Item Search

NameAudit NamePluginCategory
2.3.11.13 Ensure 'Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers' is set to 'Audit all' or higherCIS Microsoft Windows Server 2016 STIG v3.0.0 L1 MSWindows

AUDIT AND ACCOUNTABILITY

4.1.3.20 Ensure the audit configuration is immutableCIS CentOS Linux 8 Server L2 v2.0.0Unix

ACCESS CONTROL, MEDIA PROTECTION

4.1.3.41 Ensure the audit configuration is immutableCIS Amazon Linux 2 STIG v2.0.0 L2 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.3.41 Ensure the audit configuration is immutableCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L2 ServerUnix

ACCESS CONTROL, MEDIA PROTECTION

4.1.17 Ensure the audit configuration is immutableCIS CentOS 6 Server L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure the audit configuration is immutableCIS CentOS 6 Workstation L2 v3.0.0Unix

AUDIT AND ACCOUNTABILITY

4.1.17 Ensure the audit configuration is immutableCIS SUSE Linux Enterprise 12 v3.2.1 L2 WorkstationUnix

ACCESS CONTROL, MEDIA PROTECTION

5.2.3.20 Ensure the audit configuration is immutableCIS Oracle Linux 7 v4.0.0 L2 WorkstationUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.2.3.20 Ensure the audit configuration is immutableCIS Red Hat Enterprise Linux 7 v4.0.0 L2 WorkstationUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.2.3.20 Ensure the audit configuration is immutableCIS Red Hat EL8 Workstation L2 v3.0.0Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.2.3.20 Ensure the audit configuration is immutableCIS CentOS Linux 7 v4.0.0 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.2.3.20 Ensure the audit configuration is immutableCIS CentOS Linux 7 v4.0.0 L2 WorkstationUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.2.3.20 Ensure the audit configuration is immutableCIS Rocky Linux 8 Server L2 v2.0.0Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

6.1 Password protect database backupsCIS Sybase 15.0 L1 DB v1.1.0SybaseDB
6.3.3.20 Ensure the audit configuration is immutableCIS Ubuntu Linux 22.04 LTS v2.0.0 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

6.3.3.20 Ensure the audit configuration is immutableCIS Ubuntu Linux 20.04 LTS v3.0.0 L2 WorkstationUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

6.3.3.20 Ensure the audit configuration is immutableCIS Red Hat Enterprise Linux 9 v2.0.0 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

6.3.3.20 Ensure the audit configuration is immutableCIS Red Hat Enterprise Linux 9 v2.0.0 L2 WorkstationUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

6.3.3.20 Ensure the audit configuration is immutableCIS Rocky Linux 9 v2.0.0 L2 ServerUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

6.3.3.20 Ensure the audit configuration is immutableCIS Rocky Linux 9 v2.0.0 L2 WorkstationUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

6.4.3.20 Ensure the audit configuration is immutableCIS Debian Linux 11 v2.0.0 L2 WorkstationUnix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

Configure NetBIOS settingsMSCT Windows Server 2025 MS v2506 v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure NetBIOS settingsMSCT Windows 11 v24H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

DTAM045 - McAfee VirusScan On-Demand scan must be configured to scan all fixed, or local, disks and running processes - DrivesDISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

DTAM152 - McAfee VirusScan On-Access General Policies must be configured to not exclude any script processes from being scanned unless the process exclusions have been documented with, and approved by, the ISSO/ISSM/DAA.DISA McAfee VirusScan 8.8 Managed Client STIG v6r1Windows

SYSTEM AND INFORMATION INTEGRITY

Dynamic Code SettingsMSCT Edge v128 v1.0.0Windows
Dynamic Code SettingsMSCT Edge v133 v1.0.0Windows
Dynamic Code SettingsMSCT Edge v136 v1.0.0Windows
Dynamic Code SettingsMSCT Edge v137 v1.0.0Windows
Dynamic Code SettingsMSCT Edge v129 v1.0.0Windows
Minimum encryption settingsMSCT Microsoft 365 Apps for Enterprise 2206 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Minimum encryption settingsMSCT Office 2016 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Minimum encryption settingsMSCT M365 Apps for enterprise 2412 v1.0.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

Security Zones: Do not allow users to add/delete sitesMSCT Windows 10 v21H1 v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows 11 v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server v2004 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows 10 1903 v1.19.9Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows 11 v22H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows 11 v24H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows 10 v20H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows 10 v21H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server 1903 DC v1.19.9Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server 1903 MS v1.19.9Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server v2004 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server 2016 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server 2019 MS v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server 2022 v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server v20H2 DC v1.0.0Windows

CONFIGURATION MANAGEMENT

Security Zones: Do not allow users to add/delete sitesMSCT Windows Server 2025 DC v2506 v1.0.0Windows

CONFIGURATION MANAGEMENT

SPLK-CL-000320 - Splunk Enterprise must be configured to notify the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, when an attack is detected on multiple devices and hosts within its scope of coverage.DISA STIG Splunk Enterprise 7.x for Windows v3r1 REST APISplunk

CONFIGURATION MANAGEMENT