Item Search

NameAudit NamePluginCategory
1.189 WN16-MS-000010CIS Microsoft Windows Server 2016 STIG v4.0.0 MS CAT IWindows

ACCESS CONTROL

1.214 WN19-SO-000070CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.214 WN19-SO-000070CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.214 WN22-SO-000070CIS Microsoft Windows Server 2022 STIG v3.0.0 MS CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.214 WN22-SO-000070CIS Microsoft Windows Server 2022 STIG v3.0.0 DC CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.215 WN19-SO-000080CIS Microsoft Windows Server 2019 STIG v4.0.0 MS CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

1.215 WN19-SO-000080CIS Microsoft Windows Server 2019 STIG v4.0.0 DC CAT IIWindows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2 Ensure the SharePoint farm service account (database access account) is configured with the minimum privileges for the local server.CIS Microsoft SharePoint 2019 OS v1.0.0Windows

ACCESS CONTROL

2.3.8.1 Ensure 'Microsoft network client: Digitally sign communications (always)' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT

2.3.9.3 Ensure 'Microsoft network server: Digitally sign communications (if client agrees)' is set to 'Enabled'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

CONFIGURATION MANAGEMENT

3.12 Ensure the 'SYSADMIN' Role is Limited to Administrative or Built-in AccountsCIS Microsoft SQL Server 2019 v1.6.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

3.12 Ensure the 'SYSADMIN' Role is Limited to Administrative or Built-in AccountsCIS Microsoft SQL Server 2022 v1.3.0 L1 Database Engine MS_SQLDBMS_SQLDB

ACCESS CONTROL

4.10.44.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled'CIS Microsoft Intune for Windows 11 v5.0.0 L1Windows

AUDIT AND ACCOUNTABILITY

18.9.51.1.2 (L1) Ensure 'Enable Windows NTP Server' is set to 'Disabled' (MS only)CIS Microsoft Windows Server 2016 v4.0.0 L1 MSWindows

AUDIT AND ACCOUNTABILITY

18.9.53.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 NGWindows

AUDIT AND ACCOUNTABILITY

18.9.53.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

AUDIT AND ACCOUNTABILITY

18.9.53.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1Windows

AUDIT AND ACCOUNTABILITY

18.9.53.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled'CIS Microsoft Windows 11 Enterprise v5.1.0 L1 BLWindows

AUDIT AND ACCOUNTABILITY

18.9.53.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BLWindows

AUDIT AND ACCOUNTABILITY

18.9.53.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled'CIS Microsoft Windows 10 Enterprise v5.0.0 L1 BL NGWindows

AUDIT AND ACCOUNTABILITY

18.9.53.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled' (MS only)CIS Microsoft Windows Server 2022 v5.1.0 L1 MSWindows

AUDIT AND ACCOUNTABILITY

18.9.53.1.2 Ensure 'Enable Windows NTP Server' is set to 'Disabled' (MS only)CIS Microsoft Windows Server 2025 v2.1.0 L1 MSWindows

AUDIT AND ACCOUNTABILITY

Audit Other Logon/Logoff Events: MSFT Windows Server 2025 v2602 - Member ServerMSCT Windows Server 2025 MS v2602 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Other Object Access Events: MSFT Windows Server 2025 v2602 - Member ServerMSCT Windows Server 2025 MS v2602 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

Audit Other Policy Change Events: MSFT Windows Server 2025 v2602 - Member ServerMSCT Windows Server 2025 MS v2602 v1.0.0Windows

AUDIT AND ACCOUNTABILITY

DISA_STIG_Microsoft_Windows_2012_Server_DNS_v2r7.audit from DISA Microsoft Windows 2012 Server Domain Name System v2r7 STIGDISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows
IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.DISA IIS 10.0 Server v2r10Windows

AUDIT AND ACCOUNTABILITY

IIST-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 10.0 web server must be enabled.DISA Microsoft IIS 10.0 Server STIG v3r7Windows

AUDIT AND ACCOUNTABILITY

IISW-SV-000103 - Both the log file and Event Tracing for Windows (ETW) for the IIS 8.5 web server must be enabled.DISA IIS 8.5 Server v2r7Windows

AUDIT AND ACCOUNTABILITY

JBOS-AS-000470 - Network access to HTTP management must be disabled on domain-enabled application servers not designated as the domain controller.DISA JBoss Enterprise Application Platform 6.3 STIG v2r6Unix

ACCESS CONTROL

Network access: Remotely accessible registry paths and subpathsMSCT Windows Server 2012 R2 DC v1.0.0Windows

ACCESS CONTROL

Network access: Remotely accessible registry paths and subpathsMSCT Windows Server 2012 R2 MS v1.0.0Windows

ACCESS CONTROL

SQL4-00-011310 - Where SQL Server Audit is in use, SQL Server must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited at the server level.DISA STIG SQL Server 2014 Instance DB Audit v2r4MS_SQLDB

AUDIT AND ACCOUNTABILITY

WDNS-CM-000020 - The Windows 2012 DNS Servers zone database files must not be accessible for edit/write by users and/or processes other than the Windows 2012 DNS Server service account and/or the DNS database administrator.DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows

CONFIGURATION MANAGEMENT

WDNS-CM-000029 - The Windows 2012 DNS Server must be configured to prohibit or restrict unapproved ports and protocols.DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows

CONFIGURATION MANAGEMENT

WDNS-IA-000006 - The Windows 2012 DNS Server must be configured to enforce authorized access to the corresponding private key.DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows

IDENTIFICATION AND AUTHENTICATION

WDNS-SC-000003 - The Windows 2012 DNS Servers IP address must be statically defined and configured locally on the server.DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

WDNS-SC-000004 - The Windows 2012 DNS Server must return data information in responses to internal name/address resolution queries.DISA Microsoft Windows 2012 Server Domain Name System STIG v2r7Windows

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

WN16-MS-000010 - Only administrators responsible for the member server or standalone or nondomain-joined system must have Administrator rights on the system.DISA Microsoft Windows Server 2016 STIG v2r10Windows

ACCESS CONTROL

WN16-MS-000120 - Windows Server 2016 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2016 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN19-MS-000010 - Windows Server 2019 must only allow Administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2019 STIG v3r9Windows

ACCESS CONTROL

WN19-MS-000140 - Windows Server 2019 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2019 STIG v3r9Windows

CONFIGURATION MANAGEMENT

WN22-MS-000010 - Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL

WN22-MS-000010 - Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2022 STIG v2r10Windows

ACCESS CONTROL

WN22-MS-000140 - Windows Server 2022 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-MS-000140 - Windows Server 2022 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2022 STIG v2r10Windows

CONFIGURATION MANAGEMENT

WN25-MS-000010 - Windows Server 2025 must only allow administrators responsible for the member server or stand-alone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL

WN25-MS-000010 - Windows Server 2025 must only allow administrators responsible for the member server or stand-alone or nondomain-joined system to have Administrator rights on the system.DISA Microsoft Windows Server 2025 STIG v1r3Windows

ACCESS CONTROL

WN25-MS-000140 - Windows Server 2025 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-MS-000140 - Windows Server 2025 must be running Credential Guard on domain-joined member servers.DISA Microsoft Windows Server 2025 STIG v1r3Windows

CONFIGURATION MANAGEMENT