Item Search

NameAudit NamePluginCategory
1.5 Installing ISC BIND 9 - named locationCIS BIND DNS v1.0.0 L1 Authoritative Name ServerUnix

CONFIGURATION MANAGEMENT

1.5 Installing ISC BIND 9 - named locationCIS BIND DNS v3.0.1 Authoritative Name ServerUnix

CONFIGURATION MANAGEMENT

1.5 Installing ISC BIND 9 - named locationCIS BIND DNS v3.0.1 Caching Only Name ServerUnix

CONFIGURATION MANAGEMENT

2.3.7.1 (L1) Ensure 'Interactive logon: Do not display last user name' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1 BitlockerWindows

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1Windows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.6.8.7 Ensure 'Require Encryption' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 L1 BLWindows

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

18.8.7.1 (L1) Ensure 'Allow remote access to the Plug and Play interface' is set to 'Disabled'CIS Microsoft Windows Server 2008 Member Server Level 1 v3.3.1Windows

MEDIA PROTECTION

18.9.11.1.4 (BL) Ensure 'Choose how BitLocker-protected fixed drives can be recovered: Recovery Password' is set to 'Enabled: Allow 48-digit recovery password'CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

ACCESS CONTROL, CONTINGENCY PLANNING

18.9.11.3.4 (BL) Ensure 'Choose how BitLocker-protected removable drives can be recovered: Recovery Password' is set to 'Enabled: Do not allow 48-digit recovery password'CIS Microsoft Windows 8.1 v2.4.1 L2 BitlockerWindows

ACCESS CONTROL, CONTINGENCY PLANNING

18.10.9.2.4 (L1) Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Allow data recovery agent' is set to 'Enabled: False'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.2.1 Ensure 'Allow enhanced PINs for startup' is set to 'Enabled'CIS Microsoft Windows 11 Stand-alone v5.0.0 BLWindows

IDENTIFICATION AND AUTHENTICATION

18.10.10.2.6 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'CIS Microsoft Windows 10 Enterprise v5.0.0 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.2.6 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Recovery Key' is set to 'Enabled: Do not allow 256-bit recovery key'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.2.8 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Save BitLocker recovery information to AD DS for operating system drives' is set to 'Enabled: True'CIS Microsoft Windows 11 Enterprise v5.1.0 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.2.10 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for operating system drives' is set to 'Enabled: True'CIS Microsoft Windows 11 Enterprise v5.1.0 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.2.10 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for operating system drives' is set to 'Enabled: True'CIS Microsoft Windows 11 Enterprise v5.1.0 L2 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.10.2.10 Ensure 'Choose how BitLocker-protected operating system drives can be recovered: Do not enable BitLocker until recovery information is stored to AD DS for operating system drives' is set to 'Enabled: True'CIS Microsoft Windows 10 Enterprise v5.0.0 BLWindows

SYSTEM AND COMMUNICATIONS PROTECTION

18.10.36.1 (L1) Ensure 'Turn off location' is set to 'Enabled'CIS Microsoft Windows 10 EMS Gateway v3.0.0 L1Windows

CONFIGURATION MANAGEMENT

AIX7-00-002143 - AIX cron and crontab directories must have a mode of 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002146 - The AIX /etc/syslog.conf file must have a mode of 0640 or less permissive.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-002201 - The AIX audit configuration files must be group-owned by audit.DISA IBM AIX 7.x STIG v3r3Unix

AUDIT AND ACCOUNTABILITY

AIX7-00-003003 - AIX must set inactivity time-out on login sessions and terminate all login sessions after 10 minutes of inactivity.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-003009 - All system command files must not have extended ACLs.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003017 - AIX NFS server must be configured to restrict file system access to local hosts.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003019 - The AIX user home directories must not have extended ACLs.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003022 - AIX must disable trivial file transfer protocol.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003029 - AIX must enforce a delay of at least 4 seconds between login prompts following a failed login attempt.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003033 - All AIX Group Identifiers (GIDs) referenced in the /etc/passwd file must be defined in the /etc/group file.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003035 - The sticky bit must be set on all public directories on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003048 - If SNMP is not required on AIX, the snmpd service must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003049 - The AIX DHCP client must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003051 - If IPv6 is not utilized on AIX server, the autoconf6 daemon must be disabled.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003066 - The ttdbserver daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003080 - The rquotad daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003083 - The pop3 daemon must be disabled on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003102 - AIX must turn on enhanced Role-Based Access Control (RBAC) to isolate security functions from nonsecurity functions, to grant system privileges to other operating system admins, and prohibit user installation of system software without explicit privileged status.DISA IBM AIX 7.x STIG v3r3Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AIX7-00-003117 - SMTP service must not have the EXPN or VRFY features active on AIX systems.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003123 - NIS maps must be protected through hard-to-guess domain names on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003129 - The local initialization file library search paths must contain only absolute paths on AIX.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003137 - AIX must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003139 - The .rhosts file must not be supported in AIX PAM.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

AIX7-00-003204 - The AIX operating system must be configured to use a valid server_ca.pem file.DISA IBM AIX 7.x STIG v3r3Unix

CONFIGURATION MANAGEMENT

CISC-ND-001200 - The Cisco switch must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of remote maintenance sessions.DISA Cisco IOS Switch NDM STIG v3r8Cisco

IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

F5BI-AP-300152 - The F5 BIG-IP appliance must be configured to enable the secure cookie flag.DISA F5 BIG-IP TMOS ALG STIG v1r3F5

SYSTEM AND COMMUNICATIONS PROTECTION

KNOX-07-005500 - The Samsung must be configured to disable exceptions to the access control policy.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

KNOX-07-005500 - The Samsung must be configured to disable exceptions to the access control policy.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT

VCEM-67-000013 - ESX Agent Manager must have mappings set for Java servlet pages.DISA STIG VMware vSphere 6.7 EAM Tomcat v1r4Unix

CONFIGURATION MANAGEMENT

WBLC-08-000223 - Oracle WebLogic must ensure authentication of both client and server during the entire session.Oracle WebLogic Server 12c Linux v2r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WBLC-08-000223 - Oracle WebLogic must ensure authentication of both client and server during the entire session.Oracle WebLogic Server 12c Windows v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION