Item Search

NameAudit NamePluginCategory
DTBI032-IE11 - Accessing data sources across domains must be disallowed (Internet zone).DISA STIG IE 11 v2r7Windows

ACCESS CONTROL

DTBI038-IE11 - Launching programs and files in IFRAME must be disallowed (Internet zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI061-IE11 - Java permissions must be configured with High Safety (Intranet zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI114-IE11 - The Initialize and script ActiveX controls not marked as safe property must be disallowed (Restricted Sites zone).DISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI115-IE11 - ActiveX controls and plug-ins must be disallowed (Restricted Sites zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI318-IE11 - Internet Explorer must be set to disallow users to add/delete sites.DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI390-IE11 - Script-initiated windows without size or position constraints must be disallowed (Restricted Sites zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI426-IE11 - Anti-Malware programs against ActiveX controls must be run for the Local Machine zone.DISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI435-IE11 - Java permissions must be disallowed (Locked Down Intranet zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI485-IE11 - Protected Mode must be enforced (Internet zone).DISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI490-IE11 - Protected Mode must be enforced (Restricted Sites zone).DISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI580-IE11 - Automatic prompting for file downloads must be disallowed (Restricted Sites zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI590-IE11 - Internet Explorer Processes for MIME handling must be enforced. (Reserved)DISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI600-IE11 - Internet Explorer Processes for MK protocol must be enforced (Explorer).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI614-IE11 - Internet Explorer Processes for Zone Elevation must be enforced (iexplore).DISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI635-IE11 - Internet Explorer Processes for Restrict File Download must be enforced (Explorer).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI760-IE11 - Browser must retain history on exit.DISA STIG IE 11 v2r7Windows

AUDIT AND ACCOUNTABILITY

DTBI770-IE11 - Deleting websites that the user has visited must be disallowed.DISA STIG IE 11 v2r7Windows

AUDIT AND ACCOUNTABILITY

DTBI835-IE11 - Internet Explorer Processes for Notification Bars must be enforced (iexplore).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI930-IE11 - .NET Framework-reliant components signed with Authenticode must be disallowed to run (Internet zone).DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI1005-IE11 - Dragging of content from different domains across windows must be disallowed (Restricted Sites zone).DISA STIG IE 11 v2r7Windows

ACCESS CONTROL

DTBI1010-IE11 - Internet Explorer Processes Restrict ActiveX Install must be enforced (Explorer).DISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI1060-IE11 - Prevent bypassing SmartScreen Filter warnings must be enabled.DISA STIG IE 11 v2r7Windows

SYSTEM AND INFORMATION INTEGRITY

DTBI1070-IE11 - Prevent per-user installation of ActiveX controls must be enabled.DISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI1115-IE11 - Use of the Tabular Data Control (TDC) ActiveX control must be disabled for the Internet Zone.DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI1120-IE11 - Use of the Tabular Data Control (TDC) ActiveX control must be disabled for the Restricted Sites Zone.DISA STIG IE 11 v2r7Windows

CONFIGURATION MANAGEMENT

DTBI1125-IE11 - VBScript must not be allowed to run in Internet Explorer (Internet zone) - Internet zoneDISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

DTBI1130-IE11 - VBScript must not be allowed to run in Internet Explorer (Restricted Sites zone) - Restricted Sites zoneDISA STIG IE 11 v2r7Windows

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000015 - The FortiGate firewall must use organization-defined filtering rules that apply to the monitoring of remote access traffic for the traffic from the VPN access points.DISA Fortigate Firewall STIG v1r4FortiGate

ACCESS CONTROL

FNFG-FW-000020 - The FortiGate firewall must generate traffic log entries containing information to establish what type of events occurred.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000035 - The FortiGate firewall must generate traffic log entries containing information to establish the source of the events, such as the source IP address at a minimum.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000040 - The FortiGate firewall must generate traffic log entries containing information to establish the outcome of the events, such as, at a minimum, the success or failure of the application of the firewall rule.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000045 - In the event that communication with the central audit server is lost, the FortiGate firewall must continue to queue traffic log records locally.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000055 - The FortiGate firewall must protect the traffic log from unauthorized modification of local log records.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

FNFG-FW-000070 - The FortiGate firewall must block outbound traffic containing denial-of-service (DoS) attacks to protect against the use of internal information systems to launch any DoS attacks against other networks or endpoints.DISA Fortigate Firewall STIG v1r4FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

FNFG-FW-000100 - The FortiGate firewall must send traffic log entries to a central audit server for management and configuration of the traffic log entries.DISA Fortigate Firewall STIG v1r4FortiGate

AUDIT AND ACCOUNTABILITY

SLES-12-010020 - The SUSE operating system must display the Standard Mandatory DoD Notice and Consent Banner until users acknowledge the usage conditions and take explicit actions to log on for further access to the local graphical user interface.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010050 - The SUSE operating system must display the approved Standard Mandatory DoD Notice before granting local or remote access to the system via a graphical user logon.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010070 - The SUSE operating system must utilize vlock to allow for session locking.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010100 - The SUSE operating system must conceal, via the session lock, information previously visible on the display with a publicly viewable image in the graphical user interface.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010110 - The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010111 - The SUSE operating system must restrict privilege elevation to authorized personnel.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010113 - The SUSE operating system must require re-authentication when using the 'sudo' command - sudo command.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010114 - The SUSE operating system must not be configured to bypass password requirements for privilege escalation.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010120 - The SUSE operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.DISA SLES 12 STIG v3r5Unix

ACCESS CONTROL

SLES-12-010140 - The SUSE operating system must enforce a delay of at least four (4) seconds between logon prompts following a failed logon attempt.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010220 - The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

SLES-12-010221 - The SUSE operating system must not have accounts configured with blank or null passwords.DISA SLES 12 STIG v3r5Unix

CONFIGURATION MANAGEMENT

SLES-12-010280 - The SUSE operating system must be configured to create or update passwords with a maximum lifetime of 60 days.DISA SLES 12 STIG v3r5Unix

IDENTIFICATION AND AUTHENTICATION

WPAW-00-000400 - Administrative accounts of all high-value IT resources must be assigned to a specific administrative tier in Active Directory to separate highly privileged administrative accounts from less privileged administrative accounts.DISA Microsoft Windows PAW STIG v3r2Windows

ACCESS CONTROL, CONFIGURATION MANAGEMENT