Item Search

NameAudit NamePluginCategory
ALMA-09-025980 - AlmaLinux OS 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.DISA CloudLinux AlmaLinux OS 9 STIG v1r1Unix

CONFIGURATION MANAGEMENT

ALMA-09-026090 - AlmaLinux OS 9 must prevent device files from being interpreted on file systems that contain user home directories.DISA CloudLinux AlmaLinux OS 9 STIG v1r1Unix

CONFIGURATION MANAGEMENT

ALMA-09-026310 - AlmaLinux OS 9 must mount /boot with the nodev option.DISA CloudLinux AlmaLinux OS 9 STIG v1r1Unix

CONFIGURATION MANAGEMENT

ALMA-09-026640 - AlmaLinux OS 9 must mount /dev/shm with the noexec option.DISA CloudLinux AlmaLinux OS 9 STIG v1r1Unix

CONFIGURATION MANAGEMENT

ALMA-09-026860 - AlmaLinux OS 9 must mount /tmp with the nodev option.DISA CloudLinux AlmaLinux OS 9 STIG v1r1Unix

CONFIGURATION MANAGEMENT

ALMA-09-027300 - AlmaLinux OS 9 must mount /var/log/audit with the noexec option.DISA CloudLinux AlmaLinux OS 9 STIG v1r1Unix

CONFIGURATION MANAGEMENT

ALMA-09-027410 - AlmaLinux OS 9 must mount /var/log/audit with the nosuid option.DISA CloudLinux AlmaLinux OS 9 STIG v1r1Unix

CONFIGURATION MANAGEMENT

ALMA-09-027520 - AlmaLinux OS 9 must mount /var/log with the nodev option.DISA CloudLinux AlmaLinux OS 9 STIG v1r1Unix

CONFIGURATION MANAGEMENT

CNTR-R2-000550 Rancher RKE2 must be configured with only essential configurations.DISA Rancher Government Solutions RKE2 STIG v2r2Unix

CONFIGURATION MANAGEMENT

DTOO210 - The opening of pre-release versions of file formats new to Excel 2013 through the Compatibility Pack for Office 2013 and Excel 2013 Converter must be blocked.DISA STIG Microsoft Excel 2013 v1r8Windows

CONFIGURATION MANAGEMENT

DTOO210 - The opening of pre-release versions of file formats new to PowerPoint 2013 through the Compatibility Pack for Office 2013 and PowerPoint 2013 Converter must be blocked.DISA STIG Microsoft PowerPoint 2013 v1r7Windows

CONFIGURATION MANAGEMENT

GEN002420 - Removable media, remote file systems, and any file system that does not contain approved setuid files must be mounted with the 'nosuid' option - /etc/vfstabDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN002420 - Removable media, remote file systems, and any file system that does not contain approved setuid files must be mounted with the 'nosuid' option - /etc/vfstabDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GEN002420 - Removable media, remote file systems, and any file system that does not contain approved setuid files must be mounted with the 'nosuid' option - zfs getDISA STIG Solaris 10 SPARC v2r4Unix

CONFIGURATION MANAGEMENT

GEN002420 - Removable media, remote file systems, and any file system that does not contain approved setuid files must be mounted with the 'nosuid' option - zfs getDISA STIG Solaris 10 X86 v2r4Unix

CONFIGURATION MANAGEMENT

GOOG-12-006600 - Google Android 12 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-13-006600 - Google Android 13 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 13 COBO v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-13-006600 - Google Android 13 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 13 COPE v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-14-006600 - Google Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 14 COPE v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-14-006600 - Google Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Google Android 14 COBO v2r1MDM

CONFIGURATION MANAGEMENT

GOOG-14-706600 - Google Android 14 must be configured to enforce an application installation policy by specifying an application allowlist that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].AirWatch - DISA Google Android 14 BYOAD v1r1MDM

CONFIGURATION MANAGEMENT

MSFT-11-001000 - Microsoft Android 11 must be configured to enforce an application installation policy by specifying an application allow list that restricts applications by the following characteristics: [selection: list of digital signatures, cryptographic hash values, names, application version].MobileIron - DISA Microsoft Android 11 COPE v1r2MDM

CONFIGURATION MANAGEMENT

OL6-00-000530 - The Oracle Linux operating system must mount /dev/shm with the nodev option.DISA STIG Oracle Linux 6 v2r7Unix

CONFIGURATION MANAGEMENT

OL08-00-040120 - OL 8 must mount '/dev/shm' with the 'nodev' option.DISA Oracle Linux 8 STIG v2r2Unix

CONFIGURATION MANAGEMENT

OL08-00-040123 - OL 8 must mount '/tmp' with the 'nodev' option.DISA Oracle Linux 8 STIG v2r2Unix

CONFIGURATION MANAGEMENT

OL08-00-040124 - OL 8 must mount '/tmp' with the 'nosuid' option.DISA Oracle Linux 8 STIG v2r2Unix

CONFIGURATION MANAGEMENT

OL08-00-040125 - OL 8 must mount '/tmp' with the 'noexec' option.DISA Oracle Linux 8 STIG v2r2Unix

CONFIGURATION MANAGEMENT

OL08-00-040127 - OL 8 must mount '/var/log' with the 'nosuid' option.DISA Oracle Linux 8 STIG v2r2Unix

CONFIGURATION MANAGEMENT

OL08-00-040130 - OL 8 must mount '/var/log/audit' with the 'nosuid' option.DISA Oracle Linux 8 STIG v2r2Unix

CONFIGURATION MANAGEMENT

OL08-00-040132 - OL 8 must mount '/var/tmp' with the 'nodev' option.DISA Oracle Linux 8 STIG v2r2Unix

CONFIGURATION MANAGEMENT

OL08-00-040133 - OL 8 must mount '/var/tmp' with the 'nosuid' option.DISA Oracle Linux 8 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-06-000532 - The Red Hat Enterprise Linux operating system must mount /dev/shm with the noexec option.DISA Red Hat Enterprise Linux 6 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-08-040120 - RHEL 8 must mount /dev/shm with the nodev option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040121 - RHEL 8 must mount /dev/shm with the nosuid option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040124 - RHEL 8 must mount /tmp with the nosuid option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040125 - RHEL 8 must mount /tmp with the noexec option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040128 - RHEL 8 must mount /var/log with the noexec option.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-09-231050 - RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories.DISA Red Hat Enterprise Linux 9 STIG v2r3Unix

CONFIGURATION MANAGEMENT

RHEL-09-231100 - RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory.DISA Red Hat Enterprise Linux 9 STIG v2r3Unix

CONFIGURATION MANAGEMENT

RHEL-09-231135 - RHEL 9 must mount /tmp with the nosuid option.DISA Red Hat Enterprise Linux 9 STIG v2r3Unix

CONFIGURATION MANAGEMENT

RHEL-09-231140 - RHEL 9 must mount /var with the nodev option.DISA Red Hat Enterprise Linux 9 STIG v2r3Unix

CONFIGURATION MANAGEMENT

RHEL-09-231170 - RHEL 9 must mount /var/log/audit with the nosuid option.DISA Red Hat Enterprise Linux 9 STIG v2r3Unix

CONFIGURATION MANAGEMENT

RHEL-09-231180 - RHEL 9 must mount /var/tmp with the noexec option.DISA Red Hat Enterprise Linux 9 STIG v2r3Unix

CONFIGURATION MANAGEMENT

SOL-11.1-020230 - The operating system must employ automated mechanisms to prevent program execution in accordance with the organization-defined specifications.DISA STIG Solaris 11 X86 v3r1Unix

CONFIGURATION MANAGEMENT

WN10-CC-000180 - Autoplay must be turned off for non-volume devices.DISA Windows 10 STIG v3r2Windows

CONFIGURATION MANAGEMENT

WN10-CC-000185 - The default autorun behavior must be configured to prevent autorun commands.DISA Windows 10 STIG v3r2Windows

CONFIGURATION MANAGEMENT

WN11-CC-000185 - The default autorun behavior must be configured to prevent autorun commands.DISA Windows 11 STIG v2r2Windows

CONFIGURATION MANAGEMENT

WN16-CC-000260 - The default AutoRun behavior must be configured to prevent AutoRun commands.DISA Windows Server 2016 STIG v2r9Windows

CONFIGURATION MANAGEMENT

WN19-CC-000210 - Windows Server 2019 Autoplay must be turned off for non-volume devices.DISA Microsoft Windows Server 2019 STIG v3r3Windows

CONFIGURATION MANAGEMENT

WN19-CC-000220 - Windows Server 2019 default AutoRun behavior must be configured to prevent AutoRun commands.DISA Microsoft Windows Server 2019 STIG v3r3Windows

CONFIGURATION MANAGEMENT