Item Search

NameAudit NamePluginCategory
BIND-9X-001030 - The BIND 9.x secondary name server must limit the total number of zones the name server can request at any one time.DISA BIND 9.x STIG v3r2Unix

ACCESS CONTROL

BIND-9X-001220 - On a BIND 9.x server, for zones split between the external and internal sides of a network, the RRs for the external hosts must be separate from the RRs for the internal hosts.DISA BIND 9.x STIG v3r2Unix

CONFIGURATION MANAGEMENT

BIND-9X-001320 - A BIND 9.x server validity period for the RRSIGs covering a zones DNSKEY RRSet must be no less than two days and no more than one week.DISA BIND 9.x STIG v3r2Unix

CONFIGURATION MANAGEMENT

BIND-9X-001360 - The BIND 9.x server implementation must prohibit the forwarding of queries to servers controlled by organizations outside of the U.S. government.DISA BIND 9.x STIG v3r2Unix

CONFIGURATION MANAGEMENT

IIST-SI-000270 - HTTPAPI Server version must be removed from the HTTP Response Header information.DISA IIS 10.0 Site v2r14Windows

SYSTEM AND INFORMATION INTEGRITY

WN22-00-000230 - Windows Server 2022 nonsystem-created file shares must limit access to groups that require it.DISA Microsoft Windows Server 2022 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN22-00-000320 - Windows Server 2022 must not have the Fax Server role installed.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-00-000450 - Windows Server 2022 must have orphaned security identifiers (SIDs) removed from user rights.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-00-000460 - Windows Server 2022 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-AU-000080 - Windows Server 2022 must be configured to audit Account Logon - Credential Validation failures.DISA Microsoft Windows Server 2022 STIG v2r8Windows

AUDIT AND ACCOUNTABILITY

WN22-AU-000220 - Windows Server 2022 must be configured to audit Object Access - Other Object Access Events successes.DISA Microsoft Windows Server 2022 STIG v2r8Windows

AUDIT AND ACCOUNTABILITY

WN22-AU-000581 - Windows Server 2022 must be configured to audit file system failures.DISA Microsoft Windows Server 2022 STIG v2r8Windows

AUDIT AND ACCOUNTABILITY

WN22-AU-000585 - Windows Server 2022 must be configured to audit registry failures.DISA Microsoft Windows Server 2022 STIG v2r8Windows

AUDIT AND ACCOUNTABILITY

WN22-CC-000070 - Windows Server 2022 insecure logons to an SMB server must be disabled.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-CC-000150 - Windows Server 2022 downloading print driver packages over HTTP must be turned off.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-CC-000160 - Windows Server 2022 printing over HTTP must be turned off.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-DC-000130 - Windows Server 2022 domain controllers must run on a machine dedicated to that function.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-DC-000360 - Windows Server 2022 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL

WN22-DC-000400 - Windows Server 2022 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access.DISA Microsoft Windows Server 2022 STIG v2r8Windows

ACCESS CONTROL

WN22-MS-000020 - Windows Server 2022 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers.DISA Microsoft Windows Server 2022 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN22-MS-000030 - Windows Server 2022 local users on domain-joined member servers must not be enumerated.DISA Microsoft Windows Server 2022 STIG v2r8Windows

CONFIGURATION MANAGEMENT

WN22-SO-000050 - Windows Server 2022 must force audit policy subcategory settings to override audit policy category settings.DISA Microsoft Windows Server 2022 STIG v2r8Windows

AUDIT AND ACCOUNTABILITY

WN22-SO-000400 - Windows Server 2022 User Account Control (UAC) must, at a minimum, prompt administrators for consent on the secure desktop.DISA Microsoft Windows Server 2022 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN22-SO-000410 - Windows Server 2022 User Account Control (UAC) must automatically deny standard user requests for elevation.DISA Microsoft Windows Server 2022 STIG v2r8Windows

IDENTIFICATION AND AUTHENTICATION

WN22-SO-000430 - Windows Server 2022 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations.DISA Microsoft Windows Server 2022 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN22-SO-000450 - Windows Server 2022 User Account Control (UAC) must virtualize file and registry write failures to per-user locations.DISA Microsoft Windows Server 2022 STIG v2r8Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-00-000001 - Windows Server 2025 must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs).DISA Microsoft Windows Server 2025 STIG v1r1Windows

SYSTEM AND INFORMATION INTEGRITY

WN25-00-000350 - Windows Server 2025 must not have Simple TCP/IP Services installed.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-00-000390 - Windows Server 2025 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-00-000400 - Windows Server 2025 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-AU-000210 - Windows Server 2025 must be configured to audit Logon/Logoff - Special Logon successes.DISA Microsoft Windows Server 2025 STIG v1r1Windows

AUDIT AND ACCOUNTABILITY

WN25-AU-000230 - Windows Server 2025 must be configured to audit Object Access - Other Object Access Events failures.DISA Microsoft Windows Server 2025 STIG v1r1Windows

AUDIT AND ACCOUNTABILITY

WN25-AU-000585 - Windows Server 2025 must be configured to audit registry failures.DISA Microsoft Windows Server 2025 STIG v1r1Windows

AUDIT AND ACCOUNTABILITY

WN25-AU-000587 - Windows Server 2025 must be configured to audit sensitive privilege use successes.DISA Microsoft Windows Server 2025 STIG v1r1Windows

AUDIT AND ACCOUNTABILITY

WN25-CC-000080 - Windows Server 2025 hardened Universal Naming Convention (UNC) paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-CC-000110 - Windows Server 2025 virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-CC-000130 - Windows Server 2025 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-CC-000360 - Windows Server 2025 Remote Desktop Services must always prompt a client for passwords upon connection.DISA Microsoft Windows Server 2025 STIG v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-CC-000400 - Windows Server 2025 must disable Basic authentication for RSS feeds over HTTP.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-CC-000440 - Windows Server 2025 users must be notified if a web-based program attempts to install software.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-CC-000490 - Windows Server 2025 Windows Remote Management (WinRM) client must not use Digest authentication.DISA Microsoft Windows Server 2025 STIG v1r1Windows

MAINTENANCE

WN25-DC-000340 - The Windows Server 2025 'Access this computer from the network' user right must only be assigned to the Administrators, Authenticated Users, and Enterprise Domain Controllers groups on domain controllers.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL

WN25-MS-000070 - Windows Server 2025 'Access this computer from the network' user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and stand-alone or nondomain-joined systems.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL

WN25-MS-000090 - Windows Server 2025 Deny log on as a batch job user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL

WN25-SO-000050 - Windows Server 2025 must force audit policy subcategory settings to override audit policy category settings.DISA Microsoft Windows Server 2025 STIG v1r1Windows

AUDIT AND ACCOUNTABILITY

WN25-SO-000260 - Windows Server 2025 services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-SO-000270 - Windows Server 2025 must prevent NTLM from falling back to a Null session.DISA Microsoft Windows Server 2025 STIG v1r1Windows

CONFIGURATION MANAGEMENT

WN25-SO-000360 - Windows Server 2025 must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing.DISA Microsoft Windows Server 2025 STIG v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-SO-000400 - Windows Server 2025 User Account Control (UAC) must, at a minimum, prompt administrators for consent on the secure desktop.DISA Microsoft Windows Server 2025 STIG v1r1Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN25-UR-000030 - The Windows Server 2025 'Allow log on locally' user right must only be assigned to the Administrators group.DISA Microsoft Windows Server 2025 STIG v1r1Windows

ACCESS CONTROL