Item Search

NameAudit NamePluginCategory
Check for Standalone modeDISA JBoss EAP 6.3 STIG v2r5Unix
DISA_STIG_JBoss_EAP_6.3_v2r5.audit from DISA JBoss Enterprise Application Platform 6.3 v2r5 STIGDISA JBoss EAP 6.3 STIG v2r5Unix
java.security.managerDISA JBoss EAP 6.3 STIG v2r5Unix
JBOS-AS-000010 - HTTP management session traffic must be encrypted.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000015 - HTTPS must be enabled for JBoss web interfaces.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000025 - Java permissions must be set for hosted applications.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000030 - The Java Security Manager must be enabled for the JBoss application server.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000035 - The JBoss server must be configured with Role Based Access Controls.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000040 - Users in JBoss Management Security Realms must be in the appropriate role.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000050 - Silent Authentication must be removed from the Default Management Security Realm.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000075 - JBoss management interfaces must be secured.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000080 - The JBoss server must generate log records for access and authentication events to the management interface.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000085 - JBoss must be configured to allow only the ISSM (or individuals or roles appointed by the ISSM) to select which loggable events are to be logged.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000095 - JBoss must be configured to initiate session logging upon startup.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000115 - JBoss Log Formatter must be configured to produce log records that establish the date and time the events occurred.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000130 - The application server must produce log records that contain sufficient information to establish the outcome of events.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000135 - JBoss ROOT logger must be configured to utilize the appropriate logging level.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000165 - File permissions must be configured to protect log information from any type of unauthorized read access.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000170 - File permissions must be configured to protect log information from unauthorized modification.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000175 - File permissions must be configured to protect log information from unauthorized deletion.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000195 - JBoss log records must be off-loaded onto a different system or system component a minimum of every seven days.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000220 - JBoss process owner interactive access must be restricted.DISA JBoss EAP 6.3 STIG v2r5Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000230 - JBoss process owner execution permissions must be limited.DISA JBoss EAP 6.3 STIG v2r5Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000250 - Any unapproved applications must be removed - Any unapproved applications must be removed.DISA JBoss EAP 6.3 STIG v2r5Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000275 - The JBoss server must be configured to use individual accounts and not generic or shared accounts.DISA JBoss EAP 6.3 STIG v2r5Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000285 - The JBoss server must be configured to bind the management interfaces to only management networks.DISA JBoss EAP 6.3 STIG v2r5Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000290 - JBoss management Interfaces must be integrated with a centralized authentication mechanism that is configured to manage accounts according to DoD policy.DISA JBoss EAP 6.3 STIG v2r5Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000295 - The JBoss Password Vault must be used for storing passwords or other sensitive configuration information.DISA JBoss EAP 6.3 STIG v2r5Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000300 - JBoss KeyStore and Truststore passwords must not be stored in clear text.DISA JBoss EAP 6.3 STIG v2r5Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000305 - LDAP enabled security realm value allow-empty-passwords must be set to false.DISA JBoss EAP 6.3 STIG v2r5Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000310 - JBoss must utilize encryption when using LDAP for authentication.DISA JBoss EAP 6.3 STIG v2r5Unix

IDENTIFICATION AND AUTHENTICATION

JBOS-AS-000355 - The JBoss server must separate hosted application functionality from application server management functionality.DISA JBoss EAP 6.3 STIG v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

JBOS-AS-000400 - JBoss file permissions must be configured to protect the confidentiality and integrity of application files.DISA JBoss EAP 6.3 STIG v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

JBOS-AS-000480 - The JBoss server must be configured to log all admin activity.DISA JBoss EAP 6.3 STIG v2r5Unix

ACCESS CONTROL

JBOS-AS-000505 - The JBoss server must be configured to utilize syslog logging.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000550 - Production JBoss servers must log when failed application deployments occur.DISA JBoss EAP 6.3 STIG v2r5Unix

CONFIGURATION MANAGEMENT

JBOS-AS-000640 - The JBoss server, when hosting mission critical applications, must be in a high-availability (HA) cluster.DISA JBoss EAP 6.3 STIG v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

JBOS-AS-000650 - JBoss must be configured to use an approved TLS version.DISA JBoss EAP 6.3 STIG v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

JBOS-AS-000655 - JBoss must be configured to use an approved cryptographic algorithm in conjunction with TLS.DISA JBoss EAP 6.3 STIG v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

JBOS-AS-000685 - The JRE installed on the JBoss server must be kept up to date.DISA JBoss EAP 6.3 STIG v2r5Unix

SYSTEM AND INFORMATION INTEGRITY

JBOS-AS-000690 - JBoss must be configured to generate log records when successful/unsuccessful attempts to modify privileges occur.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000700 - JBoss must be configured to generate log records when successful/unsuccessful logon attempts occur.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000705 - JBoss must be configured to generate log records for privileged activities.DISA JBoss EAP 6.3 STIG v2r5Unix

AUDIT AND ACCOUNTABILITY

JBOS-AS-000730 - The JBoss server must be configured to use DoD- or CNSS-approved PKI Class 3 or Class 4 certificates.DISA JBoss EAP 6.3 STIG v2r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

keystore fileDISA JBoss EAP 6.3 STIG v2r5Unix
RedHat/CentOS 5 is installedDISA STIG for Red Hat Enterprise Linux 5 v1r18 AuditUnix
vaultDISA JBoss EAP 6.3 STIG v2r5Unix
vault-optionDISA JBoss EAP 6.3 STIG v2r5Unix
WN19-00-000410 - Windows Server 2019 must not have Windows PowerShell 2.0 installed.DISA Windows Server 2019 STIG v3r2Windows

CONFIGURATION MANAGEMENT

WN22-00-000410 - Windows Server 2022 must not have Windows PowerShell 2.0 installed.DISA Windows Server 2022 STIG v2r2Windows

CONFIGURATION MANAGEMENT