CCI|CCI-001453

Title

Implement cryptographic mechanisms to protect the integrity of remote access sessions.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.4 OL08-00-010020UnixCIS Oracle Linux 8 STIG v1.0.0 CAT I
1.19 APPL-14-000054UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT I
1.20 APPL-14-000057UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT I
1.25 UBTU-24-100830UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.27 UBTU-24-100850UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.28 UBTU-24-100860UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.39 OL08-00-010287UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.43 OL08-00-010293UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.44 OL08-00-010294UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.45 OL08-00-010295UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.64 UBTU-22-255055UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.212 RHEL-09-255055UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.213 RHEL-09-255060UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.214 RHEL-09-255064UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.215 RHEL-09-255065UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.216 RHEL-09-255070UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.217 RHEL-09-255075UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.367 OL08-00-040342UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
2.2.26 Ensure ldap_tls_cacert is set for LDAP - configUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
2.2.26 Ensure ldap_tls_cacert is set for LDAP - fileUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
2.2.26 Ensure ldap_tls_cacert is set for LDAP.UnixCIS Amazon Linux 2 STIG v2.0.0 STIG
2.2.27 Ensure ldap_id_use_start_tls is set for LDAP - LDAP authentication communications.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
2.2.27 Ensure ldap_id_use_start_tls is set for LDAP.UnixCIS Amazon Linux 2 STIG v2.0.0 STIG
2.2.28 Ensure ldap_tls_reqcert is set for LDAPUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
2.2.28 Ensure ldap_tls_reqcert is set for LDAP - LDAP communications.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
5.1.6 Ensure sshd Ciphers are configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
5.1.6 Ensure sshd Ciphers are configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
5.1.12 Ensure sshd KexAlgorithms is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
5.1.12 Ensure sshd KexAlgorithms is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
5.1.15 Ensure sshd MACs are configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
5.1.15 Ensure sshd MACs are configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
5.3.17 Ensure only strong MAC algorithms are usedUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
5.3.17 Ensure only strong MAC algorithms are usedUnixCIS Amazon Linux 2 STIG v2.0.0 L1 Workstation
5.3.17 Ensure only strong MAC algorithms are usedUnixCIS Amazon Linux 2 STIG v2.0.0 L1 Server
5.3.17 Ensure only strong MAC algorithms are used - MACs employing FIPS 140-2 approved cryptographic hash algorithms.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIX7-00-001104 - If LDAP authentication is required on AIX, SSL must be used between LDAP clients and the LDAP servers to protect the integrity of remote access sessions.UnixDISA STIG AIX 7.x v3r1
ALMA-09-002990 - AlmaLinux OS 9 SSH client must be configured to use only encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
ALMA-09-003100 - AlmaLinux OS 9 must implement DOD-approved encryption ciphers to protect the confidentiality of SSH connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
ALMA-09-003210 - AlmaLinux OS 9 SSH client must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
ALMA-09-003320 - The AlmaLinux 9 SSH server must be configured to use only DOD-approved encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
ALMA-09-003430 - AlmaLinux OS 9 must implement DOD-approved systemwide cryptographic policies to protect the confidentiality of SSH server connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
ALMA-09-003540 - The AlmaLinux OS 9 SSH server must be configured to use only Message Authentication Codes (MACs) employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH server connections.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
ALMA-09-003760 - AlmaLinux OS 9 must implement DOD-approved TLS encryption in the GnuTLS package.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
ALMA-09-003980 - AlmaLinux OS 9 must implement DOD-approved encryption in the OpenSSL package.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
ALMA-09-004090 - AlmaLinux OS 9 must implement DOD-approved TLS encryption in the OpenSSL package.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r4
AOSX-13-000605 - The macOS system must not use telnet.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - OpenSSH versionUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - SSHD currently runningUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - SSHD service disabledUnixDISA STIG Apple Mac OSX 10.14 v2r6
APPL-11-000011 - The macOS system must disable the SSHD service.UnixDISA STIG Apple macOS 11 v1r8