Item Search

NameAudit NamePluginCategory
1.2.3 Set 'seconds' for 'ssh timeout' for 60 seconds or lessCIS Cisco IOS XR 7.x v1.0.1 L1Cisco

IDENTIFICATION AND AUTHENTICATION

1.9 CISC-ND-000210CIS Cisco IOS Router NDM STIG v1.1.0 CAT IICisco

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.48 RHEL-10-200621CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIUnix

IDENTIFICATION AND AUTHENTICATION

1.50 CISC-RT-000490CIS Cisco IOS XR Router RTR STIG v1.0.0 CAT IICisco

ACCESS CONTROL

1.52 CISC-RT-000590CIS Cisco IOS XE Switch RTR STIG v1.1.0 CAT IIICisco

CONFIGURATION MANAGEMENT

1.73 O19C-00-015300CIS Oracle Database 19c STIG v1.1.0 CAT II OracleDBOracleDB

IDENTIFICATION AND AUTHENTICATION

1.96 WN16-CC-000030CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IIWindows

CONFIGURATION MANAGEMENT

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.2 Ensure net.ipv4.conf.all.forwarding is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Debian Linux 12 v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS SUSE Linux Enterprise 16 v1.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.3 Ensure net.ipv4.conf.default.forwarding is configuredCIS Ubuntu Linux 24.04 LTS v2.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.8 Ensure net.ipv4.conf.all.accept_redirects is configuredCIS Oracle Linux 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.8 Ensure net.ipv4.conf.all.accept_redirects is configuredCIS AlmaLinux OS 8 v4.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.8 Ensure net.ipv4.conf.all.accept_redirects is configuredCIS Red Hat Enterprise Linux 10 v1.0.1 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.3.1.8 Ensure net.ipv4.conf.all.accept_redirects is configuredCIS Rocky Linux 10 v1.0.0 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

3.3.1.8 Ensure net.ipv4.conf.all.accept_redirects is configuredCIS Rocky Linux 8 v3.0.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

3.4.1.1 Ensure ipfw is enabled and configuredCIS FreeBSD 14 v1.0.1 L1Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.22 (L1) Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT

5.22 Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Windows 7 Workstation Level 1 v3.2.0Windows

CONFIGURATION MANAGEMENT

5.22 Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0Windows

CONFIGURATION MANAGEMENT

5.25 Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

CONFIGURATION MANAGEMENT

5.26 Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

5.26 Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

82.27 Ensure 'Routing and Remote Access (RemoteAccess)' is set to 'Disabled'CIS Microsoft Intune for Windows 10 v5.0.0 L1Windows

CONFIGURATION MANAGEMENT

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - fingerJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - telnetJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - Disable insecure or unnecessary access services (telnet, J-Web over HTTP, FTP, etc.) - xnm-clear-textJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Access Security - Enable required secure access services - J-Web over HTTPSJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Access Security - J-Web - Set session-limit restrictions suitable for your environmentJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Access Security - J-Web - Terminate idle connections by setting the idle-time valueJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Access Security - SSH - Deny Root loginsJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Access Security - SSH - Set connection-limit and rate-limit restrictions - connection-limitJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

AMLS-L3-000100 - The Arista Multilayer Switch must enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.DISA STIG Arista MLS DCS-7000 Series RTR v1r4Arista

ACCESS CONTROL

BIND-9X-001150 - The BIND 9.x server signature generation using the key signing key (KSK) must be done offline, using the KSK-private key stored offline.DISA BIND 9.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

CISC-RT-000250 - The Cisco perimeter switch must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.DISA Cisco IOS Switch RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000250 - The Cisco perimeter switch must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

ACCESS CONTROL

CISC-RT-000250 - The Cisco perimeter switch must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

ACCESS CONTROL

CISC-RT-000590 - The Cisco MPLS switch must be configured to use its loopback address as the source address for LDP peering sessions.DISA Cisco IOS XE Switch RTR STIG v3r4Cisco

CONFIGURATION MANAGEMENT

CISC-RT-000630 - The Cisco PE switch must be configured to have each Virtual Routing and Forwarding (VRF) instance bound to the appropriate physical or logical interfaces to maintain traffic separation between all MPLS L3VPNs.DISA Cisco NX OS Switch RTR STIG v3r4Cisco

CONTINGENCY PLANNING

Firewall Filter - Protect the Routing Engine using a default deny firewall filterJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Management Services Security - Allow SNMP queries and/or send traps to more than one trusted server - client-list restrictJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Management Services Security - Community strings and USM passwords should be difficult to guess and should follow a password policyJuniper Hardening JunOS 12 Devices ChecklistJuniper

IDENTIFICATION AND AUTHENTICATION

Management Services Security - Configure automated secure configuration backups to more than one trusted server - transfer-intervalJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONTINGENCY PLANNING

Management Services Security - Configure SNMP using the most secure method with more than one trusted server - v3 configuredJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

Network Security - Disable ICMP timestamp & record route requests - no-ping-time-stampJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Network Security - Ensure IP directed broadcast has not been configuredJuniper Hardening JunOS 12 Devices ChecklistJuniper

SYSTEM AND COMMUNICATIONS PROTECTION

Network Security - Ensure Source Routing has not been configuredJuniper Hardening JunOS 12 Devices ChecklistJuniper

CONFIGURATION MANAGEMENT

VCPG-70-000010 - The vPostgres database must use 'md5' for authentication.DISA STIG VMware vSphere 7.0 PostgreSQL v1r2Unix

IDENTIFICATION AND AUTHENTICATION