Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-001312
CCI
CCI|CCI-001312
Title
Generates error messages that provide information necessary for corrective actions without revealing information that could be exploited.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
APPL-14-002021 - The macOS system must disable sending diagnostic and usage data to Apple.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004001 - The macOS system must configure Apple System Log files to be owned by root and group to wheel.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004002 - The macOS system must configure Apple System Log files to mode 640 or less permissive.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004030 - The macOS system must configure system log files to be owned by root and group to wheel.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004040 - The macOS system must configure system log files to mode 640 or less permissive.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-15-002021 - The macOS system must disable sending diagnostic and usage data to Apple.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-004001 - The macOS system must configure Apple System Log (ASL) files owned by root and group to wheel.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-004002 - The macOS system must configure Apple System Log (ASL) files to mode 640 or less permissive.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-004030 - The macOS system must configure system log files owned by root and group to wheel.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-004040 - The macOS system must configure system log files to mode 640 or less permissive.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
AS24-U1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r1
AS24-U1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r1 Middleware
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - LogLevel
Unix
DISA STIG Apache Server 2.4 Unix Server v3r1 Middleware
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled - TraceEnable
Unix
DISA STIG Apache Server 2.4 Unix Server v3r1 Middleware
AS24-U1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Unix
DISA STIG Apache Server 2.4 Unix Server v3r1
AS24-U2-000620 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r4
AS24-U2-000620 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r4 Middleware
AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r4
AS24-U2-000630 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r4 Middleware
AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r4
AS24-U2-000640 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Unix
DISA STIG Apache Server 2.4 Unix Site v2r4 Middleware
AS24-W1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Windows
DISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Windows
DISA STIG Apache Server 2.4 Windows Server v3r1
AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Windows
DISA STIG Apache Server 2.4 Windows Server v2r3
AS24-W1-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Windows
DISA STIG Apache Server 2.4 Windows Server v3r1
AS24-W2-000610 - The Apache web server must display a default hosted application web page, not a directory listing, when a requested web page cannot be found.
Windows
DISA STIG Apache Server 2.4 Windows Site v2r1
AS24-W2-000620 - Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths.
Windows
DISA STIG Apache Server 2.4 Windows Site v2r1
AS24-W2-000630 - Debugging and trace information used to diagnose the Apache web server must be disabled.
Windows
DISA STIG Apache Server 2.4 Windows Site v2r1
Big Sur - Generate Error Messages without Exploitable Information
Unix
NIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Generate Error Messages without Exploitable Information
Unix
NIST macOS Catalina v1.5.0 - All Profiles
CD12-00-000600 - PostgreSQL must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
PostgreSQLDB
DISA STIG Crunchy Data PostgreSQL DB v3r1
DB2X-00-006200 - DB2 must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
IBM_DB2DB
DISA STIG IBM DB2 v10.5 LUW v2r1 Database
DTBC-0068 - Chrome development tools must be disabled.
Windows
DISA STIG Google Chrome v2r9
DTBI1135-IE11 - Internet Explorer Development Tools Must Be Disabled.
Windows
DISA STIG IE 11 v2r5
EP11-00-006500 - The EDB Postgres Advanced Server must provide non-privileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
PostgreSQLDB
EDB PostgreSQL Advanced Server v11 DB Audit v2r4
EPAS-00-006500 - The EDB Postgres Advanced Server must provide nonprivileged users with error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.
PostgreSQLDB
EnterpriseDB PostgreSQL Advanced Server DB v2r1
FFOX-00-000015 - Firefox development tools must be disabled.
Unix
DISA STIG Mozilla Firefox Linux v6r5
FFOX-00-000015 - Firefox development tools must be disabled.
Unix
DISA STIG Mozilla Firefox MacOS v6r5
FFOX-00-000015 - Firefox development tools must be disabled.
Windows
DISA STIG Mozilla Firefox Windows v6r5
IIST-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 website, patches, loaded modules, and directory paths.
Windows
DISA IIS 10.0 Site v2r9
IIST-SI-000234 - Debugging and trace information used to diagnose the IIS 10.0 website must be disabled.
Windows
DISA IIS 10.0 Site v2r9
IIST-SV-000139 - The IIS 10.0 web server Indexing must only index web content.
Windows
DISA IIS 10.0 Server v2r10
IIST-SV-000139 - The IIS 10.0 web server Indexing must only index web content.
Windows
DISA IIS 10.0 Server v3r1
IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
Windows
DISA IIS 10.0 Server v3r1
IIST-SV-000140 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 10.0 web server, patches, loaded modules, and directory paths.
Windows
DISA IIS 10.0 Server v2r10
IIST-SV-000210 - HTTPAPI Server version must be removed from the HTTP Response Header information.
Windows
DISA IIS 10.0 Server v3r1
IIST-SV-000210 - HTTPAPI Server version must be removed from the HTTP Response Header information.
Windows
DISA IIS 10.0 Server v2r10
IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.
Windows
DISA IIS 10.0 Server v2r10
IIST-SV-000215 - ASP.NET version must be removed from the HTTP Response Header information.
Windows
DISA IIS 10.0 Server v3r1
IISW-SI-000233 - Warning and error messages displayed to clients must be modified to minimize the identity of the IIS 8.5 website, patches, loaded modules, and directory paths.
Windows
DISA IIS 8.5 Site v2r9