Item Search

NameAudit NamePluginCategory
aaa accounting default groupDISA STIG Cisco NX-OS Switch NDM v3r2Cisco
aaa authenticationDISA STIG Cisco NX-OS Switch L2S v3r2Cisco
aaa authentication login default groupDISA STIG Cisco NX-OS Switch NDM v3r2Cisco
aaa groupDISA STIG Cisco IOS XE Switch L2S v3r1Cisco
Check for session-limitDISA STIG Cisco IOS XE Switch NDM v3r2Cisco
Check for snmp-serverDISA STIG Cisco NX-OS Switch NDM v3r2Cisco
CISC-L2-000040 - The Cisco switch must manage excess bandwidth to limit the effects of packet flooding types of denial-of-service (DoS) attacks - DoS attacks.DISA STIG Cisco IOS XE Switch L2S v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000110 - The Cisco switch must have STP Loop Guard enabled.DISA STIG Cisco IOS XE Switch L2S v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000110 - The Cisco switch must have STP Loop Guard enabled.DISA STIG Cisco NX-OS Switch L2S v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000120 - The Cisco switch must have Unknown Unicast Flood Blocking (UUFB) enabled.DISA STIG Cisco NX-OS Switch L2S v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000130 - The Cisco switch must have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources.DISA STIG Cisco NX-OS Switch L2S v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000150 - The Cisco switch must have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs.DISA STIG Cisco IOS XE Switch L2S v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000160 - The Cisco switch must have Storm Control configured on all host-facing switchports.DISA STIG Cisco NX-OS Switch L2S v3r2Cisco

CONFIGURATION MANAGEMENT

CISC-L2-000190 - The Cisco switch must enable Unidirectional Link Detection (UDLD) to protect against one-way connections.DISA STIG Cisco IOS XE Switch L2S v3r1Cisco

CONFIGURATION MANAGEMENT

CISC-L2-000210 - The Cisco switch must have all disabled switch ports assigned to an unused VLAN.DISA STIG Cisco IOS XE Switch L2S v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000210 - The Cisco switch must have all disabled switch ports assigned to an unused VLAN.DISA STIG Cisco NX-OS Switch L2S v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000220 - The Cisco switch must not have the default VLAN assigned to any host-facing switch ports.DISA STIG Cisco NX-OS Switch L2S v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000250 - The Cisco switch must have all user-facing or untrusted ports configured as access switch ports.DISA STIG Cisco NX-OS Switch L2S v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000260 - The Cisco switch must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.DISA STIG Cisco NX-OS Switch L2S v3r2Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000260 - The Cisco switch must have the native VLAN assigned to an ID other than the default VLAN for all 802.1q trunk links.DISA STIG Cisco IOS XE Switch L2S v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-L2-000270 - The Cisco switch must not have any switchports assigned to the native VLAN.DISA STIG Cisco IOS XE Switch L2S v3r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-ND-000120 - The Cisco switch must be configured to automatically audit account removal actions.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

ACCESS CONTROL

CISC-ND-000160 - The Cisco switch must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.DISA STIG Cisco IOS XE Switch NDM v3r2Cisco

ACCESS CONTROL

CISC-ND-000210 - The Cisco switch must be configured to protect against an individual falsely denying having performed organization-defined actions to be covered by non-repudiation.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-000280 - The Cisco switch must produce audit records containing information to establish when (date and time) the events occurred.DISA STIG Cisco IOS XE Switch NDM v3r2Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-000290 - The Cisco switch must produce audit records containing information to establish where the events occurred.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-000490 - The Cisco switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

ACCESS CONTROL

CISC-ND-000940 - The Cisco switch must be configured to audit the execution of privileged functions.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

ACCESS CONTROL

CISC-ND-000980 - The Cisco switch must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001210 - The Cisco switch must be configured to implement cryptographic mechanisms to protect the confidentiality of remote maintenance sessions.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

MAINTENANCE

CISC-ND-001250 - The Cisco switch must be configured to generate log records when administrator privileges are deleted.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

AUDIT AND ACCOUNTABILITY

CISC-ND-001370 - The Cisco switch must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.DISA STIG Cisco NX-OS Switch NDM v3r2Cisco

CONFIGURATION MANAGEMENT

dot1x port-control autoDISA STIG Cisco NX-OS Switch L2S v3r2Cisco
dot1x system-auth-controlDISA STIG Cisco IOS XE Switch L2S v3r1Cisco
enrollmentDISA STIG Cisco IOS XE Switch NDM v3r2Cisco
FNFG-FW-000110 - The FortiGate firewall must employ filters that prevent or limit the effects of all types of commonly known denial-of-service (DoS) attacks, including flooding, packet sweeps, and unauthorized port scanning.DISA Fortigate Firewall STIG v1r3FortiGate

SYSTEM AND COMMUNICATIONS PROTECTION

interface dot1xDISA STIG Cisco NX-OS Switch L2S v3r2Cisco
ip dhcp snoopingDISA STIG Cisco NX-OS Switch L2S v3r2Cisco
ip dhcp snoopingDISA STIG Cisco IOS XE Switch L2S v3r1Cisco
ip http authentication aaa login-authenticationDISA STIG Cisco IOS XE Switch NDM v3r2Cisco
ip http max connectionsDISA STIG Cisco IOS XE Switch NDM v3r2Cisco
ip igmp snooping vlanDISA STIG Cisco NX-OS Switch L2S v3r2Cisco
ip ssh version 2DISA STIG Cisco IOS XE Switch NDM v3r2Cisco
line conDISA STIG Cisco NX-OS Switch NDM v3r2Cisco
login on-successDISA STIG Cisco IOS XE Switch NDM v3r2Cisco
ntp authenticateDISA STIG Cisco NX-OS Switch NDM v3r2Cisco
ntp serverDISA STIG Cisco NX-OS Switch NDM v3r2Cisco
ntp trusted-keyDISA STIG Cisco NX-OS Switch NDM v3r2Cisco
radius serverDISA STIG Cisco IOS XE Switch L2S v3r1Cisco
show snmp userDISA STIG Cisco IOS XE Switch NDM v3r2Cisco