Item Search

NameAudit NamePluginCategory
1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 7 L1 v1.8.0Windows

CONFIGURATION MANAGEMENT

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 8.0 v1.5.1 Level 1Windows

CONFIGURATION MANAGEMENT

1.6 Ensure 'application pool identity' is configured for anonymous user identityCIS IIS 10 v1.2.1 Level 1Windows

ACCESS CONTROL

1.6.2 Create Pod Security Policies for your clusterCIS Kubernetes 1.7.0 Benchmark v1.1.0 L1Unix

CONFIGURATION MANAGEMENT

1.6.2 Create Pod Security Policies for your clusterCIS Kubernetes 1.8 Benchmark v1.2.0 L1Unix

CONFIGURATION MANAGEMENT

1.36 IIST-SI-000252CIS Microsoft IIS 10.0 Site STIG v1.0.0 CAT IIWindows

CONFIGURATION MANAGEMENT

2.3.3 Verify Display Sleep is set to a value larger than the Screen SaverCIS Apple OSX 10.10 Yosemite L1 v1.2.0Unix

ACCESS CONTROL

3.3 Ensure custom error messages are not offCIS IIS 8.0 v1.5.1 Level 2Windows

SYSTEM AND INFORMATION INTEGRITY

3.11 Ensure 'encryption providers' are locked downCIS IIS 7 L2 v1.8.0Windows

ACCESS CONTROL

4.5 Ensure Double-Encoded requests will be rejected - ApplicationsCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND INFORMATION INTEGRITY

4.5 Ensure Double-Encoded requests will be rejected - DefaultCIS IIS 10 v1.2.1 Level 1Windows

SYSTEM AND INFORMATION INTEGRITY

CIS VMware ESXi 5.5 v1.2.0 Level 1CIS VMware ESXi 5.5 v1.2.0 Level 1VMware
ESXI-06-000001 - The VMM must limit the number of concurrent sessions to ten for all accounts and/or account types by enabling lockdown mode.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000004 - Remote logging for ESXi hosts must be configured.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-000007 - The system must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000008 - The SSH daemon must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000030 - The system must produce audit records containing information to establish what type of events occurred.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-000034 - The system must disable the Managed Object Browser (MOB).DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000041 - The system must set a timeout to automatically disable idle sessions after a predetermined period.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000042 - The system must terminate shell services after a predetermined period.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-000046 - The system must configure NTP time synchronization.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-000048 - The system must protect the confidentiality and integrity of transmitted information by isolating vMotion traffic.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000049 - The system must protect the confidentiality and integrity of transmitted information by protecting ESXi management traffic.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000050 - The system must protect the confidentiality and integrity of transmitted information by protecting IP based management traffic.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000052 - The system must protect the confidentiality and integrity of transmitted information by utilizing different TCP/IP stacks where possible.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000053 - SNMP must be configured properly.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000057 - The system must configure the firewall to block network traffic by default - IncomingDISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000059 - The virtual switch Forged Transmits policy must be set to reject.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

SYSTEM AND COMMUNICATIONS PROTECTION

ESXI-06-000066 - The non-negotiate option must be configured for trunk links between external physical switches and virtual switches in VST mode.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000071 - The system must verify the integrity of the installation media before installing ESXi.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-000076 - The system must configure the VSAN Datastore name to a unique name.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-06-100004 - The VMM must support the capability to centrally review and analyze audit records from multiple components within the system by configuring remote logging.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-100031 - The VMM must enforce password complexity by requiring that at least one lower-case character be used.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-100040 - The VMM must accept Personal Identity Verification (PIV) credentials.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-100043 - The VMM must automatically terminate a user session after inactivity timeouts have expired or at shutdown.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

ACCESS CONTROL

ESXI-06-100046 - The VMM must synchronize internal information system clocks to the authoritative time source when the time difference is greater than one second.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-200004 - The VMM must protect audit information from unauthorized modification by configuring remote logging.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-200031 - The VMM must enforce password complexity by requiring that at least one numeric character be used.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-200038 - The VMM must implement replay-resistant authentication mechanisms for network access to privileged accounts by using the vSphere Authentication Proxy.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-200040 - The VMM must electronically verify Personal Identity Verification (PIV) credentials.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-300004 - The VMM must protect audit information from unauthorized deletion by configuring remote logging.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-300031 - The VMM must require the change of at least 8 of the total number of characters when passwords are changed.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-300038 - The VMM must implement replay-resistant authentication mechanisms for network access to non-privileged accounts by using the vSphere Authentication Proxy.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

ESXI-06-400004 - The VMM must off-load audit records onto a different system or media than the system being audited by configuring remote logging.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

AUDIT AND ACCOUNTABILITY

ESXI-06-400031 - The VMM must enforce a minimum 15-character password length.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

IDENTIFICATION AND AUTHENTICATION

IIST-SI-000209 - The IIS 10.0 website must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 10.0 website events.DISA IIS 10.0 Site v2r14Windows

AUDIT AND ACCOUNTABILITY

IIST-SI-000242 - The IIS 10.0 private website must employ cryptographic mechanisms (TLS) and require client certificates.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND COMMUNICATIONS PROTECTION

IISW-SI-000209 - The IIS 8.5 website must produce log records that contain sufficient information to establish the outcome (success or failure) of IIS 8.5 website events - success or failure of IIS 8.5 website eventsDISA IIS 8.5 Site v2r9Windows

AUDIT AND ACCOUNTABILITY

IISW-SI-000220 - A private websites authentication mechanism must use client certificates to transmit session identifier to assure integrity.DISA IIS 8.5 Site v2r9Windows

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

SP13-00-000060 - SharePoint must reject or delay, as defined by the organization, network traffic generated above configurable traffic volume thresholds - maxConnectionsDISA Microsoft SharePoint 2013 STIG v2r4Windows

CONFIGURATION MANAGEMENT