Item Search

NameAudit NamePluginCategory
1.006 - Users with Administrative privilege are not documented or do not have separate accounts for administrative duties.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

2.005 - Systems must be at supported service packs (SP) or releases levels.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

2.008 - Local volumes are not formatted using NTFS.DISA Windows Vista STIG v6r41Windows

ACCESS CONTROL

3.018 - Anonymous shares are not restricted. - RestrictAnonymousDISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.018 - Anonymous shares are not restricted. - RestrictAnonymousSAMDISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.031 - The Send download LanMan compatible password option is not set to Send NTLMv2 response only\refuse LM.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.049 - The Recovery Console option is set to permit automatic logon to the system.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.062 - Anonymous SID/Name translation is allowed.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

3.063 - Unauthorized named pipes are accessible with anonymous credentials.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.064 - Unauthorized registry paths are remotely accessible.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.065 - Unauthorized shares can be accessed anonymously.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.068 - Solicited Remote Assistance is allowed.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.108 - Unauthorized registry paths and sub-paths are remotely accessible.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

3.116 - Named Pipes and Shares can be accessed anonymously.DISA Windows Vista STIG v6r41Windows

SYSTEM AND COMMUNICATIONS PROTECTION

4.017 - DOD information system access does not require the use of a password.DISA Windows Vista STIG v6r41Windows

IDENTIFICATION AND AUTHENTICATION

4.036 - The use of local accounts with blank passwords is not restricted to console logons only.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

5.005 - Installed FTP server is configured to allow access to the system drive.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

5.007 - An approved, up-to-date, DoD antivirus program must be installed and used.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

5.016 - Internet Information System (IIS) or its subcomponents are installed on a workstation.DISA Windows Vista STIG v6r41Windows

CONFIGURATION MANAGEMENT

DG0067-ORACLE11 - Database account passwords should be stored in encoded or encrypted format whether stored in database objects, external host files, environment variables or any other storage locations.DISA STIG Oracle 11 Installation v9r1 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

DG0067-ORACLE11 - Database account passwords should be stored in encoded or encrypted format whether stored in database objects, external host files, environment variables or any other storage locations.DISA STIG Oracle 11 Installation v9r1 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

DG0129-ORACLE11 - Passwords should be encrypted when transmitted across the network.DISA STIG Oracle 11 Installation v9r1 WindowsWindows

IDENTIFICATION AND AUTHENTICATION

DG0129-ORACLE11 - Passwords should be encrypted when transmitted across the network.DISA STIG Oracle 11 Installation v9r1 LinuxUnix

IDENTIFICATION AND AUTHENTICATION

DO3538-ORACLE11 - The Oracle REMOTE_OS_AUTHENT parameter should be set to FALSE - 'remote_os_authent = false'DISA STIG Oracle 11 Instance v9r1 DatabaseOracleDB

IDENTIFICATION AND AUTHENTICATION

DO3630-ORACLE11 - The Oracle Listener should be configured to require administration authentication - 'No listeners are running'DISA STIG Oracle 11 Installation v9r1 WindowsWindows

ACCESS CONTROL

GEN001640 - Run control scripts must not execute world-writable programs or scripts.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN002040 - There must be no .rhosts, .shosts, hosts.equiv, or shosts.equiv files on the system - '.shosts'DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN002220 - All shell files must have mode 0755 or less permissive.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN004220 - Administrative accounts must not run a web browser, except as needed for local service administration.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN004640 - The SMTP service must not have a uudecode alias active - '/etc/aliases uudecode alias does not exist'DISA STIG AIX 5.3 v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN004640 - The SMTP service must not have a uudecode alias active - '/usr/lib/aliases decode alias does not exist'DISA STIG AIX 5.3 v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN004640 - The SMTP service must not have a uudecode alias active - '/usr/lib/aliases uudecode alias does not exist'DISA STIG AIX 5.3 v1r2Unix

SYSTEM AND INFORMATION INTEGRITY

GEN005080 - The TFTP daemon must operate in 'secure mode' which provides access only to a single directory on the host - Not ApplicableDISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN005080 - The TFTP daemon must operate in 'secure mode' which provides access only to a single directory on the host file system.DISA STIG AIX 5.3 v1r2Unix

CONFIGURATION MANAGEMENT

GEN005100 - The TFTP daemon must have mode 0755 or less permissive.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

GEN005200 - X displays must not be exported to the world.DISA STIG AIX 5.3 v1r2Unix

ACCESS CONTROL

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.bat mappings'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.cmd mappings'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.HTR scripting Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Index Server Web Interface Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Script Source permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Write permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI6040 IIS6 - A unique non-privileged account must be used to run Worker Process Identities. - 'AppPoolIdentityType = 3 - WAMUserName'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI6040 IIS6 - A unique non-privileged account must be used to run Worker Process Identities. - 'AppPoolIdentityType Check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - -+IncludesNOEXEC|-IncludesDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - +IncludesDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - +IncludesDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - Options NoneDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

ACCESS CONTROL

WG195 IIS6 - Anonymous access accounts must be restricted.DISA STIG IIS 6.0 Server v6r16Windows

ACCESS CONTROL

WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL