Item Search

NameAudit NamePluginCategory
CIS_Aliyun_Linux_2_L2_v1.0.0.audit from CIS Aliyun Linux 2 Benchmark v1.0.0CIS Aliyun Linux 2 L2 v1.0.0Unix
CIS_Apache_Tomcat_11_v1.0.0_L2.audit from CIS Apache Tomcat 11 Benchmark v1.0.0CIS Apache Tomcat 11 v1.0.0 L2Unix
CIS_Apple_macOS_14_Sonoma_STIG_v1.0.0_CAT_I.audit from CIS Apple macOS 14 Sonoma STIG v1.0.0CIS Apple macOS 14 Sonoma STIG v1.0.0 CAT IUnix
CIS_Apple_macOS_15_Sequoia_STIG_v1.0.0_CAT_II.audit from CIS Apple macOS 15 Sequoia STIG v1.0.0CIS Apple macOS 15 Sequoia STIG v1.0.0 CAT IIUnix
CIS_Apple_macOS_26_Tahoe_STIG_v1.0.0_CAT_I.audit from CIS Apple macOS 26 Tahoe STIG v1.0.0CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IUnix
CIS_Cisco_IOS_XE_Switch_L2S_STIG_v1.0.0_CAT_I.audit from CIS Cisco IOS XE Switch L2S STIG v1.0.0CIS Cisco IOS XE Switch L2S STIG v1.0.0 CAT ICisco
CIS_Microsoft_Office_System_2016_STIG_v1.0.0_CAT_II.audit from CIS Microsoft Office System 2016 STIG v1.0.0CIS Microsoft Office System 2016 STIG v1.0.0 CAT IIWindows
CIS_Mozilla_Firefox_38_ESR_v1.0.0_Windows_Level1.audit for CIS Mozilla Firefox 38 ESR v1.0.0CIS Mozilla Firefox 38 ESR Windows L1 v1.0.0Windows
CIS_Mozilla_Firefox_38_ESR_v1.0.0_Windows_Level2.audit for CIS Mozilla Firefox 38 ESR v1.0.0CIS Mozilla Firefox 38 ESR Windows L2 v1.0.0Windows
CIS_Red_Hat_Enterprise_Linux_9_STIG_v1.0.0_CAT_I.audit from CIS Red Hat Enterprise Linux 9 STIG v1.0.0CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IUnix
CIS_Red_Hat_Enterprise_Linux_9_STIG_v1.0.0_CAT_II.audit from CIS Red Hat Enterprise Linux 9 STIG v1.0.0CIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT IIUnix
CIS_Red_Hat_Enterprise_Linux_10_STIG_v1.0.0_CAT_III.audit from CIS Red Hat Enterprise Linux 10 STIG v1.0.0CIS Red Hat Enterprise Linux 10 STIG v1.0.0 CAT IIIUnix
CIS_VMware_vSphere_8.0_ESXi_STIG_v1.0.0_CAT_I_Unix.audit from CIS VMware vSphere 8.0 ESXi STIG v1.0.0CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT I UnixUnix
CIS_VMware_vSphere_8.0_ESXi_STIG_v1.0.0_CAT_II_Unix.audit from CIS VMware vSphere 8.0 ESXi STIG v1.0.0CIS VMware vSphere 8.0 ESXi STIG v1.0.0 CAT II UnixUnix
VMCH-80-000203 Virtual machines (VMs) must enable encryption for vMotion.DISA VMware vSphere 8.0 Virtual Machine STIG v2r1VMware

CONFIGURATION MANAGEMENT

WA000-WI030 IIS6 - The IUSR_machinename account must not have read access to the .inc files or their equivalent. - 'global.asa'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.bat mappings'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - '.HTR scripting Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Index Server Web Interface Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI050 IIS6 - Unused and vulnerable script mappings in IIS 6 must be removed. - 'Internet Data Connector Disallowed'DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI070 IIS6 - Indexing Services must only index web content.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI092 IIS6 - The IIS web site permissions 'Write' or 'Script Source' must not be selected. - 'Script Source permission check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI6020 IIS6 - The Recycle Worker processes in minutes monitor must be set properly.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6024 IIS6 - The maximum virtual memory monitor must be enabled.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6026 IIS6 - The maximum used memory monitor must be enabled.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6028 IIS6 - The Shutdown worker processes Idle Timeout monitor must be enabled.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WA000-WI6040 IIS6 - A unique non-privileged account must be used to run Worker Process Identities. - 'AppPoolIdentityType = 3 - WAMUserName'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WA000-WI6040 IIS6 - A unique non-privileged account must be used to run Worker Process Identities. - 'AppPoolIdentityType Check'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL

WG140 IIS6 - A private web sites authentication mechanism must use client certificates. - 'AccessSSLRequireCert Enabled'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG145 IIS6 - The private web server must use an approved DoD certificate validation process. - 'Check W3SVC CertCheckMode'DISA STIG IIS 6.0 Site Checklist v6r16Windows

IDENTIFICATION AND AUTHENTICATION

WG210 IIS6 - Web content directories must not be anonymously shared.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WG240 IIS6 - Logs of web server access and errors must be established and maintained.DISA STIG IIS 6.0 Site Checklist v6r16Windows
WG250 IIS6 - Users other than Auditors group must not have greater than read access to log files.DISA STIG IIS 6.0 Site Checklist v6r16Windows

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

WG260 IIS6 - Only fully reviewed and tested web sites must exist on a production web server.DISA STIG IIS 6.0 Site Checklist v6r16Windows
WG310 IIS6 - A web site must not contain a robots.txt file.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WG340 IIS6 - A private web server must utilize an approved TLS version. - 'PCT 1.0\Server'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG340 IIS6 - A private web server must utilize an approved TLS version. - 'SSL 2.0\Server'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG340 IIS6 - A private web server must utilize an approved TLS version. - 'SSL 3.0\Server'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG342 IIS6 - Public web servers must use TLS if authentication is required. - '128-Bit Encryption Enabled'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG342 IIS6 - Public web servers must use TLS if authentication is required. - 'SSL 3.0 Client'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG342 IIS6 - Public web servers must use TLS if authentication is required. - 'TLS 1.0 Server'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG350 IIS6 - A private web server must have a valid server certificate.DISA STIG IIS 6.0 Site Checklist v6r16Windows
WG355 IIS6 - A private web site must utilize certificates from a trusted DoD CA.DISA STIG IIS 6.0 Site Checklist v6r16Windows
WG410 IIS6 - Interactive scripts must have proper access controls. - 'AspScriptTimeout set to 90 or less'DISA STIG IIS 6.0 Site Checklist v6r16Windows

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

WG410 IIS6 - Interactive scripts must have proper access controls. - 'CGI Directory Permissions'DISA STIG IIS 6.0 Site Checklist v6r16Windows
WG410 IIS6 - Interactive scripts must have proper access controls. - 'Execute Permissions set 'Script only'DISA STIG IIS 6.0 Site Checklist v6r16Windows
WG410 IIS6 - Interactive scripts must have proper access controls. - 'Virtual Directories - Enable Parent Paths set to False'DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WG420 IIS6 - Backup interactive scripts must be removed from the web site.DISA STIG IIS 6.0 Site Checklist v6r16Windows

CONFIGURATION MANAGEMENT

WG460 IIS6 - PERL scripts must use the TAINT option.DISA STIG IIS 6.0 Site Checklist v6r16Windows

SYSTEM AND INFORMATION INTEGRITY

Word 6.0 binary documents and templatesMSCT Microsoft 365 Apps for Enterprise 2112 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY