GEN005760 - The NFS export configuration file must have mode 0644 or less permissive. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN005880 - The NFS server must not allow remote root access. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN006140 - The /usr/lib/smb.conf file must have mode 0644 or less permissive. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN006210 - The /var/private/smbpasswd file must not have an extended ACL. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN006460 - Any NIS+ server must be operating at security level 2. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN006565 - The system package management tool must be used to verify system software periodically. | DISA STIG AIX 5.3 v1r2 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
GEN006620 - The system's access control program must be configured to grant or deny system access to specific hosts - 'hosts.deny ALL:ALL' | DISA STIG AIX 5.3 v1r2 | Unix | CONFIGURATION MANAGEMENT |
GEN007820 - The system must not have IP tunnels configured - 'ifconfig -a' | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN008460 - The system must have USB disabled unless needed - 'lsdev' | DISA STIG AIX 5.3 v1r2 | Unix | CONFIGURATION MANAGEMENT |
GEN008620 - System BIOS or system controllers supporting password protection must have administrator accounts/passwords configured. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN009160 - The system must not have the Calendar Manager Service Daemon (CMSD) service active. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN009190 - The system must not have the comsat service active. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
GEN009320 - The system must not have the sprayd service active. | DISA STIG AIX 5.3 v1r2 | Unix | ACCESS CONTROL |
SLES-15-010480 - The SUSE operating system must disable the USB mass storage kernel module. | DISA SLES 15 STIG v2r2 | Unix | IDENTIFICATION AND AUTHENTICATION |
SLES-15-020181 - The SUSE operating system must not have accounts configured with blank or null passwords. | DISA SLES 15 STIG v2r2 | Unix | CONFIGURATION MANAGEMENT |
SLES-15-040040 - The SUSE operating system file integrity tool must be configured to verify Access Control Lists (ACLs). | DISA SLES 15 STIG v2r2 | Unix | CONFIGURATION MANAGEMENT |
SLES-15-040210 - The SUSE operating system must use a separate file system for /var. | DISA SLES 15 STIG v2r2 | Unix | CONFIGURATION MANAGEMENT |
SLES-15-040410 - All SUSE operating system files and directories must have a valid group owner. | DISA SLES 15 STIG v2r2 | Unix | SYSTEM AND INFORMATION INTEGRITY |
WN10-00-000110 - Simple TCP/IP Services must not be installed on the system. | DISA Windows 10 STIG v3r2 | Windows | CONFIGURATION MANAGEMENT |
WN10-00-000120 - The TFTP Client must not be installed on the system. | DISA Windows 10 STIG v3r2 | Windows | CONFIGURATION MANAGEMENT |
WN10-AC-000025 - The maximum password age must be configured to 60 days or less. | DISA Windows 10 STIG v3r2 | Windows | IDENTIFICATION AND AUTHENTICATION |
WN10-CC-000185 - The default autorun behavior must be configured to prevent autorun commands. | DISA Windows 10 STIG v3r2 | Windows | CONFIGURATION MANAGEMENT |
WN10-CC-000200 - Administrator accounts must not be enumerated during elevation. | DISA Windows 10 STIG v3r2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
WN10-CC-000238 - Windows 10 must be configured to prevent certificate error overrides in Microsoft Edge. | DISA Windows 10 STIG v3r2 | Windows | CONFIGURATION MANAGEMENT |
WN10-CC-000275 - Local drives must be prevented from sharing with Remote Desktop Session Hosts. | DISA Windows 10 STIG v3r2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
WN10-CC-000290 - Remote Desktop Services must be configured with the client connection encryption set to the required level. | DISA Windows 10 STIG v3r2 | Windows | ACCESS CONTROL, MAINTENANCE |
WN10-CC-000310 - Users must be prevented from changing installation options. | DISA Windows 10 STIG v3r2 | Windows | CONFIGURATION MANAGEMENT |
WN10-CC-000330 - The Windows Remote Management (WinRM) client must not use Basic authentication. | DISA Windows 10 STIG v3r2 | Windows | MAINTENANCE |
WN10-CC-000355 - The Windows Remote Management (WinRM) service must not store RunAs credentials. | DISA Windows 10 STIG v3r2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
WN10-SO-000035 - Outgoing secure channel traffic must be encrypted or signed. | DISA Windows 10 STIG v3r2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
WN10-SO-000040 - Outgoing secure channel traffic must be encrypted when possible. | DISA Windows 10 STIG v3r2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
WN10-UR-000125 - The Lock pages in memory user right must not be assigned to any groups or accounts. | DISA Windows 10 STIG v3r2 | Windows | ACCESS CONTROL |
WN11-00-000045 - The Windows 11 system must use an antivirus program. | DISA Windows 11 STIG v2r2 | Windows | CONFIGURATION MANAGEMENT |
WN11-00-000135 - A host-based firewall must be installed and enabled on the system. | DISA Windows 11 STIG v2r2 | Windows | CONFIGURATION MANAGEMENT |
WN11-AC-000025 - The maximum password age must be configured to 60 days or less. | DISA Windows 11 STIG v2r2 | Windows | IDENTIFICATION AND AUTHENTICATION |
WN11-AC-000045 - Reversible password encryption must be disabled. | DISA Windows 11 STIG v2r2 | Windows | IDENTIFICATION AND AUTHENTICATION |
WN11-CC-000010 - The display of slide shows on the lock screen must be disabled. | DISA Windows 11 STIG v2r2 | Windows | CONFIGURATION MANAGEMENT |
WN11-CC-000165 - Unauthenticated RPC clients must be restricted from connecting to the RPC server. | DISA Windows 11 STIG v2r2 | Windows | IDENTIFICATION AND AUTHENTICATION |
WN11-CC-000200 - Administrator accounts must not be enumerated during elevation. | DISA Windows 11 STIG v2r2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
WN11-CC-000252 - Windows 11 must be configured to disable Windows Game Recording and Broadcasting. | DISA Windows 11 STIG v2r2 | Windows | CONFIGURATION MANAGEMENT |
WN11-CC-000270 - Passwords must not be saved in the Remote Desktop Client. | DISA Windows 11 STIG v2r2 | Windows | IDENTIFICATION AND AUTHENTICATION |
WN11-CC-000335 - The Windows Remote Management (WinRM) client must not allow unencrypted traffic. | DISA Windows 11 STIG v2r2 | Windows | MAINTENANCE |
WN11-CC-000350 - The Windows Remote Management (WinRM) service must not allow unencrypted traffic. | DISA Windows 11 STIG v2r2 | Windows | MAINTENANCE |
WN11-CC-000360 - The Windows Remote Management (WinRM) client must not use Digest authentication. | DISA Windows 11 STIG v2r2 | Windows | MAINTENANCE |
WN11-SO-000060 - The system must be configured to require a strong session key. | DISA Windows 11 STIG v2r2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
WN11-SO-000095 - The Smart Card removal option must be configured to Force Logoff or Lock Workstation. | DISA Windows 11 STIG v2r2 | Windows | CONFIGURATION MANAGEMENT |
WN11-SO-000145 - Anonymous enumeration of SAM accounts must not be allowed. | DISA Windows 11 STIG v2r2 | Windows | CONFIGURATION MANAGEMENT |
WN11-SO-000160 - The system must be configured to prevent anonymous users from having the same rights as the Everyone group. | DISA Windows 11 STIG v2r2 | Windows | CONFIGURATION MANAGEMENT |
WN11-SO-000180 - NTLM must be prevented from falling back to a Null session. | DISA Windows 11 STIG v2r2 | Windows | CONFIGURATION MANAGEMENT |
WN11-SO-000260 - User Account Control must be configured to detect application installations and prompt for elevation. | DISA Windows 11 STIG v2r2 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |