Item Search

NameAudit NamePluginCategory
1.4.9 Ensure GRUB 2 is configured to enable poisoning of SLUB/SLAB objects to mitigate use-after-free vulnerabilitiesCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIGUnix

SYSTEM AND COMMUNICATIONS PROTECTION

1.13.3.1.2 Ensure 'Display Level 1 attachments' is set to DisabledCIS Microsoft Office Outlook 2013 v1.1.0 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

1.13.3.1.2 Ensure 'Display Level 1 attachments' is set to DisabledCIS Microsoft Office Outlook 2016 v1.1.0 Level 1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

2.2.4.7.2.2.3 Ensure 'Excel 2 macrosheets and add-in files' is set to 'Enabled: Open/Save blocked, use open policy'CIS Microsoft Office Enterprise v1.2.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

4.10 Ensure 'notListedCgisAllowed' is set to falseCIS IIS 7 L1 v1.8.0Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000090 - The Apache web server must produce log records containing sufficient information to establish what type of events occurred.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000160 - The Apache web server must use a logging mechanism that is configured to alert the (ISSO) and System Administrator (SA) in the event of a processing failure.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000200 - The log information from the Apache web server must be protected from unauthorized deletion and modification.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000210 - The log data and records from the Apache web server must be backed up onto a different system or media.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

AUDIT AND ACCOUNTABILITY

AS24-W1-000240 - The Apache web server must not perform user management for hosted applications.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000250 - The Apache web server must only contain services and functions necessary for operationDISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000310 - The Apache web server must allow the mappings to unused and vulnerable scripts to be removed.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W1-000370 - The Apache web server must encrypt passwords during transmission.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

IDENTIFICATION AND AUTHENTICATION

AS24-W1-000450 - The Apache web server must separate the hosted applications from hosted Apache web server management functionality.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W1-000650 - The Apache web server must set an inactive timeout for completing the TLS handshakeDISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL

AS24-W1-000690 - Non-privileged accounts on the hosting system must only access Apache web server security-relevant information and functions through a distinct administrative account.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

ACCESS CONTROL

AS24-W1-000970 - The Apache web server must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.DISA STIG Apache Server 2.4 Windows Server v3r4Windows

CONFIGURATION MANAGEMENT

AS24-W2-000610 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND INFORMATION INTEGRITY

AS24-W2-000670 - The Apache web server must restrict inbound connections from nonsecure zones.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

ACCESS CONTROL

AS24-W2-000780 - The Apache web server must prohibit or restrict the use of nonsecure or unnecessary ports, protocols, modules, and/or services.DISA Apache Server 2.4 Windows Site STIG v2r3Windows

CONFIGURATION MANAGEMENT

AS24-W2-000870 - Cookies exchanged between the Apache web server and the client, such as session cookies, must have cookie properties set to prohibit client-side scripts from reading the cookie dataDISA Apache Server 2.4 Windows Site STIG v2r3Windows

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI5-VMNET-000013 - The system must ensure that the virtual switch Forged Transmits policy is set to reject.DISA VMWare ESXi 5.0 Server STIG v2r1VMware

SYSTEM AND COMMUNICATIONS PROTECTION

F5BI-DM-300034 - The F5 BIG-IP appliance must generate audit records and send records to redundant central syslog servers that are separate from the appliance.DISA F5 BIG-IP TMOS NDM STIG v1r2F5

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

O19C-00-015500 - Oracle Database must use NIST-validated FIPS 140-2/140-3 compliant cryptography for authentication mechanisms.DISA Oracle Database 19c STIG v1r5 UnixUnix

IDENTIFICATION AND AUTHENTICATION

O19C-00-015500 - Oracle Database must use NIST-validated FIPS 140-2/140-3 compliant cryptography for authentication mechanisms.DISA Oracle Database 19c STIG v1r5 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

OH12-1X-000225 - Symbolic links must not be used in the web content directory tree.DISA STIG Oracle HTTP Server 12.1.3 v2r3Unix

CONFIGURATION MANAGEMENT

PPS9-00-012900 - The EDB Postgres Advanced Server must implement NIST FIPS 140-2 or 140-3 validated cryptographic modules to protect unclassified information requiring confidentiality and cryptographic protection, in accordance with the requirements of the data owner.EDB PostgreSQL Advanced Server OS Linux Audit v2r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLEM-05-611080 - SLEM 5 must employ FIPS 140-2/140-3-approved cryptographic hashing algorithms for system authentication.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

UBTU-20-010442 - The Ubuntu operating system must implement NIST FIPS-validated cryptography to protect classified information and for the following: To provision digital signatures, to generate cryptographic hashes, and to protect unclassified information requiring confidentiality and cryptographic protection in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards.DISA Canonical Ubuntu 20.04 LTS STIG v2r4Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA020 A22 - The Timeout directive must be properly set.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA028 A22 - The httpd.conf MinSpareServers directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - confDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - test-cgiDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA056 A22 - The MultiViews directive must be disabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA140 A22 - Web server content and configuration files must be part of a routine backup program.DISA STIG Apache Server 2.2 Unix v1r11Unix
WA00525 A22 - User specific directories must not be globally enabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00525 A22 - User specific directories must not be globally enabled.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00540 A22 - The web server must be configured to explicitly deny access to the OS root - OrderDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA00540 A22 - The web server must be configured to explicitly deny access to the OS root - OrderDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00555 A22 - The web server must be configured to listen on a specific IP address and port - 80DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00560 A22 - The URL-path name must be set to the file path name or the directory path name.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00565 A22 - HTTP request methods must be limited - LimitExceptDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WA00565 A22 - HTTP request methods must be limited - OrderDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG204 A22 - A web server must be segregated from other services.DISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix
WG280 - The access control files are owned by a privileged web server account - HTACCESS_DIRDISA STIG Apache Server 2.2 Unix v1r11Unix
WG300 A22 - Web server system files must conform to minimum file permission requirements - htdocs/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG345 A22 - The web server must remove all export ciphers from the cipher suite.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WG370 A22 - MIME types for csh or sh shell programs must be disabled - ActionDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG520 A22 - Web server and/or operating system information must be protected.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION