Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-002421
CCI
CCI|CCI-002421
Title
Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
3.042 - Outgoing secure channel traffic is not signed when possible.
Windows
DISA Windows Vista STIG v6r41
3.043 - Outgoing secure channel traffic is not encrypted when possible.
Windows
DISA Windows Vista STIG v6r41
3.045 - The Windows SMB client is not enabled to perform SMB packet signing when possible.
Windows
DISA Windows Vista STIG v6r41
3.046 - The Windows SMB server is not enabled to perform SMB packet signing when possible.
Windows
DISA Windows Vista STIG v6r41
3.113 - Outgoing secure channel traffic is not encrypted or signed.
Windows
DISA Windows Vista STIG v6r41
3.114 - The Windows Server SMB client is not enabled to always perform SMB packet signing.
Windows
DISA Windows Vista STIG v6r41
3.115 - The Windows Server SMB server is not enabled to always perform SMB packet signing.
Windows
DISA Windows Vista STIG v6r41
4.044 - The system is not configured to require a strong session key.
Windows
DISA Windows Vista STIG v6r41
5.3.1 Ensure SSH is installed
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
5.3.2 Ensure SSH is running
Unix
CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
AOSX-13-000035 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission.
Unix
DISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - OpenSSH version
Unix
DISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - SSHD currently running
Unix
DISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000011 - The macOS system must implement DoD-approved encryption to protect the confidentiality and integrity of remote access sessions including transmitted data and data during preparation for transmission - SSHD service disabled
Unix
DISA STIG Apple Mac OSX 10.14 v2r6
APPL-11-000011 - The macOS system must disable the SSHD service.
Unix
DISA STIG Apple macOS 11 v1r8
APPL-11-000011 - The macOS system must disable the SSHD service.
Unix
DISA STIG Apple macOS 11 v1r5
APPL-14-000054 - The macOS system must limit SSHD to FIPS-compliant connections.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-000057 - The macOS system must limit SSH to FIPS-compliant connections.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-15-000054 - The macOS system must limit SSHD to FIPS-compliant connections.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-000057 - The macOS system must limit SSH to FIPS-compliant connections.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
Catalina - Enable SSH for Remote Access Sessions
Unix
NIST macOS Catalina v1.5.0 - All Profiles
DKER-EE-001050 - TCP socket binding for all Docker Engine - Enterprise nodes in a Universal Control Plane (UCP) cluster must be disabled.
Unix
DISA STIG Docker Enterprise 2.x Linux/Unix v2r2
EX13-CA-000155 - Exchange OWA must have S/MIME Certificates enabled.
Windows
DISA Microsoft Exchange 2013 Client Access Server STIG v2r2
JBOS-AS-000655 - JBoss must be configured to use an approved cryptographic algorithm in conjunction with TLS.
Unix
DISA RedHat JBoss EAP 6.3 STIG v2r4
O121-C1-019700 - The DBMS must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures.
Unix
DISA STIG Oracle 12c v3r1 Linux
O121-C1-019700 - The DBMS must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission unless the transmitted data is otherwise protected by alternative physical measures.
Windows
DISA STIG Oracle 12c v3r1 Windows
OL6-00-000293 - Wireless network adapters must be disabled.
Unix
DISA STIG Oracle Linux 6 v2r7
OL07-00-041010 - The Oracle Linux operating system must be configured so that all wireless network adapters are disabled.
Unix
DISA Oracle Linux 7 STIG v2r14
OL08-00-040159 - All OL 8 networked systems must have SSH installed.
Unix
DISA Oracle Linux 8 STIG v2r1
OL08-00-040160 - All OL 8 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
Unix
DISA Oracle Linux 8 STIG v2r1
PHTN-30-000064 - The Photon operating system must configure sshd to use FIPS 140-2 ciphers.
Unix
DISA STIG VMware vSphere 7.0 Photon OS v1r3
PHTN-67-000067 - The Photon operating system must configure sshd to use FIPS 140-2 ciphers.
Unix
DISA STIG VMware vSphere 6.7 Photon OS v1r6
RHEL-07-040300 - The Red Hat Enterprise Linux operating system must be configured so that all networked systems have SSH installed.
Unix
DISA Red Hat Enterprise Linux 7 STIG v3r15
RHEL-07-040310 - The Red Hat Enterprise Linux operating system must be configured so that all networked systems use SSH for confidentiality and integrity of transmitted and received information as well as information during preparation for transmission.
Unix
DISA Red Hat Enterprise Linux 7 STIG v3r15
RHEL-09-255010 - All RHEL 9 networked systems must have SSH installed.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-255015 - All RHEL 9 networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-255090 - RHEL 9 must force a frequent session key renegotiation for SSH connections to the server.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-291040 - RHEL 9 wireless network adapters must be disabled.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
SHPT-00-000805 - The organization must employ cryptographic mechanisms to prevent unauthorized disclosure of information during transmission unless otherwise protected by alternative physical measures.
Windows
DISA STIG SharePoint 2010 v1r9
SLES-12-030100 - All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
Unix
DISA SLES 12 STIG v2r13
SLES-15-010530 - All networked SUSE operating systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission.
Unix
DISA SLES 15 STIG v2r1
SOL-11.1-060080 - The operating system must employ cryptographic mechanisms to recognize changes to information during transmission unless otherwise protected by alternative physical measures.
Unix
DISA STIG Solaris 11 X86 v3r1
SOL-11.1-060080 - The operating system must employ cryptographic mechanisms to recognize changes to information during transmission unless otherwise protected by alternative physical measures.
Unix
DISA STIG Solaris 11 SPARC v3r1
SOL-11.1-060110 - The operating system must employ cryptographic mechanisms to prevent unauthorized disclosure of information during transmission unless otherwise protected by alternative physical measures.
Unix
DISA STIG Solaris 11 X86 v3r1
SOL-11.1-060110 - The operating system must employ cryptographic mechanisms to prevent unauthorized disclosure of information during transmission unless otherwise protected by alternative physical measures.
Unix
DISA STIG Solaris 11 SPARC v3r1
SP13-00-000135 - SharePoint must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission, unless the transmitted data is otherwise protected by alternative physical measures.
Windows
DISA STIG SharePoint 2013 v2r3
SQL2-00-022600 - SQL Server must employ cryptographic mechanisms preventing the unauthorized disclosure of information during transmission.
MS_SQLDB
DISA STIG SQL Server 2012 DB Instance Security v1r20
TCAT-AS-000750 - Tomcat must use FIPS-validated ciphers on secured connectors.
Unix
DISA STIG Apache Tomcat Application Server 9 v3r1 Middleware
UBTU-16-030420 - All networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission - installed
Unix
DISA STIG Ubuntu 16.04 LTS v2r3
UBTU-16-030420 - All networked systems must have and implement SSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission - running
Unix
DISA STIG Ubuntu 16.04 LTS v2r3