Item Search

NameAudit NamePluginCategory
AMLS-L3-000250 - Arista MLS must encrypt all methods of configured authentication for the OSPF routing protocol - message-digestDISA STIG Arista MLS DCS-7000 Series RTR V1R2Arista

IDENTIFICATION AND AUTHENTICATION

CISC-RT-000040 - The Cisco router must be configured to use encryption for routing protocol authentication - EIGRPDISA STIG Cisco IOS-XR Router RTR v2r2Cisco
CISC-RT-000040 - The Cisco router must be configured to use encryption for routing protocol authentication - EIGRPDISA STIG Cisco IOS-XR Router RTR v2r3Cisco
CISC-RT-000040 - The Cisco router must be configured to use encryption for routing protocol authentication - EIGRPDISA STIG Cisco IOS XE Router RTR v2r6Cisco
CISC-RT-000040 - The Cisco router must be configured to use encryption for routing protocol authentication - IS-ISDISA STIG Cisco IOS Router RTR v2r4Cisco
CISC-RT-000040 - The Cisco router must be configured to use encryption for routing protocol authentication - RIPDISA STIG Cisco IOS Router RTR v1r4Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000040 - The Cisco switch must be configured to use encryption for routing protocol authentication - bgpDISA STIG Cisco IOS Switch RTR v2r2Cisco
CISC-RT-000040 - The Cisco switch must be configured to use encryption for routing protocol authentication - eigrpDISA STIG Cisco IOS XE Switch RTR v2r1Cisco
CISC-RT-000040 - The Cisco switch must be configured to use encryption for routing protocol authentication - eigrpDISA STIG Cisco IOS Switch RTR v2r2Cisco
CISC-RT-000040 - The Cisco switch must be configured to use encryption for routing protocol authentication - is-isDISA STIG Cisco IOS Switch RTR v1r1Cisco

SYSTEM AND COMMUNICATIONS PROTECTION

CISC-RT-000040 - The Cisco switch must be configured to use encryption for routing protocol authentication - ripDISA STIG Cisco IOS XE Switch RTR v2r2Cisco
CISC-RT-000050 - The Cisco router must be configured to authenticate all routing protocol messages using NIST-validated FIPS 198-1 message authentication code algorithm.DISA STIG Cisco IOS Router RTR v2r4Cisco
CISC-RT-000050 - The Cisco switch must be configured to authenticate all routing protocol messages using NIST-validated FIPS 198-1 message authentication code algorithm.DISA STIG Cisco IOS Switch RTR v2r1Cisco
EP11-00-004900 - The EDB Postgres Advanced Server must use NIST FIPS 140-2 validated cryptographic modules for all cryptographic operations including generation of cryptographic hashes and data protection. - hostsslEDB PostgreSQL Advanced Server v11 Windows OS Audit v1r1Windows

CONFIGURATION MANAGEMENT

EP11-00-004900 - The EDB Postgres Advanced Server must use NIST FIPS 140-2 validated cryptographic modules for all cryptographic operations including generation of cryptographic hashes and data protection. - openssl_confEDB PostgreSQL Advanced Server v11 Windows OS Audit v1r1Windows

CONFIGURATION MANAGEMENT

EP11-00-013200 - The EDB Postgres Advanced Server must be configured on a platform that has a NIST certified FIPS 140-2 or 140-3 installation of OpenSSL - openssl_confEDB PostgreSQL Advanced Server v11 Windows OS Audit v2r2Windows
GEN000590 - The system must use a FIPS 140-2 approved cryptographic hashing algorithm for generating account password hashes.DISA STIG AIX 6.1 v1r14Unix

IDENTIFICATION AND AUTHENTICATION

JUNI-RT-000040 - The Juniper router must be configured to use encryption for routing protocol authentication - BGPDISA STIG Juniper Router RTR v2r3Juniper
JUNI-RT-000040 - The Juniper router must be configured to use encryption for routing protocol authentication - IS-ISDISA STIG Juniper Router RTR v2r3Juniper
MD3X-00-000380 - MongoDB must use NIST FIPS 140-2-validated cryptographic modules for cryptographic operations.DISA STIG MongoDB Enterprise Advanced 3.x v1r1Unix

SYSTEM AND COMMUNICATIONS PROTECTION

MD3X-00-000380 - MongoDB must use NIST FIPS 140-2-validated cryptographic modules for cryptographic operations.DISA STIG MongoDB Enterprise Advanced 3.x v1r2Unix

SYSTEM AND COMMUNICATIONS PROTECTION

O112-C2-015700 - The DBMS must use NIST-validated FIPS 140-2-compliant cryptography for authentication mechanisms.DISA STIG Oracle 11.2g v2r3 WindowsWindows
O365-CO-000015 - Consistent MIME handling must be enabled for all Office 365 ProPlus programs - mspub.exeDISA STIG Microsoft Office 365 ProPlus v2r10Windows
O365-CO-000015 - Consistent MIME handling must be enabled for all Office 365 ProPlus programs - pptview.exeDISA STIG Microsoft Office 365 ProPlus v2r10Windows
O365-CO-000015 - Consistent MIME handling must be enabled for all Office 365 ProPlus programs - visio.exeDISA STIG Microsoft Office 365 ProPlus v2r10Windows
O365-CO-000019 - The MIME Sniffing safety feature must be enabled in all Office programs - msaccess.exeDISA STIG Microsoft Office 365 ProPlus v2r10Windows
O365-CO-000019 - The MIME Sniffing safety feature must be enabled in all Office programs - pptview.exeDISA STIG Microsoft Office 365 ProPlus v2r10Windows
O365-CO-000019 - The MIME Sniffing safety feature must be enabled in all Office programs - visio.exeDISA STIG Microsoft Office 365 ProPlus v2r10Windows
O365-CO-000021 - Object Caching Protection must be enabled in all Office programs - pptview.exeDISA STIG Microsoft Office 365 ProPlus v2r10Windows
OH12-1X-000253 - OHS must have the LoadModule ossl_module directive enabled to meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when encrypting stored data.DISA STIG Oracle HTTP Server 12.1.3 v1r7Unix

ACCESS CONTROL

OH12-1X-000255 - OHS must have the SSLEngine, SSLProtocol, and SSLWallet directives enabled to meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when encrypting stored data - SSLWalletDISA STIG Oracle HTTP Server 12.1.3 v1r7Unix

SYSTEM AND COMMUNICATIONS PROTECTION

PGS9-00-012300 - PostgreSQL must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for cryptographic operations.DISA STIG PostgreSQL 9.x on RHEL OS v2r3Unix
PPS9-00-004900 - The EDB Postgres Advanced Server must use NIST FIPS 140-2 or 140-3 validated cryptographic modules for cryptographic operations - opensslEDB PostgreSQL Advanced Server OS Linux Audit v2r2Unix
RHEL-09-611050 - RHEL 9 password-auth must be configured to use a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 9 STIG v2r1Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611055 - RHEL 9 system-auth must be configured to use a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 9 STIG v2r1Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-611150 - RHEL 9 shadow password suite must be configured to use a sufficient number of hashing rounds.DISA Red Hat Enterprise Linux 9 STIG v2r1Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-09-671015 - RHEL 9 must employ FIPS 140-3 approved cryptographic hashing algorithms for all stored passwords.DISA Red Hat Enterprise Linux 9 STIG v2r1Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020180 - The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.DISA SLES 15 STIG v2r1Unix

IDENTIFICATION AND AUTHENTICATION

SLES-15-020190 - The SUSE operating system must employ FIPS 140-2-approved cryptographic hashing algorithms for all stored passwords.DISA SLES 15 STIG v2r1Unix

IDENTIFICATION AND AUTHENTICATION

SPLK-CL-000390 - Splunk Enterprise must be installed in FIPS mode to implement NIST FIPS-approved cryptography for all cryptographic functions.DISA STIG Splunk Enterprise 8.x for Linux v1r3 STIG REST APISplunk
SPLK-CL-000390 - Splunk Enterprise must be installed in FIPS mode to implement NIST FIPS-approved cryptography for all cryptographic functions.DISA STIG Splunk Enterprise 8.x for Linux v1r4 STIG REST APISplunk
SPLK-CL-000390 - Splunk Enterprise must be installed in FIPS mode to implement NIST FIPS-approved cryptography for all cryptographic functions.DISA STIG Splunk Enterprise 8.x for Linux v1r5 STIG REST APISplunk
SYMP-NM-000280 - Symantec ProxySG must be configured to use only FIPS 140-2 approved algorithms for authentication to a cryptographic module with any application or protocol.DISA Symantec ProxySG Benchmark NDM v1r1BlueCoat

ACCESS CONTROL

VCLD-67-000002 - VAMI must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r1Unix
VCLD-67-000002 - VAMI must be configured with FIPS 140-2 compliant ciphers for HTTPS connections.DISA STIG VMware vSphere 6.7 VAMI-lighttpd v1r2Unix
WN08-SO-000064 - The use of DES encryption suites must not be allowed for Kerberos encryption.DISA Windows 8/8.1 STIG v1r23Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WN10-SO-000190 - Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.DISA Windows 10 STIG v2r1Windows

IDENTIFICATION AND AUTHENTICATION

WN16-SO-000350 - Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.DISA Windows Server 2016 STIG v2r5Windows
WN19-SO-000290 - Windows Server 2019 Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.DISA Windows Server 2019 STIG v2r5Windows
WN19-SO-000290 - Windows Server 2019 Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.DISA Windows Server 2019 STIG v2r7Windows