CCI|CCI-000803

Title

Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.19 APPL-14-000054UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT I
1.20 APPL-14-000057UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT I
1.23 OL08-00-010159UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.24 OL08-00-010160UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.25 OL08-00-010161UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.26 OL08-00-010162UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.27 OL08-00-010163UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.96 UBTU-24-400400UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.101 UBTU-22-611070UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.179 RHEL-09-252065UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.319 RHEL-09-611050UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.320 RHEL-09-611055UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.358 RHEL-09-652015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.447 RHEL-09-671015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.451 RHEL-09-672025UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
5.3.16 Ensure only FIPS 140-2 ciphers are used for SSHUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIOS-17-007200 - Apple iOS/iPadOS 17 must not include applications with the following characteristics: access to Siri when the device is locked.MDMAirWatch - DISA Apple iOS/iPadOS 17 v2r2
AIOS-17-007200 - Apple iOS/iPadOS 17 must not include applications with the following characteristics: access to Siri when the device is locked.MDMMobileIron - DISA Apple iOS/iPadOS 17 v2r2
AIOS-18-007200 - Apple iOS/iPadOS 18 must not include applications with the following characteristics: access to Siri when the device is locked.MDMAirWatch - DISA Apple iOS/iPadOS 18 v1r4
AIOS-18-007200 - Apple iOS/iPadOS 18 must not include applications with the following characteristics: access to Siri when the device is locked.MDMMobileIron - DISA Apple iOS/iPadOS 18 v1r4
ALMA-09-039290 - AlmaLinux 9 cryptographic policy must not be overridden.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-039510 - The libreswan package must be installed.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
ALMA-09-039620 - AlmaLinux OS 9 must have the packages required for encrypting offloaded audit logs installed.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r3
AMLS-L3-000250 - The Arista Multilayer Switch must encrypt all methods of configured authentication for the OSPF routing protocol - ipv6 OSPF checksAristaDISA STIG Arista MLS DCS-7000 Series RTR v1r4
AMLS-L3-000250 - The Arista Multilayer Switch must encrypt all methods of configured authentication for the OSPF routing protocol - ospf message-digestAristaDISA STIG Arista MLS DCS-7000 Series RTR v1r4
AMLS-L3-000250 - The Arista Multilayer Switch must encrypt all methods of configured authentication for the OSPF routing protocol - ospf message-digest-keyAristaDISA STIG Arista MLS DCS-7000 Series RTR v1r4
AMLS-L3-000320 - The Arista Multilayer Switch must not enable the RIP routing protocol.AristaDISA STIG Arista MLS DCS-7000 Series RTR v1r4
AMLS-NM-200825 - The Arista Multilayer Switch must use FIPS-compliant mechanisms for authentication to a cryptographic module - entropy sourceAristaDISA STIG Arista MLS DCS-7000 Series NDM v1r4
AMLS-NM-200825 - The Arista Multilayer Switch must use FIPS-compliant mechanisms for authentication to a cryptographic module - SSH FIPSAristaDISA STIG Arista MLS DCS-7000 Series NDM v1r4
AOSX-13-000054 - The macOS system must implement approved Ciphers to protect the confidentiality of SSH connections.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-000056 - The macOS system must implement an approved Key Exchange Algorithm.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-000054 - The macOS system must implement approved Ciphers to protect the confidentiality of SSH connections.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000056 - The macOS system must implement an approved Key Exchange Algorithm.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-000054 - The macOS system must implement approved Ciphers to protect the confidentiality of SSH connections..UnixDISA STIG Apple Mac OSX 10.15 v1r10
AOSX-15-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.UnixDISA STIG Apple Mac OSX 10.15 v1r10
AOSX-15-000056 - The macOS system must implement an approved Key Exchange Algorithm.UnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-11-000054 - The macOS system must implement approved ciphers to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 11 v1r8
APPL-11-000054 - The macOS system must implement approved ciphers to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.UnixDISA STIG Apple macOS 11 v1r8
APPL-11-000056 - The macOS system must implement an approved Key Exchange Algorithm.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-000056 - The macOS system must implement an approved Key Exchange Algorithm.UnixDISA STIG Apple macOS 11 v1r8
APPL-12-000054 - The macOS system must implement approved ciphers within the SSH server configuration to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000055 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH server configuration.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000056 - The macOS system must implement approved Key Exchange Algorithms within the SSH server configuration.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000057 - The macOS system must implement approved ciphers within the SSH client configuration to protect the confidentiality of SSH connections.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000058 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH client configuration.UnixDISA STIG Apple macOS 12 v1r9
APPL-12-000059 - The macOS system must implement approved Key Exchange Algorithms within the SSH client configuration.UnixDISA STIG Apple macOS 12 v1r9