CCI|CCI-001199

Title

The information system protects the confidentiality and/or integrity of organization-defined information at rest.

Reference Item Details

Category: 2009

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.5.9 Ensure NIST FIPS-validated cryptography is configured - etcUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.5.9 Ensure NIST FIPS-validated cryptography is configured - grubUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.5.9 Ensure NIST FIPS-validated cryptography is configured - procUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.5.9 Ensure NIST FIPS-validated cryptography is configured - rpmUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIOS-12-010500 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.MDMAirWatch - DISA Apple iOS 12 v2r1
AIOS-12-010500 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.MDMMobileIron - DISA Apple iOS 12 v2r1
AIOS-12-010600 - Apple iOS must implement the management setting: limit Ad Tracking.MDMAirWatch - DISA Apple iOS 12 v2r1
AIOS-12-010600 - Apple iOS must implement the management setting: limit Ad Tracking.MDMMobileIron - DISA Apple iOS 12 v2r1
AIOS-13-008900 - Apple iOS/iPadOS must implement the management setting: remove managed applications upon unenrollment from MDM (including sensitive and protected data).MDMMobileIron - DISA Apple iOS/iPadOS 13 v2r1
AIOS-13-008900 - Apple iOS/iPadOS must implement the management setting: remove managed applications upon unenrollment from MDM (including sensitive and protected data).MDMAirWatch - DISA Apple iOS/iPadOS 13 v2r1
AIOS-13-010500 - Apple iOS/iPadOS must require a valid password be successfully entered before the mobile device data is unencrypted.MDMAirWatch - DISA Apple iOS/iPadOS 13 v2r1
AIOS-13-010500 - Apple iOS/iPadOS must require a valid password be successfully entered before the mobile device data is unencrypted.MDMMobileIron - DISA Apple iOS/iPadOS 13 v2r1
AIOS-13-010600 - Apple iOS/iPadOS must implement the management setting: limit Ad Tracking.MDMMobileIron - DISA Apple iOS/iPadOS 13 v2r1
AIOS-13-010600 - Apple iOS/iPadOS must implement the management setting: limit Ad Tracking.MDMAirWatch - DISA Apple iOS/iPadOS 13 v2r1
AIOS-14-007600 - Apple iOS/iPadOS must implement the management setting: remove managed applications upon unenrollment from MDM (including sensitive and protected data).MDMMobileIron - DISA Apple iOS/iPadOS 14 v1r3
AIOS-14-007600 - Apple iOS/iPadOS must implement the management setting: remove managed applications upon unenrollment from MDM (including sensitive and protected data).MDMAirWatch - DISA Apple iOS/iPadOS 14 v1r3
AIOS-14-008800 - Apple iOS/iPadOS must require a valid password be successfully entered before the mobile device data is unencrypted.MDMAirWatch - DISA Apple iOS/iPadOS 14 v1r3
AIOS-14-008800 - Apple iOS/iPadOS must require a valid password be successfully entered before the mobile device data is unencrypted.MDMMobileIron - DISA Apple iOS/iPadOS 14 v1r3
AIOS-14-008900 - Apple iOS/iPadOS must implement the management setting: limit Ad Tracking.MDMMobileIron - DISA Apple iOS/iPadOS 14 v1r3
AIOS-14-008900 - Apple iOS/iPadOS must implement the management setting: limit Ad Tracking.MDMAirWatch - DISA Apple iOS/iPadOS 14 v1r3
AIOS-14-011800 - Apple iOS must be configured to disable automatic transfer of diagnostic data to an external device other than an MDM service with which the device has enrolled.MDMAirWatch - DISA Apple iOS/iPadOS 14 v1r3
AIOS-14-011800 - Apple iOS must be configured to disable automatic transfer of diagnostic data to an external device other than an MDM service with which the device has enrolled.MDMMobileIron - DISA Apple iOS/iPadOS 14 v1r3
AIX7-00-001048 - AIX must protect the confidentiality and integrity of all information at rest.UnixDISA STIG AIX 7.x v2r9
AOSX-13-000780 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-11-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple macOS 11 v1r8
APPL-12-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple macOS 12 v1r8
APPL-13-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple macOS 13 v1r3
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
BIND-9X-001130 - The DNSSEC keys used with the BIND 9.x implementation must be owned by a privileged account.UnixDISA BIND 9.x STIG v2r2
BIND-9X-001131 - The DNSSEC keys used with the BIND 9.x implementation must be group owned by a privileged account.UnixDISA BIND 9.x STIG v2r2
BIND-9X-001132 - Permissions assigned to the DNSSEC keys used with the BIND 9.x implementation must enforce read-only access to the key owner and deny access to all other users.UnixDISA BIND 9.x STIG v2r2
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
DB2X-00-005400 - DB2 must protect the confidentiality and integrity of all information at rest.IBM_DB2DBDISA STIG IBM DB2 v10.5 LUW v2r1 Database
DKER-EE-001070 - FIPS mode must be enabled on all Docker Engine - Enterprise nodes - docker info .SecurityOptionsUnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r1
DKER-EE-002660 - Docker Secrets must be used to store configuration files and small amounts of user-generated data (up to 500 kb in size) in Docker Enterprise.UnixDISA STIG Docker Enterprise 2.x Linux/Unix v2r1