Item Search

NameAudit NamePluginCategory
2.2.6 Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users'CIS Windows 7 Workstation Level 1 v3.2.0Windows

ACCESS CONTROL

2.2.6 Ensure 'Allow log on through Remote Desktop Services' is set to 'Administrators, Remote Desktop Users'CIS Microsoft Windows 10 Stand-alone v5.0.0 L1 BL NGWindows

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

3.3.5 Secure the JDK 32-bit runtime library - FILE_PERMISSIONSCIS IBM DB2 9 Benchmark v3.0.1 Level 2 OS WindowsWindows
18.6.8.2 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L1 DCWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.2 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows Server 2025 Stand-alone v2.0.0 L1 MSWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows Server 2025 v2.1.0 L1 DCWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.10.9.2.14 (L1) Ensure 'Require additional authentication at startup: Allow BitLocker without a compatible TPM' is set to 'Enabled: False'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

ACCESS CONTROL

19.1.3.2 Ensure 'Force specific screen saver: Screen saver executable name' is set to 'Enabled: scrnsave.scr'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

ACCESS CONTROL

AIX7-00-001000 - AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001007 - If AIX is using LDAP for authentication or account information, the /etc/ldap.conf file (or equivalent) must not contain passwords.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001014 - The AIX system must automatically remove or disable emergency accounts after the crisis is resolved or 72 hours.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001019 - AIX device files and directories must only be writable by users with a system account or as configured by the vendor.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001028 - AIX must provide the lock command to let users retain their session lock until users are reauthenticated.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001031 - All AIX public directories must be owned by root or an application account.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-001033 - AIX default system accounts (with the exception of root) must not be listed in the cron.allow file or must be included in the cron.deny file, if cron.allow does not exist.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002071 - AIX log files must be owned by a system group.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND INFORMATION INTEGRITY

AIX7-00-002078 - AIX cron and crontab directories must be owned by root or bin.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002081 - AIX time synchronization configuration file must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002083 - The AIX /etc/group file must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002091 - The AIX /etc/group file must have mode 0644 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002104 - The AIX SSH server must use SSH Protocol 2.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002114 - AIX must turn on SSH daemon privilege separation.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002142 - The AIX /etc/hosts file must have a mode of 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002145 - The AIX /etc/syslog.conf file must be group-owned by system.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002202 - The AIX audit configuration files must be set to 640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-003000 - AIX must automatically lock after 15 minutes of inactivity in the CDE Graphical desktop environment.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003004 - AIX SSH private host key files must have mode 0600 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003013 - AIX passwd.nntp file must have mode 0600 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003055 - If AIX server is not functioning as a network router, the routed daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003056 - If rwhod is not required on AIX, the rwhod daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003061 - The aixmibd daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003082 - The imap2 service must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003090 - If automated file system mounting tool is not required on AIX, it must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-003097 - AIX must protect against or limit the effects of Denial of Service (DoS) attacks by ensuring AIX is implementing rate-limiting measures on impacted network interfaces.DISA IBM AIX 7.x STIG v3r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-003099 - AIX must allow admins to send a message to a user who logged in currently.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003100 - The AIX SSH daemon must be configured to only use FIPS 140-2 approved ciphers.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-003125 - All AIX files and directories must have a valid group owner.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003134 - AIX must not process ICMP timestamp requests.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003135 - AIX must not respond to ICMPv6 echo requests sent to a broadcast address.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003140 - The AIX root user home directory must not be the root directory (/).DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

CASA-ND-001140 - The Cisco ASA must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of non-local maintenance and diagnostic communications.DISA STIG Cisco ASA NDM v2r5Cisco

MAINTENANCE

CISC-ND-001200 - The Cisco switch must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA Cisco NX OS Switch NDM STIG v3r6Cisco

MAINTENANCE

CISC-ND-001200 - The Cisco switch must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA Cisco IOS XE Switch NDM STIG v3r6Cisco

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

DISA_VMware_vSphere_8.0_vCenter_Appliance_User_Interface_(UI)_STIG_v2r1.audit from DISA VMware vSphere 8.0 vCenter Appliance User Interface (UI) STIG v2r1DISA VMware vSphere 8.0 vCenter Appliance User Interface (UI) STIG v2r1Unix
KNOX-07-002000 - The Samsung whitelist must be configured to not include applications that Allows synchronization of data.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

PHTN-40-000246 - The Photon operating system must restrict core dumps.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT

SYMP-NM-000300 - The Symantec ProxySG must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.DISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

MAINTENANCE