Item Search

NameAudit NamePluginCategory
1 - Remove or Disable Example Content - ExampleDSTNS Best Practice JBoss 7 LinuxUnix

CONFIGURATION MANAGEMENT

1.5.4 Ensure prelink is disabledCIS Distribution Independent Linux Server L1 v2.0.0Unix

AUDIT AND ACCOUNTABILITY

2.1 Enable Automatic Updates - app.update.autoCIS Mozilla Firefox 38 ESR Linux L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.1 Enable Automatic Updates - app.update.staging.enabledCIS Mozilla Firefox 38 ESR Windows L1 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.1 Enable Automatic Updates - app.update.staging.enabledCIS Mozilla Firefox 38 ESR Linux L1 v1.0.0Unix

SYSTEM AND INFORMATION INTEGRITY

2.2.1 - Configuring SSH - installation - 'openssh.base.server is installed'CIS AIX 5.3/6.1 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.2.1 - Configuring SSH - installation - 'openssh.license is installed'CIS AIX 5.3/6.1 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.2.7 Ensure a tftp server is not installedCIS Amazon Linux 2023 Server L1 v1.0.0Unix

CONFIGURATION MANAGEMENT

2.3.10.9 (L1) Configure 'Network access: Remotely accessible registry paths and sub-paths' is configuredCIS Microsoft Windows Server 2008 R2 Member Server Level 1 v3.3.1Windows

ACCESS CONTROL

2.4.1.1 Ensure cron daemon is enabled and activeCIS Debian Linux 12 v1.1.0 L1 ServerUnix

CONFIGURATION MANAGEMENT

2.4.1.1 Ensure cron daemon is enabled and activeCIS SUSE Linux Enterprise 15 v2.0.1 L1 WorkstationUnix

CONFIGURATION MANAGEMENT

2.5 Create Separate Partition for /varCIS Ubuntu 12.04 LTS Benchmark L1 v1.1.0Unix

CONFIGURATION MANAGEMENT

3 - Audit Logging - HandlerTNS Best Practice JBoss 7 LinuxUnix

AUDIT AND ACCOUNTABILITY

4.2 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iOS 10 v2.0.0 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.2 Ensure 'Software Update' returns 'Your software is up to date.'MobileIron - CIS Apple iOS 11 v1.0.0 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

4.2 Ensure excessive administrative privileges are revokedCIS PostgreSQL 10 DB v1.0.0PostgreSQLDB

ACCESS CONTROL

4.2 Ensure excessive administrative privileges are revokedCIS PostgreSQL 16 DB v1.0.0PostgreSQLDB

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.1.6.1 (L2) Ensure that collaboration invitations are sent to allowed domains onlyCIS Microsoft 365 Foundations v5.0.0 L2 E3microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.6.1 (L2) Ensure that collaboration invitations are sent to allowed domains onlyCIS Microsoft 365 Foundations v5.0.0 L2 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.2 Ensure PostgreSQL is Bound to an IP AddressCIS PostgreSQL 13 DB v1.2.0PostgreSQLDB

PLANNING, SYSTEM AND SERVICES ACQUISITION

6.12 Ensure all HTTP Header Logging options are enabled - RefererCIS Palo Alto Firewall 8 Benchmark L1 v1.0.0Palo_Alto

AUDIT AND ACCOUNTABILITY

10.3.5 Ensure 'Allow Azure services on the trusted services list to access this storage account' is Enabled for Storage Account AccessCIS Microsoft Azure Foundations v4.0.0 L2microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

12 - Remove and mask informational headers - JSP ConfigurationTNS Best Practice JBoss 7 LinuxUnix

SYSTEM AND COMMUNICATIONS PROTECTION

17 - Setup a security domainTNS Best Practice JBoss 7 LinuxUnix

CONFIGURATION MANAGEMENT

18 - Role Based Authentication per queueTNS Best Practice JBoss 7 LinuxUnix

ACCESS CONTROL

20.52 Ensure 'Permissions for the Windows installation directory conform to minimum requirements'CIS Microsoft Windows Server 2019 STIG v3.0.0 STIG MSWindows

ACCESS CONTROL

20.52 Ensure 'Permissions for the Windows installation directory conform to minimum requirements'CIS Microsoft Windows Server 2019 STIG v3.0.0 STIG DCWindows

ACCESS CONTROL

Adtran : Disable SSLv2TNS Adtran AOS Best Practice AuditAdtran

CONFIGURATION MANAGEMENT

Adtran : Enable NTPTNS Adtran AOS Best Practice AuditAdtran
Adtran : Enable service password-encryptionTNS Adtran AOS Best Practice AuditAdtran

IDENTIFICATION AND AUTHENTICATION

Adtran : Encrypt enable passwordTNS Adtran AOS Best Practice AuditAdtran

IDENTIFICATION AND AUTHENTICATION

Adtran : Ensure DHCP is Disabled unless neededTNS Adtran AOS Best Practice AuditAdtran

CONFIGURATION MANAGEMENT

Adtran : Ensure the log level is set at an appropriate settingTNS Adtran AOS Best Practice AuditAdtran

AUDIT AND ACCOUNTABILITY

Adtran : Set 'login' BannerTNS Adtran AOS Best Practice AuditAdtran

ACCESS CONTROL

Adtran : SNMP 'PUBLIC' community string not usedTNS Adtran AOS Best Practice AuditAdtran

IDENTIFICATION AND AUTHENTICATION

Adtran : Web Session Timeout <= 900 secsTNS Adtran AOS Best Practice AuditAdtran

ACCESS CONTROL

CISC-RT-000010 - The Cisco router must be configured to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.DISA Cisco IOS XE Router RTR STIG v3r3Cisco

ACCESS CONTROL

CISC-RT-000890 - The Cisco multicast Designated switch (DR) must be configured to set the shortest-path tree (SPT) threshold to infinity to minimalize source-group (S, G) state within the multicast topology where Any Source Multicast (ASM) is deployed.DISA Cisco NX OS Switch RTR STIG v3r3Cisco

CONFIGURATION MANAGEMENT

Configuration files should be secured against unauthorized access.TNS IBM HTTP Server Best PracticeWindows
Configuration files should be secured against unauthorized access.TNS IBM HTTP Server Best PracticeUnix
ESXi : set-dcui-accessVMWare vSphere 5.X Hardening GuideVMware
EX13-EG-000290 - The Exchange application directory must be protected from unauthorized access.DISA Microsoft Exchange 2013 Edge Transport Server STIG v1r6Windows

CONFIGURATION MANAGEMENT

FFOX-00-000006 - Firefox must be configured to not automatically execute or download MIME types that are not authorized for auto-download.DISA STIG Mozilla Firefox Linux v6r6Unix

SYSTEM AND INFORMATION INTEGRITY

IIST-SV-000110 - The IIS 10.0 web server must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 web server events.DISA IIS 10.0 Server v3r3Windows

AUDIT AND ACCOUNTABILITY

Logs containing auditing information should be secured at the directory level.TNS IBM HTTP Server Best PracticeUnix

AUDIT AND ACCOUNTABILITY

SHPT-00-000190 - SharePoint must enforce organizational requirements to implement separation of duties through assigned information access authorizations.DISA STIG SharePoint 2010 v1r9Windows

ACCESS CONTROL

SLES-12-010499 - The SUSE operating system must use a file integrity tool to verify correct operation of all security functions.DISA SLES 12 STIG v3r2Unix

SYSTEM AND INFORMATION INTEGRITY

SYMP-AG-000500 - If reverse proxy is used for validating and restricting certs from external entities, and this function is required by the SSP, Symantec ProxySG providing user authentication intermediary services using PKI-based user authentication must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of protected sessions.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

WBSP-AS-001230 - The WebSphere Application Server default keystore passwords must be changed.DISA IBM WebSphere Traditional 9 STIG v1r1 MiddlewareUnix

IDENTIFICATION AND AUTHENTICATION

WG080 A22 - Installation of a compiler on production web server is prohibited.DISA STIG Apache Server 2.2 Unix v1r11Unix