMENT

EP11-00-004900 - The EDB Postgres Advanced Server must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for all cryptographic operations including generation of cryptographic hashes and data protection.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

EP11-00-008000 - The EDB Postgres Advanced Server must provide a warning to appropriate support staff when allocated audit record storage volume reaches 75% of maximum audit record storage capacity.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

AUDIT AND ACCOUNTABILITY

EP11-00-008700 - The EDB Postgres Advanced Server must disable network functions, ports, protocols, and services deemed by the organization to be nonsecure, in accord with the Ports, Protocols, and Services Management (PPSM) guidance.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

CONFIGURATION MANAGEMENT

EP11-00-009100 - The EDB Postgres Advanced Server must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of all encrypted sessions.EDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

OL08-00-030720 - OL 8 must authenticate the remote logging server for offloading audit logs.DISA Oracle Linux 8 STIG v2r9Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-000700 - Privileges to change PostgreSQL software modules must be limited.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

CONFIGURATION MANAGEMENT

PGS9-00-000800 - If passwords are used for authentication, PostgreSQL must transmit only encrypted representations of passwords.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

IDENTIFICATION AND AUTHENTICATION

PGS9-00-002300 - The audit information produced by PostgreSQL must be protected from unauthorized deletion - log filesDISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-008000 - PostgreSQL must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to generate and validate cryptographic hashes.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

PGS9-00-008400 - PostgreSQL must prohibit user installation of logic modules (functions, trigger procedures, views, etc.) without explicit privileged status.DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

CONFIGURATION MANAGEMENT

PGS9-00-010700 - PostgreSQL must protect its audit features from unauthorized access - LogsDISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

AUDIT AND ACCOUNTABILITY

PGS9-00-011500 - PostgreSQL must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).DISA STIG PostgreSQL 9.x on RHEL OS v2r5Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-08-030720 - RHEL 8 must authenticate the remote logging server for off-loading audit logs.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

AUDIT AND ACCOUNTABILITY

RHEL-10-200646 - RHEL 10 must encrypt, via the gtls driver, the transfer of audit records off-loaded onto a different system or media from the system being audited via rsyslog.DISA Red Hat Enterprise Linux 10 STIG v1r2Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-070160 - User .netrc files must not exist.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-070160 - User .netrc files must not exist.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

WBSP-AS-001740 - The WebSphere Application Server must remove organization-defined software components after updated versions have been installed.DISA IBM WebSphere Traditional 9 STIG v2r1 MiddlewareUnix

SYSTEM AND INFORMATION INTEGRITY

WPAW-00-002600 - If several PAWs are set up in virtual machines (VMs) on a host server, domain administrative accounts used to manage high-value IT resources must not have access to the VM host operating system (OS) (only domain administrative accounts designated to manage PAWs should be able to access the VM host OS).DISA Microsoft Windows PAW STIG v3r2Windows

CONFIGURATION MANAGEMENT