Item Search

NameAudit NamePluginCategory
1.1.1.1.3 Ensure passcode is set to have at least 1 numberCIS Zoom L1 v1.0.0Zoom

CONFIGURATION MANAGEMENT

1.1.10 - /etc/security/user - 'maxexpired <= 2'CIS AIX 5.3/6.1 L1 v1.1.0Unix

IDENTIFICATION AND AUTHENTICATION

1.8.1 Enable FIPS ModeCIS Cisco NX-OS v1.2.0 L2Cisco

IDENTIFICATION AND AUTHENTICATION

1.75 O19C-00-015500CIS Oracle Database 19c STIG v1.1.0 CAT I WindowsWindows

IDENTIFICATION AND AUTHENTICATION

1.75 O19C-00-015500CIS Oracle Database 19c STIG v1.1.0 CAT I UnixUnix

IDENTIFICATION AND AUTHENTICATION

2.2.3 (L2) Ensure 'Control use of the WebUSB API' is set to 'Enabled: Do not allow any site to request access to USB devices via the WebUSB API'CIS Google Chrome L2 v3.0.0Windows

CONFIGURATION MANAGEMENT

2.2.6 - AirWatch - Set Maximum Auto-lockAirWatch - CIS Apple iOS 9 v1.0.0 L1MDM

ACCESS CONTROL

2.61 (L1) Ensure 'Enable network prediction' is set to 'Enabled: Do not predict actions on any network connection'CIS Google Chrome Group Policy v1.0.0 L1Windows

CONFIGURATION MANAGEMENT

3.3.3.4 Set 'ip rip authentication key-chain'CIS Cisco IOS 12 L2 v4.0.0Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

3.10 (L1) Ensure 'Enable predict network actions` is set to 'Enabled: Do not predict actions on any network connection'CIS Google Chrome L1 v3.0.0Windows

CONFIGURATION MANAGEMENT

4.10.9.1.3 Ensure 'Prevent installation of devices that match any of these device IDs: Prevent installation of devices that match any of these device IDs' is set to 'PCI\CC_0C0A'CIS Microsoft Intune for Windows 10 v5.0.0 BLWindows

MEDIA PROTECTION

5.1.3.4 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No'CIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.3.17 Ensure only strong MAC algorithms are used - MACs employing FIPS 140-2 approved cryptographic hash algorithms.CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

ACCESS CONTROL

6 - Storage EncryptionNetApp Security Hardening Guide for ONTAP 9 v1.7.0Netapp_API
8.4.21 Ensure Host Guest File System Server is disabledCIS VMware ESXi 6.5 v1.0.0 Level 2VMware

SYSTEM AND INFORMATION INTEGRITY

18.6.8.1 (L1) Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.1 (L1) Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BLWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.1 (L1) Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 BL NGWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.1 (L1) Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 10 Stand-alone v4.0.0 L1 NGWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.4 Ensure 'Enable insecure guest logons' is set to 'Disabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.6.8.4 Ensure 'Enable insecure guest logons' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

CONFIGURATION MANAGEMENT

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-041160 - AlmaLinux OS 9 must prevent kernel profiling by nonprivileged users.DISA Cloud Linux AlmaLinux OS 9 STIG v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AZLX-23-001105 - Amazon Linux 2023 must have the libreswan package installed.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

AZLX-23-002490 - Amazon Linux 2023 password-auth must be configured to use a sufficient number of hashing rounds.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

AZLX-23-002495 - Amazon Linux 2023 system-auth must be configured to use a sufficient number of hashing rounds.DISA Amazon Linux 2023 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

CIS Amazon Linux Benchmark Level 2CIS Amazon Linux v2.1.0 L2Unix
ESXI-06-100010 - The SSH daemon must be configured to only use FIPS 140-2 approved ciphers.DISA VMware vSphere ESXi 6.0 STIG v1r5 UnixUnix

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-65-000011 - The ESXi host SSH daemon must be configured to use only the SSHv2 protocol.DISA STIG VMware vSphere ESXi OS 6.5 v2r4Unix

ACCESS CONTROL

F5BI-VN-300041 - The F5 BIG-IP appliance IPsec VPN must be configured to use FIPS-validated SHA-2 or higher for Internet Key Exchange (IKE).DISA F5 BIG-IP TMOS VPN STIG v1r1F5

SYSTEM AND COMMUNICATIONS PROTECTION

GEN000242 - The system must use at least two time sources for clock synchronization - service ntp server 2DISA STIG Solaris 10 SPARC v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN000242 - The system must use at least two time sources for clock synchronization - service ntp server 2DISA STIG Solaris 10 X86 v2r4Unix

AUDIT AND ACCOUNTABILITY

GEN000500-2 - The graphical desktop environment must set the idle timeout to no more than 15 minutes.DISA STIG for Oracle Linux 5 v2r1Unix

ACCESS CONTROL

GEN000500-2 - The graphical desktop environment must set the idle timeout to no more than 15 minutes.DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

ACCESS CONTROL

GEN002820-2 - The audit system must be configured to audit all discretionary access control permission modifications - 'fchmod'DISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix

AUDIT AND ACCOUNTABILITY

GEN002820-2 - The audit system must be configured to audit all discretionary access control permission modifications - 'fchmod'DISA STIG for Oracle Linux 5 v2r1Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

GEN006575 - The file integrity tool must use FIPS 140-2 approved cryptographic hashes for validating file contents.DISA AIX 5.3 STIG v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

JUNI-RT-000690 - The Juniper PE router must be configured to implement Protocol Independent Multicast (PIM) snooping for each Virtual Private LAN Services (VPLS) bridge domain.DISA STIG Juniper Router RTR v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

Number of changes allowed within the change interval (changes)Tenable Cisco ACICisco_ACI

IDENTIFICATION AND AUTHENTICATION

O365-WD-000008 - Open/Save of Word 2 and earlier binary documents and templates must be blocked.DISA Microsoft Office 365 ProPlus STIG v3r5Windows

SYSTEM AND COMMUNICATIONS PROTECTION

OH12-1X-000255 - OHS must have the SSLEngine, SSLProtocol, and SSLWallet directives enabled to meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when encrypting stored data - SSLEngineDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

IDENTIFICATION AND AUTHENTICATION

OH12-1X-000259 - OHS must have the SSLEngine, SSLProtocol, and SSLWallet directives enabled and configured to meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication - SSLEngineDISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-08-010160 - The RHEL 8 pam_unix.so module must be configured in the password-auth file to use a FIPS 140-2 approved cryptographic hashing algorithm for system authentication.DISA Red Hat Enterprise Linux 8 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010260 - The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (login.defs).DISA SUSE Linux Enterprise Server 15 STIG v2r6Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-010260 - The SUSE operating system must employ FIPS 140-2 approved cryptographic hashing algorithm for system authentication (login.defs).DISA SUSE Linux Enterprise Server 15 STIG v2r8Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-060010 - The operating system must use mechanisms for authentication to a cryptographic module meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for such authentication.DISA Solaris 11 SPARC STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-060010 - The operating system must use mechanisms for authentication to a cryptographic module meeting the requirements of applicable federal laws, Executive orders, directives, policies, regulations, standards, and guidance for such authentication.DISA Solaris 11 X86 STIG v3r6Unix

IDENTIFICATION AND AUTHENTICATION

WN11-UR-000090 - The 'Deny log on through Remote Desktop Services' user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.DISA Microsoft Windows 11 STIG v2r8Windows

ACCESS CONTROL