CCI|CCI-002476

Title

Implement cryptographic mechanisms to prevent unauthorized disclosure of organization-defined information at rest on organization-defined system components.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.5.9 Ensure NIST FIPS-validated cryptography is configured - etcUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.5.9 Ensure NIST FIPS-validated cryptography is configured - grubUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.5.9 Ensure NIST FIPS-validated cryptography is configured - procUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.5.9 Ensure NIST FIPS-validated cryptography is configured - rpmUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIOS-01-080006 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.MDMMobileIron - DISA Apple iOS 10 v1r3
AIOS-01-080006 - Apple iOS must require a valid password be successfully entered before the mobile device data is unencrypted.MDMAirWatch - DISA Apple iOS 10 v1r3
AIX7-00-002096 - AIX must encrypt user data at rest using AIX Encrypted File System (EFS) if it is required.UnixDISA STIG AIX 7.x v3r1
AOSX-13-000780 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-11-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple macOS 11 v1r8
APPL-12-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple macOS 12 v1r9
APPL-13-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.UnixDISA STIG Apple macOS 13 v1r4
APPL-14-005020 - The macOS system must enforce FileVault.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-15-005020 - The macOS system must enforce FileVault.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
AS24-W2-000890 - An Apache web server must maintain the confidentiality of controlled information during transmission through the use of an approved TLS version - SSLEngineWindowsDISA STIG Apache Server 2.4 Windows Site v2r1
AS24-W2-000890 - An Apache web server must maintain the confidentiality of controlled information during transmission through the use of an approved TLS version - SSLProtocolWindowsDISA STIG Apache Server 2.4 Windows Site v2r1
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Enforce FileVaultUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Enforce FileVaultUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
CD12-00-010500 - PostgreSQL must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.PostgreSQLDBDISA STIG Crunchy Data PostgreSQL DB v3r1
CNTR-R2-001500 Rancher RKE2 keystore must implement encryption to prevent unauthorized disclosure of information at rest within Rancher RKE2.UnixDISA Rancher Government Solutions RKE2 STIG v2r2
DB2X-00-008900 - DB2 must implement and/or support cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.IBM_DB2DBDISA STIG IBM DB2 v10.5 LUW v2r1 Database
DTOO187 - Office System - Rights managed Office Open XML files must be protected.WindowsDISA STIG Office System 2010 v1r13
DTOO187 - Rights managed Office Open XML files must be protected.WindowsDISA STIG Microsoft Office System 2016 v2r3
DTOO187 - Rights managed Office Open XML files must be protected.WindowsDISA STIG Microsoft Office System 2013 v2r2
DTOO321 - Encrypt document properties must be configured for OLE documents.WindowsDISA STIG Microsoft Office System 2013 v2r2
DTOO321 - Encrypt document properties must be configured for OLE documents.WindowsDISA STIG Microsoft Office System 2016 v2r3
DTOO321 - Office System - Encrypt document properties must be configured for OLE documents.WindowsDISA STIG Office System 2010 v1r13
EP11-00-009300 - The EDB Postgres Advanced Server must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.WindowsEDB PostgreSQL Advanced Server v11 Windows OS Audit v2r4
EPAS-00-009300 - The EDB Postgres Advanced Server must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.UnixEnterpriseDB PostgreSQL Advanced Server OS Linux v2r1
IIST-SI-000242 - The IIS 10.0 private website must employ cryptographic mechanisms (TLS) and require client certificates.WindowsDISA IIS 10.0 Site v2r9
IISW-SI-000242 - The IIS 8.5 private website must employ cryptographic mechanisms (TLS) and require client certificates.WindowsDISA IIS 8.5 Site v2r9
MADB-10-008700 - MariaDB must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.MySQLDBDISA MariaDB Enterprise 10.x v2r1 DB
Monterey - Enforce FileVaultUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Enforce FileVaultUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Enforce FileVaultUnixNIST macOS Monterey v1.0.0 - 800-171
MYS8-00-012100 - The MySQL Database Server 8.0 must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.MySQLDBDISA Oracle MySQL 8.0 v2r2 DB