CCI|CCI-001958

Title

Authenticate organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.27 Disable AutomountingUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.1.28 Disable USB Storage - /bin/trueUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.1.28 Disable USB Storage - blacklistUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
3.4.1 Ensure DCCP is disabled - blacklist dccpUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
3.4.1 Ensure DCCP is disabled - dccp /bin/trueUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AIX7-00-003090 - If automated file system mounting tool is not required on AIX, it must be disabled.UnixDISA STIG AIX 7.x v3r1
AOSX-14-002069 - The macOS system must authenticate peripherals before establishing a connection.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-002069 - The macOS system must authenticate peripherals before establishing a connection.UnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-11-002069 - The macOS system must authenticate peripherals before establishing a connection.UnixDISA STIG Apple macOS 11 v1r8
APPL-11-002069 - The macOS system must authenticate peripherals before establishing a connection.UnixDISA STIG Apple macOS 11 v1r5
APPL-14-005090 - The macOS system must authorize USB devices before allowing connection.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-15-005090 - The macOS system must authorize USB devices before allowing connection.UnixDISA Apple macOS 15 (Sequoia) STIG v1r1
Big Sur - Must authenticate peripherals before establishing a connectionUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Must authenticate peripherals before establishing a connectionUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Must authenticate peripherals before establishing a connectionUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Must authenticate peripherals before establishing a connectionUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Must authenticate peripherals before establishing a connectionUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Must authenticate peripherals before establishing a connectionUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Must authenticate peripherals before establishing a connectionUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Must authenticate peripherals before establishing a connectionUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Must authenticate peripherals before establishing a connectionUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Must authenticate peripherals before establishing a connectionUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Must authenticate peripherals before establishing a connectionUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Must authenticate peripherals before establishing a connectionUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
CISC-L2-000020 - The Cisco switch must uniquely identify and authenticate all network-connected endpoint devices before establishing any connection.CiscoDISA STIG Cisco IOS XE Switch L2S v3r1
CISC-L2-000020 - The Cisco switch must uniquely identify and authenticate all network-connected endpoint devices before establishing any connection.CiscoDISA STIG Cisco IOS Switch L2S v3r1
CISC-RT-000910 - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to authenticate all received MSDP packets.CiscoDISA STIG Cisco IOS XE Router RTR v3r2
CISC-RT-000910 - The Cisco Multicast Source Discovery Protocol (MSDP) router must be configured to authenticate all received MSDP packets.CiscoDISA STIG Cisco IOS Router RTR v3r2
CISC-RT-000910 - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to authenticate all received MSDP packets.CiscoDISA STIG Cisco NX-OS Switch RTR v3r2
CISC-RT-000910 - The Cisco Multicast Source Discovery Protocol (MSDP) switch must be configured to authenticate all received MSDP packets.CiscoDISA STIG Cisco IOS XE Switch RTR v3r1
DTOO225 - Outlook - Outlook Dial-up options to Warn user before allowing switch in dial-up access must be configured.WindowsDISA STIG Office 2010 Outlook v1r13
JUNI-RT-000900 - The Juniper Multicast Source Discovery Protocol (MSDP) router must be configured to authenticate all received MSDP packets.JuniperDISA STIG Juniper Router RTR v3r1
Monterey - Must authenticate peripherals before establishing a connectionUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Must authenticate peripherals before establishing a connectionUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Must authenticate peripherals before establishing a connectionUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Must authenticate peripherals before establishing a connectionUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Must authenticate peripherals before establishing a connectionUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Must authenticate peripherals before establishing a connectionUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
OL07-00-020100 - The Oracle Linux operating system must be configured to disable USB mass storage - blacklist.UnixDISA Oracle Linux 7 STIG v3r1
OL07-00-020101 - The Oracle Linux operating system must be configured so that the Datagram Congestion Control Protocol (DCCP) kernel module is disabled unless required - dccp /bin/true.UnixDISA Oracle Linux 7 STIG v3r1
OL07-00-020111 - The Oracle Linux operating system must disable the graphical user interface automounter unless required.UnixDISA Oracle Linux 7 STIG v3r1
OL08-00-040139 - OL 8 must have the USBGuard installed.UnixDISA Oracle Linux 8 STIG v2r2
RHEL-07-020100 - The Red Hat Enterprise Linux operating system must be configured to disable USB mass storage.UnixDISA Red Hat Enterprise Linux 7 STIG v3r15
RHEL-07-020101 - The Red Hat Enterprise Linux operating system must be configured so that the Datagram Congestion Control Protocol (DCCP) kernel module is disabled unless required.UnixDISA Red Hat Enterprise Linux 7 STIG v3r15
RHEL-07-020110 - The Red Hat Enterprise Linux operating system must disable the file system automounter unless required.UnixDISA Red Hat Enterprise Linux 7 STIG v3r15
RHEL-07-020111 - The Red Hat Enterprise Linux operating system must disable the graphical user interface automounter unless required.UnixDISA Red Hat Enterprise Linux 7 STIG v3r15
RHEL-08-040139 - RHEL 8 must have the USBGuard installed.UnixDISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-09-231040 - RHEL 9 file system automount function must be disabled unless required.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-271020 - RHEL 9 must disable the graphical user interface automount function unless required.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-271025 - RHEL 9 must prevent a user from overriding the disabling of the graphical user interface automount function.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2