Item Search

NameAudit NamePluginCategory
ALMA-09-007500 - AlmaLinux OS 9 must automatically lock an account when three unsuccessful logon attempts occur.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-007610 - AlmaLinux OS 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-007720 - AlmaLinux OS 9 must automatically lock an account when three unsuccessful logon attempts occur during a 15-minute time period.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-008160 - AlmaLinux OS 9 must maintain an account lock until the locked account is manually released by an administrator; and not automatically after a set time.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

ACCESS CONTROL

ALMA-09-011240 - AlmaLinux OS 9 must disable core dumps for all users.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-011570 - AlmaLinux OS 9 must disable core dump backtraces.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-011680 - AlmaLinux OS 9 must disable the kernel.core_pattern.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-011900 - AlmaLinux OS 9 cron configuration files directory must be owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-014320 - The graphical display manager must not be the default target on AlmaLinux OS 9 unless approved.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-016630 - AlmaLinux OS 9 /etc/shadow- file must be group-owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-017180 - AlmaLinux OS 9 /etc/shadow file must have mode 0000 to prevent unauthorized access.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-018280 - AlmaLinux OS 9 must be configured so that the file integrity tool verifies extended attributes.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-020590 - The AlmaLinux OS 9 SSH server configuration file must be owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-021800 - AlmaLinux OS 9 must enable hardening for the Berkeley Packet Filter (BPF) just-in-time (JIT) compiler.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-022900 - AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-023560 - AlmaLinux OS 9 must configure a DNS processing mode set be Network Manager.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-023670 - AlmaLinux OS 9 systems using Domain Name Servers (DNS) resolution must have at least two name servers configured.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-023780 - AlmaLinux OS 9 must prevent special devices on nonroot local partitions.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-025540 - AlmaLinux OS 9 must use a separate file system for /var/tmp.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-025650 - AlmaLinux OS 9 must disable virtual system calls.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-025760 - AlmaLinux OS 9 must use cron logging.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-028730 - AlmaLinux OS 9 must not have the iprutils package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-029610 - AlmaLinux OS 9 must disable the Asynchronous Transfer Mode (ATM) kernel module.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-030930 - AlmaLinux OS 9 must not have the tuned package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

CONFIGURATION MANAGEMENT

ALMA-09-035440 - AlmaLinux OS 9 must block unauthorized peripherals before establishing a connection.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

IDENTIFICATION AND AUTHENTICATION

ALMA-09-041930 - AlmaLinux OS 9 must use a Linux Security Module configured to enforce limits on system services.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042040 - AlmaLinux OS 9 must have the policycoreutils package installed.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-042260 - A sticky bit must be set on all AlmaLinux OS 9 public directories.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND COMMUNICATIONS PROTECTION

ALMA-09-044130 - AlmaLinux OS 9 /var/log/messages file must be owned by root.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-044240 - AlmaLinux OS 9 /var/log/messages file must have mode 0640 or less permissive.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

SYSTEM AND INFORMATION INTEGRITY

ALMA-09-046220 - AlmaLinux OS 9 must generate audit records for any use of the "poweroff" command.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-046880 - AlmaLinux OS 9 must produce audit records containing information to establish the identity of any individual or process associated with the event.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-053920 - AlmaLinux OS 9 must have mail aliases to notify the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054360 - AlmaLinux OS 9 audit system must make full use of the audit storage space.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

ALMA-09-054470 - AlmaLinux OS 9 audit system must take appropriate action when the audit files have reached maximum size.DISA Cloud Linux AlmaLinux OS 9 STIG v1r6Unix

AUDIT AND ACCOUNTABILITY

UBTU-24-900320 - Ubuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the crontab command.DISA Canonical Ubuntu 24.04 LTS STIG v1r5Unix

AUDIT AND ACCOUNTABILITY

UBTU-24-900350 - Ubuntu 24.04 LTS must generate audit records for successful/unsuccessful uses of the delete_module syscall.DISA Canonical Ubuntu 24.04 LTS STIG v1r5Unix

AUDIT AND ACCOUNTABILITY

UBTU-24-900510 - Ubuntu 24.04 LTS must generate audit records when successful/unsuccessful attempts to modify the /etc/sudoers file occur.DISA Canonical Ubuntu 24.04 LTS STIG v1r5Unix

AUDIT AND ACCOUNTABILITY

UBTU-24-900750 - Ubuntu 24.04 LTS must generate audit records when successful/unsuccessful attempts to use the fdisk command.DISA Canonical Ubuntu 24.04 LTS STIG v1r5Unix

AUDIT AND ACCOUNTABILITY

UBTU-24-901280 - Ubuntu 24.04 LTS must have directories that contain system commands group-owned by root.DISA Canonical Ubuntu 24.04 LTS STIG v1r5Unix

AUDIT AND ACCOUNTABILITY

WN11-00-000005 - Domain-joined systems must use Windows 11 Enterprise Edition 64-bit version.DISA Microsoft Windows 11 STIG v2r7Windows

CONFIGURATION MANAGEMENT

WN11-00-000032 - Windows 11 systems must use a BitLocker PIN with a minimum length of six digits for pre-boot authentication.DISA Microsoft Windows 11 STIG v2r7Windows

IDENTIFICATION AND AUTHENTICATION

WN11-00-000105 - Simple Network Management Protocol (SNMP) must not be installed on the system.DISA Microsoft Windows 11 STIG v2r7Windows

CONFIGURATION MANAGEMENT

WN11-00-000110 - Simple TCP/IP Services must not be installed on the system.DISA Microsoft Windows 11 STIG v2r7Windows

CONFIGURATION MANAGEMENT

WN11-00-000140 - Inbound exceptions to the firewall on Windows 11 domain workstations must only allow authorized remote management hosts.DISA Microsoft Windows 11 STIG v2r7Windows

CONFIGURATION MANAGEMENT

WN11-00-000165 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB server.DISA Microsoft Windows 11 STIG v2r7Windows

CONFIGURATION MANAGEMENT

WN11-00-000230 - The system must notify the user when a Bluetooth device attempts to connect.DISA Microsoft Windows 11 STIG v2r7Windows

CONFIGURATION MANAGEMENT

WN11-AC-000010 - The number of allowed bad logon attempts must be configured to three or less.DISA Microsoft Windows 11 STIG v2r7Windows

ACCESS CONTROL

WN11-AU-000005 - The system must be configured to audit Account Logon - Credential Validation failures.DISA Microsoft Windows 11 STIG v2r7Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000054 - The system must be configured to audit Logon/Logoff - Account Lockout failures.DISA Microsoft Windows 11 STIG v2r7Windows

AUDIT AND ACCOUNTABILITY