CM-7 Least Functionality
Configuration Management family. 40 Control Correlation Identifiers map to this control, and 234 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to CM-7 |
|---|---|---|
| Red Hat Enterprise Linux 9 | V2 | 50 |
| Microsoft Windows 10 | V3 | 40 |
| Microsoft Windows 11 | V2 | 38 |
| Red Hat Enterprise Linux 8 | V2 | 34 |
| Microsoft Windows Server 2019 | V3 | 26 |
| Microsoft Windows Server 2022 | V2 | 26 |
| Google Chrome Current Windows | V2 | 14 |
| Kubernetes | V2 | 6 |
Control Correlation Identifiers mapped to CM-7
| CCI | Definition | Rev |
|---|---|---|
| CCI-000380 | Defines prohibited or restricted functions, system ports, protocols, software and/or services for the system. | 5, 4 |
| CCI-000381 | Configure the system to provide only organization-defined mission essential capabilities. | 5, 4 |
| CCI-000382 | Configure the system to prohibit or restrict the use of organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services. | 5, 4 |
| CCI-000384 | Review the system per organization-defined frequency to identify unnecessary and nonsecure functions, ports, protocols, software, and services. | 5, 4 |
| CCI-000387 | Defines registration requirements for functions, ports, protocols, and services. | 5, 4 |
| CCI-000388 | Ensure compliance with organization-defined registration requirements for functions, ports, protocols, and services. | 5, 4 |
| CCI-001592 | Defines the rules authorizing the terms and conditions of software program usage on the system. | 5, 4 |
| CCI-001760 | Defines the frequency of system reviews to identify unnecessary and/or nonsecure functions, ports, protocols, software, and services. | 5, 4 |
| CCI-001761 | Defines the functions, ports, protocols, software, and services within the information system that are to be disabled or removed when deemed unnecessary and/or nonsecure. | 5, 4 |
| CCI-001762 | Disable or remove organization-defined functions, ports, protocols, software, and services within the system deemed to be unnecessary and/or nonsecure. | 5, 4 |
| CCI-001763 | Defines the policies regarding software program usage and restrictions. | 5, 4 |
| CCI-001764 | Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage. | 5, 4 |
| CCI-001765 | Defines the software programs not authorized to execute on the system. | 5, 4 |
| CCI-001766 | Identify the organization-defined software programs not authorized to execute on the system. | 5, 4 |
| CCI-001767 | Employ an allow-all, deny-by-exception policy to prohibit the execution of unauthorized software programs on the system. | 5, 4 |
| CCI-001768 | Defines the frequency on which the list of unauthorized software programs will be reviewed and updated. | 5, 4 |
| CCI-001769 | The organization defines the frequency on which it will update the list of unauthorized software programs. | 4 |
| CCI-001770 | Review and update the list of unauthorized software programs per organization-defined frequency. | 5, 4 |
| CCI-001771 | The organization updates the list of unauthorized software programs per organization-defined frequency. | 4 |
| CCI-001772 | Defines the software programs authorized to execute on the system. | 5, 4 |
| CCI-001773 | Identify the organization-defined software programs authorized to execute on the system. | 5, 4 |
| CCI-001774 | Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system. | 5, 4 |
| CCI-001775 | Defines the frequency on which the list of authorized software programs will be reviewed and updated. | 5, 4 |
| CCI-001776 | The organization defines the frequency on which it will update the list of authorized software programs. | 4 |
| CCI-001777 | Review and update the list of authorized software programs per organization-defined frequency. | 5, 4 |
| CCI-001778 | The organization updates the list of authorized software programs per organization-defined frequency. | 4 |
| CCI-003948 | Defines the mission essential capabilities for configuring the system. | 5 |
| CCI-003949 | Require that organization-defined user-installed software in a confined physical or virtual machine environment with limited privileges. | 5 |
| CCI-003950 | Defines the user-installed software required for executing in a confined physical or virtual machine environment with limited privileges. | 5 |
| CCI-003951 | Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of organization-defined personnel or roles when such code is obtained from sources with limited or no warranty. | 5 |
| CCI-003952 | Defines the personnel or roles who allow execution of binary or machine-executable code only in confined physical or virtual machine environments when such code is obtained from sources with limited or no warranty. | 5 |
| CCI-003953 | Allow execution of binary or machine-executable code only in confined physical or virtual machine environments and with the explicit approval of organization-defined personnel or roles when such code is without the provision of source code. | 5 |
| CCI-003954 | Defines the personnel or roles who allow execution of binary or machine-executable code only in confined physical or virtual machine environments when such code is without the provision of source code. | 5 |
| CCI-003955 | Prohibit the use of binary or machine-executable code from sources with limited or no warranty or without the provision of source code. | 5 |
| CCI-003956 | Allow exceptions only for compelling mission or operational requirements and with the approval of the authorizing official. | 5 |
| CCI-003957 | Identify organization-defined hardware components authorized for system use. | 5 |
| CCI-003958 | Defines the hardware components to be identified for authorized system use. | 5 |
| CCI-003959 | Prohibit the use or connection of unauthorized hardware components. | 5 |
| CCI-003960 | Review and update the list of authorized hardware components on an organization-defined frequency. | 5 |
| CCI-003961 | Defines the frequency the hardware components are reviewed and updated. | 5 |
STIG rules that implement CM-7
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205677 | WN19-00-000270 | medium | Windows Server 2019 must have the roles and features required by the system documented. |
| V-205678 | WN19-00-000320 | medium | Windows Server 2019 must not have the Fax Server role installed. |
| V-205679 | WN19-00-000340 | medium | Windows Server 2019 must not have the Peer Name Resolution Protocol installed. |
| V-205680 | WN19-00-000350 | medium | Windows Server 2019 must not have Simple TCP/IP Services installed. |
| V-205681 | WN19-00-000370 | medium | Windows Server 2019 must not have the TFTP Client installed. |
| V-205682 | WN19-00-000380 | medium | Windows Server 2019 must not have the Server Message Block (SMB) v1 protocol installed. |
| V-205683 | WN19-00-000390 | medium | Windows Server 2019 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server. |
| V-205684 | WN19-00-000400 | medium | Windows Server 2019 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client. |
| V-205685 | WN19-00-000410 | medium | Windows Server 2019 must not have Windows PowerShell 2.0 installed. |
| V-205686 | WN19-CC-000010 | medium | Windows Server 2019 must prevent the display of slide shows on the lock screen. |
| V-205687 | WN19-CC-000020 | medium | Windows Server 2019 must have WDigest Authentication disabled. |
| V-205688 | WN19-CC-000150 | medium | Windows Server 2019 downloading print driver packages over HTTP must be turned off. |
| V-205689 | WN19-CC-000160 | medium | Windows Server 2019 printing over HTTP must be turned off. |
| V-205690 | WN19-CC-000170 | medium | Windows Server 2019 network selection user interface (UI) must not be displayed on the logon screen. |
| V-205691 | WN19-CC-000200 | low | Windows Server 2019 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft. |
| V-205692 | WN19-CC-000300 | medium | Windows Server 2019 Windows Defender SmartScreen must be enabled. |
| V-205693 | WN19-CC-000400 | medium | Windows Server 2019 must disable Basic authentication for RSS feeds over HTTP. |
| V-205694 | WN19-CC-000410 | medium | Windows Server 2019 must prevent Indexing of encrypted files. |
| V-205695 | WN19-DC-000130 | medium | Windows Server 2019 domain controllers must run on a machine dedicated to that function. |
| V-205696 | WN19-MS-000030 | medium | Windows Server 2019 local users on domain-joined member servers must not be enumerated. |
| V-205697 | WN19-00-000330 | medium | Windows Server 2019 must not have the Microsoft FTP service installed unless required by the organization. |
| V-205698 | WN19-00-000360 | medium | Windows Server 2019 must not have the Telnet Client installed. |
| V-205804 | WN19-CC-000210 | high | Windows Server 2019 Autoplay must be turned off for non-volume devices. |
| V-205805 | WN19-CC-000220 | high | Windows Server 2019 default AutoRun behavior must be configured to prevent AutoRun commands. |
| V-205806 | WN19-CC-000230 | high | Windows Server 2019 AutoPlay must be disabled for all drives. |
| V-205807 | WN19-00-000080 | medium | Windows Server 2019 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| V-220705 | WN10-00-000035 | medium | The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| V-220714 | WN10-00-000080 | medium | Only authorized user accounts must be allowed to create or run virtual machines on Windows 10 systems. |
| V-220718 | WN10-00-000100 | high | Internet Information System (IIS) or its subcomponents must not be installed on a workstation. |
| V-220719 | WN10-00-000105 | medium | Simple Network Management Protocol (SNMP) must not be installed on the system. |
| V-220720 | WN10-00-000110 | medium | Simple TCP/IP Services must not be installed on the system. |
| V-220721 | WN10-00-000115 | medium | The Telnet Client must not be installed on the system. |
| V-220722 | WN10-00-000120 | medium | The TFTP Client must not be installed on the system. |
| V-220728 | WN10-00-000155 | medium | The Windows PowerShell 2.0 feature must be disabled on the system. |
| V-220729 | WN10-00-000160 | medium | The Server Message Block (SMB) v1 protocol must be disabled on the system. |
| V-220730 | WN10-00-000165 | medium | The Server Message Block (SMB) v1 protocol must be disabled on the SMB server. |
| V-220731 | WN10-00-000170 | medium | The Server Message Block (SMB) v1 protocol must be disabled on the SMB client. |
| V-220732 | WN10-00-000175 | medium | The Secondary Logon service must be disabled on Windows 10. |
| V-220734 | WN10-00-000210 | medium | Bluetooth must be turned off unless approved by the organization. |
| V-220735 | WN10-00-000220 | medium | Bluetooth must be turned off when not in use. |
| V-220792 | WN10-CC-000005 | medium | Camera access from the lock screen must be disabled. |
| V-220793 | WN10-CC-000007 | medium | Windows 10 must cover or disable the built-in or attached camera when not in use. |
| V-220794 | WN10-CC-000010 | medium | The display of slide shows on the lock screen must be disabled. |
| V-220800 | WN10-CC-000038 | medium | WDigest Authentication must be disabled. |
| V-220801 | WN10-CC-000039 | medium | Run as different user must be removed from context menus. |
| V-220803 | WN10-CC-000044 | medium | Internet connection sharing must be disabled. |
| V-220815 | WN10-CC-000100 | medium | Downloading print driver packages over HTTP must be prevented. |
| V-220816 | WN10-CC-000105 | medium | Web publishing and online ordering wizards must be prevented from downloading a list of providers. |
| V-220817 | WN10-CC-000110 | medium | Printing over HTTP must be prevented. |
| V-220819 | WN10-CC-000120 | medium | The network selection user interface (UI) must not be displayed on the logon screen. |
| V-220820 | WN10-CC-000130 | medium | Local users on domain-joined computers must not be enumerated. |
| V-220826 | WN10-CC-000175 | low | The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft. |
| V-220827 | WN10-CC-000180 | high | Autoplay must be turned off for non-volume devices. |
| V-220828 | WN10-CC-000185 | high | The default autorun behavior must be configured to prevent autorun commands. |
| V-220829 | WN10-CC-000190 | high | Autoplay must be disabled for all drives. |
| V-220831 | WN10-CC-000197 | low | Microsoft consumer experiences must be turned off. |
| V-220836 | WN10-CC-000210 | medium | The Windows Defender SmartScreen for Explorer must be enabled. |
| V-220845 | WN10-CC-000252 | medium | Windows 10 must be configured to disable Windows Game Recording and Broadcasting. |
| V-220854 | WN10-CC-000300 | medium | Basic authentication for RSS feeds over HTTP must not be used. |
| V-220855 | WN10-CC-000305 | medium | Indexing of encrypted files must be turned off. |
| V-220870 | WN10-CC-000370 | medium | The convenience PIN for Windows 10 must be disabled. |
| V-220871 | WN10-CC-000385 | medium | Windows Ink Workspace must be configured to disallow access above the lock. |
| V-220872 | WN10-CC-000390 | low | Windows 10 should be configured to prevent users from receiving suggestions for third-party or additional applications. |
| V-220954 | WN10-UC-000015 | low | Toast notifications to the lock screen must be turned off. |
| V-221561 | DTBC-0004 | medium | Sites ability to show pop-ups must be disabled. |
| V-221564 | DTBC-0007 | medium | The default search providers name must be set. |
| V-221565 | DTBC-0008 | medium | The default search provider URL must be set to perform encrypted searches. |
| V-221566 | DTBC-0009 | medium | Default search provider must be enabled. |
| V-221567 | DTBC-0011 | medium | The Password Manager must be disabled. |
| V-221572 | DTBC-0021 | medium | The URL protocol schema javascript must be disabled. |
| V-221575 | DTBC-0026 | medium | Metrics reporting to Google must be disabled. |
| V-221576 | DTBC-0027 | medium | Search suggestions must be disabled. |
| V-221577 | DTBC-0029 | medium | Importing of saved passwords must be disabled. |
| V-221591 | DTBC-0058 | medium | WebUSB must be disabled. |
| V-221594 | DTBC-0063 | medium | Google Cast must be disabled. |
| V-221595 | DTBC-0064 | medium | Autoplay must be disabled. |
| V-230485 | RHEL-08-030741 | low | RHEL 8 must disable the chrony daemon from acting as a server. |
| V-230486 | RHEL-08-030742 | low | RHEL 8 must disable network management of the chrony daemon. |
| V-230487 | RHEL-08-040000 | high | RHEL 8 must not have the telnet-server package installed. |
| V-230488 | RHEL-08-040001 | medium | RHEL 8 must not have any automated bug reporting tools installed. |
| V-230489 | RHEL-08-040002 | medium | RHEL 8 must not have the sendmail package installed. |
| V-230491 | RHEL-08-040004 | low | RHEL 8 must enable mitigations against processor-based vulnerabilities. |
| V-230492 | RHEL-08-040010 | high | RHEL 8 must not have the rsh-server package installed. |
| V-230493 | RHEL-08-040020 | medium | RHEL 8 must cover or disable the built-in or attached camera when not in use. |
| V-230494 | RHEL-08-040021 | low | RHEL 8 must disable the asynchronous transfer mode (ATM) protocol. |
| V-230495 | RHEL-08-040022 | low | RHEL 8 must disable the controller area network (CAN) protocol. |
| V-230496 | RHEL-08-040023 | low | RHEL 8 must disable the stream control transmission protocol (SCTP). |
| V-230497 | RHEL-08-040024 | low | RHEL 8 must disable the transparent inter-process communication (TIPC) protocol. |
| V-230498 | RHEL-08-040025 | low | RHEL 8 must disable mounting of cramfs. |
| V-230499 | RHEL-08-040026 | low | RHEL 8 must disable IEEE 1394 (FireWire) Support. |
| V-230500 | RHEL-08-040030 | medium | RHEL 8 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. |
| V-230508 | RHEL-08-040120 | medium | RHEL 8 must mount /dev/shm with the nodev option. |
| V-230509 | RHEL-08-040121 | medium | RHEL 8 must mount /dev/shm with the nosuid option. |
| V-230510 | RHEL-08-040122 | medium | RHEL 8 must mount /dev/shm with the noexec option. |
| V-230511 | RHEL-08-040123 | medium | RHEL 8 must mount /tmp with the nodev option. |
| V-230512 | RHEL-08-040124 | medium | RHEL 8 must mount /tmp with the nosuid option. |
| V-230513 | RHEL-08-040125 | medium | RHEL 8 must mount /tmp with the noexec option. |
| V-230514 | RHEL-08-040126 | medium | RHEL 8 must mount /var/log with the nodev option. |
| V-230515 | RHEL-08-040127 | medium | RHEL 8 must mount /var/log with the nosuid option. |
| V-230516 | RHEL-08-040128 | medium | RHEL 8 must mount /var/log with the noexec option. |
| V-230517 | RHEL-08-040129 | medium | RHEL 8 must mount /var/log/audit with the nodev option. |
| V-230518 | RHEL-08-040130 | medium | RHEL 8 must mount /var/log/audit with the nosuid option. |
| V-230519 | RHEL-08-040131 | medium | RHEL 8 must mount /var/log/audit with the noexec option. |
| V-230520 | RHEL-08-040132 | medium | RHEL 8 must mount /var/tmp with the nodev option. |
| V-230521 | RHEL-08-040133 | medium | RHEL 8 must mount /var/tmp with the nosuid option. |
| V-230522 | RHEL-08-040134 | medium | RHEL 8 must mount /var/tmp with the noexec option. |
| V-230523 | RHEL-08-040135 | medium | The RHEL 8 fapolicy module must be installed. |
| V-230559 | RHEL-08-040370 | medium | The gssproxy package must not be installed unless mission essential on RHEL 8. |
| V-241787 | DTBC-0073 | medium | Web Bluetooth API must be disabled. |
| V-242409 | CNTR-K8-000910 | medium | Kubernetes Controller Manager must disable profiling. |
| V-242410 | CNTR-K8-000920 | medium | The Kubernetes API Server must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). |
| V-242411 | CNTR-K8-000930 | medium | The Kubernetes Scheduler must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). |
| V-242412 | CNTR-K8-000940 | medium | The Kubernetes Controllers must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). |
| V-242413 | CNTR-K8-000950 | medium | The Kubernetes etcd must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). |
| V-242414 | CNTR-K8-000960 | medium | The Kubernetes cluster must use non-privileged host ports for user pods. |
| V-244545 | RHEL-08-040136 | medium | The RHEL 8 fapolicy module must be enabled. |
| V-244546 | RHEL-08-040137 | medium | The RHEL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| V-245538 | DTBC-0074 | medium | Use of the QUIC protocol must be disabled. |
| V-253262 | WN11-00-000035 | medium | The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| V-253275 | WN11-00-000100 | high | Internet Information System (IIS) or its subcomponents must not be installed on a workstation. |
| V-253276 | WN11-00-000105 | medium | Simple Network Management Protocol (SNMP) must not be installed on the system. |
| V-253277 | WN11-00-000110 | medium | Simple TCP/IP Services must not be installed on the system. |
| V-253278 | WN11-00-000115 | medium | The Telnet Client must not be installed on the system. |
| V-253279 | WN11-00-000120 | medium | The TFTP Client must not be installed on the system. |
| V-253285 | WN11-00-000155 | medium | The Windows PowerShell 2.0 feature must be disabled on the system. |
| V-253286 | WN11-00-000160 | medium | The Server Message Block (SMB) v1 protocol must be disabled on the system. |
| V-253287 | WN11-00-000165 | medium | The Server Message Block (SMB) v1 protocol must be disabled on the SMB server. |
| V-253288 | WN11-00-000170 | medium | The Server Message Block (SMB) v1 protocol must be disabled on the SMB client. |
| V-253289 | WN11-00-000175 | medium | The Secondary Logon service must be disabled on Windows 11. |
| V-253291 | WN11-00-000210 | medium | Bluetooth must be turned off unless approved by the organization. |
| V-253292 | WN11-00-000220 | medium | Bluetooth must be turned off when not in use. |
| V-253350 | WN11-CC-000005 | medium | Camera access from the lock screen must be disabled. |
| V-253351 | WN11-CC-000007 | medium | Windows 11 must cover or disable the built-in or attached camera when not in use. |
| V-253352 | WN11-CC-000010 | medium | The display of slide shows on the lock screen must be disabled. |
| V-253358 | WN11-CC-000038 | medium | WDigest Authentication must be disabled. |
| V-253359 | WN11-CC-000039 | medium | Run as different user must be removed from context menus. |
| V-253361 | WN11-CC-000044 | medium | Internet connection sharing must be disabled. |
| V-253374 | WN11-CC-000100 | medium | Downloading print driver packages over HTTP must be prevented. |
| V-253375 | WN11-CC-000105 | medium | Web publishing and online ordering wizards must be prevented from downloading a list of providers. |
| V-253376 | WN11-CC-000110 | medium | Printing over HTTP must be prevented. |
| V-253378 | WN11-CC-000120 | medium | The network selection user interface (UI) must not be displayed on the logon screen. |
| V-253379 | WN11-CC-000130 | medium | Local users on domain-joined computers must not be enumerated. |
| V-253385 | WN11-CC-000175 | low | The Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft. |
| V-253386 | WN11-CC-000180 | high | Autoplay must be turned off for non-volume devices. |
| V-253387 | WN11-CC-000185 | high | The default autorun behavior must be configured to prevent autorun commands. |
| V-253388 | WN11-CC-000190 | high | Autoplay must be disabled for all drives. |
| V-253390 | WN11-CC-000197 | low | Microsoft consumer experiences must be turned off. |
| V-253395 | WN11-CC-000210 | medium | The Microsoft Defender SmartScreen for Explorer must be enabled. |
| V-253399 | WN11-CC-000252 | medium | Windows 11 must be configured to disable Windows Game Recording and Broadcasting. |
| V-253408 | WN11-CC-000300 | medium | Basic authentication for RSS feeds over HTTP must not be used. |
| V-253409 | WN11-CC-000305 | medium | Indexing of encrypted files must be turned off. |
| V-253423 | WN11-CC-000370 | medium | The convenience PIN for Windows 11 must be disabled. |
| V-253425 | WN11-CC-000390 | low | Windows 11 must be configured to prevent users from receiving suggestions for third-party or additional applications. |
| V-253477 | WN11-UC-000015 | low | Toast notifications to the lock screen must be turned off. |
| V-254245 | WN22-00-000080 | medium | Windows Server 2022 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| V-254264 | WN22-00-000270 | medium | Windows Server 2022 must have the roles and features required by the system documented. |
| V-254269 | WN22-00-000320 | medium | Windows Server 2022 must not have the Fax Server role installed. |
| V-254270 | WN22-00-000330 | medium | Windows Server 2022 must not have the Microsoft FTP service installed unless required by the organization. |
| V-254271 | WN22-00-000340 | medium | Windows Server 2022 must not have the Peer Name Resolution Protocol installed. |
| V-254272 | WN22-00-000350 | medium | Windows Server 2022 must not have Simple TCP/IP Services installed. |
| V-254273 | WN22-00-000360 | medium | Windows Server 2022 must not have the Telnet Client installed. |
| V-254274 | WN22-00-000370 | medium | Windows Server 2022 must not have the TFTP Client installed. |
| V-254275 | WN22-00-000380 | medium | Windows Server 2022 must not the Server Message Block (SMB) v1 protocol installed. |
| V-254276 | WN22-00-000390 | medium | Windows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server. |
| V-254277 | WN22-00-000400 | medium | Windows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client. |
| V-254278 | WN22-00-000410 | medium | Windows Server 2022 must not have Windows PowerShell 2.0 installed. |
| V-254333 | WN22-CC-000010 | medium | Windows Server 2022 must prevent the display of slide shows on the lock screen. |
| V-254334 | WN22-CC-000020 | medium | Windows Server 2022 must have WDigest Authentication disabled. |
| V-254346 | WN22-CC-000150 | medium | Windows Server 2022 downloading print driver packages over HTTP must be turned off. |
| V-254347 | WN22-CC-000160 | medium | Windows Server 2022 printing over HTTP must be turned off. |
| V-254348 | WN22-CC-000170 | medium | Windows Server 2022 network selection user interface (UI) must not be displayed on the logon screen. |
| V-254351 | WN22-CC-000200 | low | Windows Server 2022 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft. |
| V-254352 | WN22-CC-000210 | high | Windows Server 2022 Autoplay must be turned off for nonvolume devices. |
| V-254353 | WN22-CC-000220 | high | Windows Server 2022 default AutoRun behavior must be configured to prevent AutoRun commands. |
| V-254354 | WN22-CC-000230 | high | Windows Server 2022 AutoPlay must be disabled for all drives. |
| V-254361 | WN22-CC-000300 | medium | Windows Server 2022 Microsoft Defender antivirus SmartScreen must be enabled. |
| V-254371 | WN22-CC-000400 | medium | Windows Server 2022 must disable Basic authentication for RSS feeds over HTTP. |
| V-254372 | WN22-CC-000410 | medium | Windows Server 2022 must prevent Indexing of encrypted files. |
| V-254397 | WN22-DC-000130 | medium | Windows Server 2022 domain controllers must run on a machine dedicated to that function. |
| V-254430 | WN22-MS-000030 | medium | Windows Server 2022 local users on domain-joined member servers must not be enumerated. |
| V-257592 | WN11-00-000395 | medium | Windows 11 must not have portproxy enabled or in use. |
| V-257593 | WN10-00-000395 | medium | Windows 10 must not have portproxy enabled or in use. |
| V-257795 | RHEL-09-212050 | low | RHEL 9 must enable mitigations against processor-based vulnerabilities. |
| V-257804 | RHEL-09-213045 | medium | RHEL 9 must be configured to disable the Asynchronous Transfer Mode kernel module. |
| V-257805 | RHEL-09-213050 | medium | RHEL 9 must be configured to disable the Controller Area Network kernel module. |
| V-257806 | RHEL-09-213055 | medium | RHEL 9 must be configured to disable the FireWire kernel module. |
| V-257807 | RHEL-09-213060 | medium | RHEL 9 must disable the Stream Control Transmission Protocol (SCTP) kernel module. |
| V-257808 | RHEL-09-213065 | medium | RHEL 9 must disable the Transparent Inter Process Communication (TIPC) kernel module. |
| V-257826 | RHEL-09-215015 | high | RHEL 9 must not have a File Transfer Protocol (FTP) server package installed. |
| V-257827 | RHEL-09-215020 | medium | RHEL 9 must not have the sendmail package installed. |
| V-257828 | RHEL-09-215025 | medium | RHEL 9 must not have the nfs-utils package installed. |
| V-257829 | RHEL-09-215030 | medium | RHEL 9 must not have the ypserv package installed. |
| V-257830 | RHEL-09-215035 | medium | RHEL 9 must not have the rsh-server package installed. |
| V-257831 | RHEL-09-215040 | medium | RHEL 9 must not have the telnet-server package installed. |
| V-257832 | RHEL-09-215045 | medium | RHEL 9 must not have the gssproxy package installed. |
| V-257833 | RHEL-09-215050 | medium | RHEL 9 must not have the iprutils package installed. |
| V-257834 | RHEL-09-215055 | medium | RHEL 9 must not have the tuned package installed. |
| V-257850 | RHEL-09-231045 | medium | RHEL 9 must prevent device files from being interpreted on file systems that contain user home directories. |
| V-257851 | RHEL-09-231050 | medium | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that contain user home directories. |
| V-257860 | RHEL-09-231095 | medium | RHEL 9 must mount /boot with the nodev option. |
| V-257861 | RHEL-09-231100 | medium | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot directory. |
| V-257862 | RHEL-09-231105 | medium | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory. |
| V-257863 | RHEL-09-231110 | medium | RHEL 9 must mount /dev/shm with the nodev option. |
| V-257864 | RHEL-09-231115 | medium | RHEL 9 must mount /dev/shm with the noexec option. |
| V-257865 | RHEL-09-231120 | medium | RHEL 9 must mount /dev/shm with the nosuid option. |
| V-257866 | RHEL-09-231125 | medium | RHEL 9 must mount /tmp with the nodev option. |
| V-257867 | RHEL-09-231130 | medium | RHEL 9 must mount /tmp with the noexec option. |
| V-257868 | RHEL-09-231135 | medium | RHEL 9 must mount /tmp with the nosuid option. |
| V-257869 | RHEL-09-231140 | medium | RHEL 9 must mount /var with the nodev option. |
| V-257870 | RHEL-09-231145 | medium | RHEL 9 must mount /var/log with the nodev option. |
| V-257871 | RHEL-09-231150 | medium | RHEL 9 must mount /var/log with the noexec option. |
| V-257872 | RHEL-09-231155 | medium | RHEL 9 must mount /var/log with the nosuid option. |
| V-257873 | RHEL-09-231160 | medium | RHEL 9 must mount /var/log/audit with the nodev option. |
| V-257874 | RHEL-09-231165 | medium | RHEL 9 must mount /var/log/audit with the noexec option. |
| V-257875 | RHEL-09-231170 | medium | RHEL 9 must mount /var/log/audit with the nosuid option. |
| V-257876 | RHEL-09-231175 | medium | RHEL 9 must mount /var/tmp with the nodev option. |
| V-257877 | RHEL-09-231180 | medium | RHEL 9 must mount /var/tmp with the noexec option. |
| V-257878 | RHEL-09-231185 | medium | RHEL 9 must mount /var/tmp with the nosuid option. |
| V-257880 | RHEL-09-231195 | low | RHEL 9 must disable mounting of cramfs. |
| V-257935 | RHEL-09-251010 | medium | RHEL 9 must have the firewalld package installed. |
| V-257936 | RHEL-09-251015 | medium | The firewalld service on RHEL 9 must be active. |
| V-257940 | RHEL-09-251035 | medium | RHEL 9 must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management (PPSM) Category Assignments List (CAL) and vulnerability assessments. |
| V-257946 | RHEL-09-252025 | low | RHEL 9 must disable the chrony daemon from acting as a server. |
| V-257947 | RHEL-09-252030 | low | RHEL 9 must disable network management of the chrony daemon. |
| V-258016 | RHEL-09-271030 | medium | RHEL 9 must disable the graphical user interface autorun function unless required. |
| V-258034 | RHEL-09-291010 | medium | RHEL 9 must be configured to disable USB mass storage. |
| V-258035 | RHEL-09-291015 | medium | RHEL 9 must have the USBGuard package installed. |
| V-258036 | RHEL-09-291020 | medium | RHEL 9 must have the USBGuard package enabled. |
| V-258039 | RHEL-09-291035 | medium | RHEL 9 Bluetooth must be disabled. |
| V-258089 | RHEL-09-433010 | medium | RHEL 9 fapolicy module must be installed. |
| V-258090 | RHEL-09-433015 | medium | RHEL 9 fapolicy module must be enabled. |
| V-268315 | WN10-00-000107 | medium | Copilot in Windows must be disabled for Windows 10. |
| V-268317 | WN11-00-000125 | medium | Copilot in Windows must be disabled for Windows 11 |
| V-270180 | RHEL-09-433016 | medium | The RHEL 9 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/CM-7. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.