Item Search

NameAudit NamePluginCategory
1.1.11 - AirWatch - Erase all data before return, recycle, reassignment, or other dispositionAirWatch - CIS Google Android 4 v1.0.0 L1MDM

ACCESS CONTROL

1.5 Installing ISC BIND 9 - bind9 installationCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

CONFIGURATION MANAGEMENT

1.5 Installing ISC BIND 9 - named locationCIS BIND DNS v1.0.0 L1 Caching Only Name ServerUnix

CONFIGURATION MANAGEMENT

1.10.5 Ensure 'logging history severity level' is set to greater than or equal to '5'CIS Cisco ASA 9.x Firewall L1 v1.1.0Cisco

AUDIT AND ACCOUNTABILITY

5.4.2 Ensure system accounts are securedCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0Unix

ACCESS CONTROL

5.10 Set DCUI.Access to allow trusted users to override lockdown modeCIS VMware ESXi 6.5 v1.0.0 Level 1VMware

IDENTIFICATION AND AUTHENTICATION

8.3 Ensure the backup and restore tool, 'pgBackRest', is installed and configuredCIS PostgreSQL 11 OS v1.0.0Unix

CONTINGENCY PLANNING

18.6.11.4 Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

ACCESS CONTROL

18.9.102.6 Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled'CIS Windows 7 Workstation Level 1 v3.2.0Windows

SYSTEM AND INFORMATION INTEGRITY

18.10.10.2.10 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for operating system drives' is set to 'Enabled: True'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-001008 - All accounts on AIX system must have unique account names.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001009 - All accounts on AIX must be assigned unique User Identification Numbers (UIDs) and must authenticate organizational and non-organizational users (or processes acting on behalf of these users).DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001029 - AIX must provide xlock command in the CDE environment to let users retain their sessions lock until users are reauthenticated.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001044 - Any publically accessible connection to AIX operating system must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-001123 - AIX must require the change of at least 50% of the total number of characters when passwords are changed.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001126 - AIX Operating systems must enforce a 60-day maximum password lifetime restriction.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-001136 - AIX must require passwords to contain no more than three consecutive repeating characters.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002001 - AIX must produce audit records containing information to establish what the date, time, and type of events that occurred.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002004 - AIX must produce audit records containing information to establish the source and the identity of any individual or process associated with an event.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002013 - Audit logs on the AIX system must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-002062 - AIX must remove !authenticate option from sudo config files.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002064 - IP forwarding for IPv4 must not be enabled on AIX unless the system is a router.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002065 - AIX must be configured with a default gateway for IPv6 if the system uses IPv6 unless the system is a router.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002072 - AIX system files, programs, and directories must be group-owned by a system group.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002082 - AIX time synchronization configuration file must be group-owned by bin, or system.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002087 - All files and directories contained in users home directories on AIX must be group-owned by a group in which the home directory owner is a member.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002101 - AIX must monitor and record unsuccessful remote logins.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002110 - AIX must setup SSH daemon to disable revoked public keys.DISA IBM AIX 7.x STIG v3r3Unix

IDENTIFICATION AND AUTHENTICATION

AIX7-00-002117 - AIX must turn off X11 forwarding for the SSH daemon.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002124 - If AIX SSH daemon is required, the SSH daemon must only listen on the approved listening IP addresses.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002127 - AIX system must require authentication upon booting into single-user and maintenance modes.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002128 - If bash is used, AIX must display logout messages.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002129 - If Bourne / ksh shell is used, AIX must display logout messages.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL

AIX7-00-002140 - The AIX /etc/hosts file must be owned by root.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003124 - The AIX systems access control program must be configured to grant or deny system access to specific hosts.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003127 - The control script lists of preloaded libraries must contain only absolute paths on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003128 - The global initialization file lists of preloaded libraries must contain only absolute paths on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003131 - AIX package management tool must be used daily to verify system software.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003132 - The AIX DHCP client must not send dynamic DNS updates.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003141 - All AIX interactive users must be assigned a home directory in the passwd file and the directory must exist.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003201 - The AIX operating system must be configured to authenticate using Multi Factor Authentication.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003202 - The AIX operating system must be configured to use Multi Factor Authentication for remote connections.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

ARST-ND-000690 - The Arista network devices must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA Arista MLS EOS 4.X NDM STIG v2r2Arista

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

ARST-ND-000690 - The Arista network devices must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA STIG Arista MLS EOS 4.2x NDM v2r1Arista

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

FGFW-ND-000260 - The FortiGate devices must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.DISA Fortigate Firewall NDM STIG v1r4FortiGate

MAINTENANCE

JUNI-ND-001190 - The Juniper router must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA STIG Juniper Router NDM v3r2Juniper

MAINTENANCE

KNOX-07-001700 - The Samsung whitelist must be configured to not include applications that Transmit MD diagnostic data to non-DoD servers.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-002000 - The Samsung whitelist must be configured to not include applications that Allows synchronization of data.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

PHTN-40-000267 - The Photon operating system must be configured to use the pam_deny.so module.DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r2Unix

CONFIGURATION MANAGEMENT

WBLC-08-000223 - Oracle WebLogic must ensure authentication of both client and server during the entire session.Oracle WebLogic Server 12c Linux v2r2 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION