CCI|CCI-004910

Title

Provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
ALMA-09-039070 - AlmaLinux OS 9, for PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r1
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS Router NDM v3r2
CISC-ND-000620 - The Cisco router must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS XE Router NDM v3r2
CISC-ND-000620 - The Cisco switch must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS XE Switch NDM v3r2
CISC-ND-000620 - The Cisco switch must only store cryptographic representations of passwords.CiscoDISA STIG Cisco IOS Switch NDM v3r2
SPLK-CL-000040 - Splunk Enterprise must only allow the use of DOD-approved certificate authorities for cryptographic functions.SplunkDISA STIG Splunk Enterprise 7.x for Windows v3r1 REST API
SPLK-CL-000450 - Splunk Enterprise must only allow the use of DOD-approved certificate authorities for cryptographic functions.SplunkDISA STIG Splunk Enterprise 8.x for Linux v2r1 STIG REST API
TCAT-AS-000710 - Keystore file must be protected.UnixDISA STIG Apache Tomcat Application Server 9 v3r1 Middleware
UBTU-24-600090 - Ubuntu 24.04 LTS handling data requiring "data at rest" protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest.UnixDISA Canonical Ubuntu 24.04 LTS STIG v1r1