Item Search

NameAudit NamePluginCategory
3.084 - The system is configured to use an unauthorized time server. - 'NTPServer'DISA Windows Vista STIG v6r41Windows

AUDIT AND ACCOUNTABILITY

EDGE-00-000034 - Edge development tools must be disabled.DISA STIG Edge v2r1Windows

CONFIGURATION MANAGEMENT

ESXI-67-000027 - The ESXi host SSH daemon must set a timeout interval on idle sessions.DISA STIG VMware vSphere 6.7 ESXi OS v1r3Unix

CONFIGURATION MANAGEMENT

ESXI-67-000055 - The ESXi host must disable Inter-VM transparent page sharing.DISA STIG VMware vSphere 6.7 ESXi v1r3VMware

CONFIGURATION MANAGEMENT

F5BI-AP-000236 - The F5 BIG-IP appliance must be configured to limit authenticated client sessions to initial session source IP.DISA F5 BIG-IP Access Policy Manager STIG v2r3F5

SYSTEM AND COMMUNICATIONS PROTECTION

FFOX-00-000015 - Firefox development tools must be disabled.DISA STIG Mozilla Firefox Linux v6r5Unix

SYSTEM AND INFORMATION INTEGRITY

FFOX-00-000015 - Firefox development tools must be disabled.DISA STIG Mozilla Firefox MacOS v6r5Unix

SYSTEM AND INFORMATION INTEGRITY

HONW-09-000500 - The Honeywell Mobility Edge Android Pie device must be configured to not allow more than 10 consecutive failed authentication attempts.MobileIron - DISA Honeywell Android 9.x COPE v1r2MDM

ACCESS CONTROL

HONW-09-006100 - The Honeywell Mobility Edge Android Pie device must be configured to generate audit records for the following auditable events: detected integrity violations.MobileIron - DISA Honeywell Android 9.x COBO v1r2MDM

AUDIT AND ACCOUNTABILITY

KNOX-07-004300 - The Samsung must be configured to display the DoD advisory warning message at start-up or when the user unlocks the device.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

ACCESS CONTROL

KNOX-07-017800 - The Samsung Android 7 with Knox must be configured to Disable Bixby.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-018000 - The Samsung Android 7 with Knox must be configured to Disable Smart Call.AirWatch - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

KNOX-07-018000 - The Samsung Android 7 with Knox must be configured to Disable Smart Call.MobileIron - DISA Samsung Android 7 with Knox 2.x v1r1MDM

CONFIGURATION MANAGEMENT

MOTO-09-000500 - The Motorola Android Pie must be configured to not allow more than 10 consecutive failed authentication attempts.AirWatch - DISA Motorola Android Pie.x COPE v1r2MDM

ACCESS CONTROL

MOTO-09-003400 - The Motorola Android Pie must be configured to display the DoD advisory warning message at startup or each time the user unlocks the device.AirWatch - DISA Motorola Android Pie.x COBO v1r2MDM

ACCESS CONTROL

MOTS-11-006100 - Motorola Solutions Android 11 must be configured to generate audit records for the following auditable events: Detected integrity violations.AirWatch - DISA Motorola Solutions Android 11 COBO v1r3MDM

AUDIT AND ACCOUNTABILITY

MSFT-11-003400 - Microsoft Android 11 must be configured to display the DOD advisory warning message at start-up or each time the user unlocks the device.MobileIron - DISA Microsoft Android 11 COBO v1r2MDM

ACCESS CONTROL

OL08-00-010292 - The OL 8 SSH server must be configured to use strong entropy.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

OL08-00-010472 - OL 8 must have the packages required to use the hardware random number generator entropy gatherer service.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

OL08-00-010473 - OL 8 must enable the hardware random number generator entropy gatherer service.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

OL08-00-030741 - OL 8 must disable the chrony daemon from acting as a server.DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

OL08-00-040310 - The OL 8 file integrity tool must be configured to verify Access Control Lists (ACLs).DISA Oracle Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-010292 - RHEL 8 must ensure the SSH server uses strong entropy.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-010541 - RHEL 8 must use a separate file system for /var/log.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-020024 - RHEL 8 must limit the number of concurrent sessions to ten for all accounts and/or account types.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

ACCESS CONTROL

RHEL-08-030063 - RHEL 8 must resolve audit information before writing to disk.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040004 - RHEL 8 must enable mitigations against processor-based vulnerabilities.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040022 - RHEL 8 must disable the controller area network (CAN) protocol.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040024 - RHEL 8 must disable the transparent inter-process communication (TIPC) protocol.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040026 - RHEL 8 must disable IEEE 1394 (FireWire) Support.DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-08-040310 - The RHEL 8 file integrity tool must be configured to verify Access Control Lists (ACLs).DISA Red Hat Enterprise Linux 8 STIG v2r1Unix

CONFIGURATION MANAGEMENT

RHEL-09-231195 - RHEL 9 must disable mounting of cramfs.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-09-412075 - RHEL 9 must display the date and time of the last successful account logon upon logon.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

CONFIGURATION MANAGEMENT

RHEL-09-651035 - RHEL 9 must be configured so that the file integrity tool verifies extended attributes.DISA Red Hat Enterprise Linux 9 STIG v2r2Unix

CONFIGURATION MANAGEMENT

SLES-12-010375 - The SUSE operating system must restrict access to the kernel message buffer.DISA SLES 12 STIG v2r13Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SLES-15-010375 - The SUSE operating system must restrict access to the kernel message buffer.DISA SLES 15 STIG v2r1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

SQL2-00-022300 - SQL Server must limit the use of resources by priority and not impede the host from servicing processes designated as a higher priority.DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

SYSTEM AND COMMUNICATIONS PROTECTION

SQL2-00-023700 - SQL Server must protect against an individual using a shared account from falsely denying having performed a particular action.DISA STIG SQL Server 2012 DB Instance Security v1r20MS_SQLDB

AUDIT AND ACCOUNTABILITY

SQL2-00-039100 - The SQL Server Browser service must be disabled if its use is not necessary.DISA STIG SQL Server 2012 Database OS Audit v1r20Windows

CONFIGURATION MANAGEMENT

UBTU-20-010401 - The Ubuntu operating system must restrict access to the kernel message buffer.DISA STIG Ubuntu 20.04 LTS v2r1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

UBTU-20-010453 - The Ubuntu operating system must display the date and time of the last successful account logon upon logon.DISA STIG Ubuntu 20.04 LTS v2r1Unix

ACCESS CONTROL

VMCH-67-000002 - Drag and drop operations must be disabled on the virtual machine.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

VMCH-67-000015 - Informational messages from the virtual machine to the VMX file must be limited on the virtual machine.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

VMCH-67-000018 - Shared salt values must be disabled on the virtual machine.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

VMCH-67-000019 - Access to virtual machines through the dvfilter network APIs must be controlled.DISA STIG VMware vSphere 6.7 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

VMCH-70-000003 - Paste operations must be disabled on the virtual machine (VM).DISA STIG VMware vSphere 7.0 Virtual Machine v1r3VMware

CONFIGURATION MANAGEMENT

WBSP-AS-000640 - The WebSphere Application Server must alert the SA and ISSO, in the event of a log processing failure - notificationDISA IBM WebSphere Traditional 9 STIG v1r1Unix

AUDIT AND ACCOUNTABILITY

WN22-00-000180 - Windows Server 2022 nonadministrative accounts or groups must only have print permissions on printer shares.DISA Windows Server 2022 STIG v2r2Windows

ACCESS CONTROL

WN22-CC-000030 - Windows Server 2022 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing.DISA Windows Server 2022 STIG v2r2Windows

CONFIGURATION MANAGEMENT

WN22-CC-000060 - Windows Server 2022 must be configured to ignore NetBIOS name release requests except from WINS servers.DISA Windows Server 2022 STIG v2r2Windows

SYSTEM AND COMMUNICATIONS PROTECTION