Item Search

NameAudit NamePluginCategory
ARST-ND-000820 - The network device must be configured to conduct backups of system level information contained in the information system when changes occur.DISA STIG Arista MLS EOS 4.x NDM v2r2Arista

CONTINGENCY PLANNING

ARST-RT-000030 - The Arista BGP router must be configured to reject inbound route advertisements for any prefixes belonging to the local autonomous system (AS).DISA STIG Arista MLS EOS 4.x Router v2r2Arista

ACCESS CONTROL

ARST-RT-000110 - The Arista perimeter router must be configured to enforce approved authorizations for controlling the flow of information between interconnected networks in accordance with applicable policy.DISA STIG Arista MLS EOS 4.x Router v2r2Arista

ACCESS CONTROL

ARST-RT-000120 - The Arista multicast router must be configured to disable Protocol Independent Multicast (PIM) on all interfaces that are not required to support multicast routing.DISA STIG Arista MLS EOS 4.x Router v2r2Arista

ACCESS CONTROL

ARST-RT-000130 - The Arista multicast router must be configured to bind a Protocol Independent Multicast (PIM) neighbor filter to interfaces that have PIM enabled.DISA STIG Arista MLS EOS 4.x Router v2r2Arista

ACCESS CONTROL

ARST-RT-000530 - The Arista router must be configured to have Internet Control Message Protocol (ICMP) unreachable notifications disabled on all external interfaces.DISA STIG Arista MLS EOS 4.x Router v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000540 - The Arista router must be configured to have Internet Control Message Protocol (ICMP) mask replies disabled on all external interfaces.DISA STIG Arista MLS EOS 4.x Router v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

ARST-RT-000650 - The Arista perimeter router must be configured to block all outbound management traffic.DISA STIG Arista MLS EOS 4.x Router v2r2Arista

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000391 - The Cisco perimeter switch must be configured to suppress Router Advertisements on all external IPv6-enabled interfaces.DISA Cisco IOS Switch RTR STIG v3r1Cisco

CONFIGURATION MANAGEMENT

HONW-13-006300 - Honeywell Android 13 must be configured to lock the display after 15 minutes (or less) of inactivity.MobileIron - DISA Honeywell Android 13 COBO v1r1MDM

ACCESS CONTROL

HONW-13-008500 - Honeywell Android 13 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.AirWatch - DISA Honeywell Android 13 COBO v1r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

HONW-13-008500 - Honeywell Android 13 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.MobileIron - DISA Honeywell Android 13 COBO v1r1MDM

SYSTEM AND COMMUNICATIONS PROTECTION

HONW-13-010100 - The Honeywell Android 13 work profile must be configured to prevent users from adding personal email accounts to the work email app.AirWatch - DISA Honeywell Android 13 COBO v1r1MDM

CONFIGURATION MANAGEMENT

HONW-13-010200 - The Honeywell Android 13 work profile must be configured to enforce the system application disable list.AirWatch - DISA Honeywell Android 13 COBO v1r1MDM

CONFIGURATION MANAGEMENT

SYMP-AG-000310 - Symantec ProxySG providing user authentication intermediary services must require users to reauthenticate every 900 seconds when organization-defined circumstances or situations require reauthentication - iwaDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000310 - Symantec ProxySG providing user authentication intermediary services must require users to reauthenticate every 900 seconds when organization-defined circumstances or situations require reauthentication - siteminderDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

IDENTIFICATION AND AUTHENTICATION

SYMP-AG-000450 - Symantec ProxySG providing forward proxy encryption intermediary services must use NIST FIPS-validated cryptography to implement encryption services. - SourceDISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

SYMP-NM-000050 - Symantec ProxySG must be configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period - Lockout durationDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

ACCESS CONTROL

SYMP-NM-000050 - Symantec ProxySG must be configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period - max-failed-attemptsDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

ACCESS CONTROL

SYMP-NM-000050 - Symantec ProxySG must be configured to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period - Reset intervalDISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

ACCESS CONTROL

WN10-CC-000391 - Internet Explorer must be disabled for Windows 10.DISA Microsoft Windows 10 STIG v3r4Windows

CONFIGURATION MANAGEMENT

WN11-00-000075 - Only accounts responsible for the backup operations must be members of the Backup Operators group.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-00-000115 - The Telnet Client must not be installed on the system.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-00-000120 - The TFTP Client must not be installed on the system.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-00-000125 - Copilot in Windows must be disabled for Windows 11DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-00-000170 - The Server Message Block (SMB) v1 protocol must be disabled on the SMB client.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-AU-000010 - The system must be configured to audit Account Logon - Credential Validation successes.DISA Microsoft Windows 11 STIG v2r4Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000075 - The system must be configured to audit Logon/Logoff - Logon successes.DISA Microsoft Windows 11 STIG v2r4Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000083 - Windows 11 must be configured to audit Object Access - Other Object Access Events successes.DISA Microsoft Windows 11 STIG v2r4Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000085 - The system must be configured to audit Object Access - Removable Storage failures.DISA Microsoft Windows 11 STIG v2r4Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000160 - The system must be configured to audit System - System Integrity successes.DISA Microsoft Windows 11 STIG v2r4Windows

AUDIT AND ACCOUNTABILITY

WN11-AU-000525 - Windows 11 permissions for the System event log must prevent access by non-privileged accounts.DISA Microsoft Windows 11 STIG v2r4Windows

AUDIT AND ACCOUNTABILITY

WN11-CC-000005 - Camera access from the lock screen must be disabled.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-CC-000010 - The display of slide shows on the lock screen must be disabled.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-CC-000039 - Run as different user must be removed from context menus.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-CC-000060 - Connections to non-domain networks when connected to a domain authenticated network must be blocked.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-CC-000085 - Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-CC-000130 - Local users on domain-joined computers must not be enumerated.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-CC-000280 - Remote Desktop Services must always prompt a client for passwords upon connection.DISA Microsoft Windows 11 STIG v2r4Windows

IDENTIFICATION AND AUTHENTICATION

WN11-CC-000295 - Attachments must be prevented from being downloaded from RSS feeds.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-SO-000010 - The built-in guest account must be disabled.DISA Microsoft Windows 11 STIG v2r4Windows

IDENTIFICATION AND AUTHENTICATION

WN11-SO-000015 - Local accounts with blank passwords must be restricted to prevent access from the network.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-SO-000160 - The system must be configured to prevent anonymous users from having the same rights as the Everyone group.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-SO-000180 - NTLM must be prevented from falling back to a Null session.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-SO-000250 - User Account Control must prompt administrators for consent on the secure desktop.DISA Microsoft Windows 11 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000260 - User Account Control must be configured to detect application installations and prompt for elevation.DISA Microsoft Windows 11 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-SO-000275 - User Account Control must virtualize file and registry write failures to per-user locations.DISA Microsoft Windows 11 STIG v2r4Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN11-UC-000020 - Zone information must be preserved when saving attachments.DISA Microsoft Windows 11 STIG v2r4Windows

CONFIGURATION MANAGEMENT

WN11-UR-000025 - The 'Allow log on locally' user right must only be assigned to the Administrators and Users groups.DISA Microsoft Windows 11 STIG v2r4Windows

ACCESS CONTROL

WN11-UR-000080 - The 'Deny log on as a service' user right on Windows 11 domain-joined workstations must be configured to prevent access from highly privileged domain accounts.DISA Microsoft Windows 11 STIG v2r4Windows

ACCESS CONTROL