Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 561 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.44/71,6.45/72 and 6.46/73) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
Vanguard Integrity Professionals, Inc.
10/20/2021 ZIP - Vanguard z/OS RACF Checklist 6.44/7.1 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.45/7.2 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.46/7.3 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.44/7.1 XML version
ZIP - Vanguard z/OS RACF Checklist 6.45/7.2 XML version
ZIP - Vanguard z/OS RACF Checklist 6.46/7.3 XML version
Fortinet Fortigate Firewall STIG - Ver 1, Rel 1 (Ver 1, Rel 1) Fortinet Fortigate Firewall
Defense Information Systems Agency
10/18/2021 Standalone XCCDF 1.1.4 - Fortinet Fortigate Firewall STIG - Ver 1, Rel 1
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.50-8.4) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
Vanguard Integrity Professionals, Inc.
10/18/2021 ZIP - Vanguard z/OS RACF Checklist 6.50/8.4 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.50/8.4 XML version
McAfee VSEL 1.9/2.0 STIG (Version 1, Release 1) McAfee VirusScan Enterprise for Linux 1.9x
McAfee VirusScan Enterprise for Linux 2.0x
Defense Information Systems Agency
10/07/2021 Standalone XCCDF 1.1.4 - Sunset-McAfee VSEL 1.9/2.0 STIG
McAfee Antivirus 8.8 STIG (Version 5, Release 21) Mcafee Virusscan Enterprise 8.8.0
Defense Information Systems Agency
10/07/2021 SCAP 1.2 Content - Sunset-McAfee VirusScan 8.8 Local Client STIG Benchmark - Ver 1, Rel 3
SCAP 1.2 Content - Sunset-McAfee VirusScan 8.8 Managed Client STIG Benchmark - Ver 1, Rel 3
Automated Content - SCC 5.4.2 Windows
Standalone XCCDF 1.1.4 - Sunset-McAfee Virus Scan 8.8 Local Client STIG - Ver 5, Rel 16
Standalone XCCDF 1.1.4 - Sunset-McAfee VirusScan 8.8 Managed Client STIG - Ver 5, Rel 21
CIS Cisco IOS Benchmark (v3.0.1) Cisco IOS
Center for Internet Security (CIS)
10/07/2021 Prose - CIS Cisco IOS Benchmark v3.0.1
IBM WebSphere Liberty Server STIG (Ver 1 Rel 1) IBM WebSphere Liberty Server
Defense Information Systems Agency
09/28/2021 Standalone XCCDF 1.1.4 - IBM WebSphere Liberty Server STIG - Ver 1 Rel 1
Oracle Linux 8 STIG (Ver 1 Rel 1) Oracle Linux 8.0
Defense Information Systems Agency
09/24/2021 Standalone XCCDF 1.1.4 - Oracle Linux 8 STIG - Ver 1 Rel 1
Vmware Horizon 7.13 STIG (Ver 1, Rel 1) VMWare Horizon
Defense Information Systems Agency
09/20/2021 Standalone XCCDF 1.1.4 - Vmware Horizon 7.13 STIG - Ver 1, Rel 1
NetApp ONTAP DSC 9.x STIG (Ver 1, Rel 1) NetApp ONTAP DSC 9.x
Defense Information Systems Agency
09/20/2021 Standalone XCCDF 1.1.4 - NetApp ONTAP DSC 9.x STIG - Ver 1, Rel 1
Cisco ASA STIG (Version 1, Release 1) Cisco ASA
Defense Information Systems Agency
09/20/2021 Standalone XCCDF 1.1.4 - Cisco ASA STIG
Adobe Acrobat Reader DC Continuous Track STIG (Ver 2, Rel 1) Adobe Acrobat Reader
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Adobe Acrobat Reader DC Continuous Track STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4.2 Windows
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Continuous Track STIG - Ver 2, Rel 1
Canonical Ubuntu 18.04 LTS for Ansible (Version 2, Release 2) Canonical Ubuntu 18.04 LTS for Ansible
Defense Information Systems Agency
09/16/2021 Automated Content - SCC 5.4.2 Ubuntu 16 AMD64
Automated Content - SCC 5.4.2 Ubuntu 16 i686
Automated Content - SCC 5.4.2 Ubuntu 18 AMD64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 18.04 LTS for Ansible STIG - Ver 2, Rel 2
CIS Microsoft IIS 8 Benchmark (1.5.0) Microsoft Internet Information Services (IIS) 8.0
Center for Internet Security (CIS)
09/16/2021 Prose - CIS Microsoft IIS 8 Benchmark, 1.5.0
CIS CISCO Firewall Benchmark (4.1.0) Cisco ASA 8
Cisco ASA 9
Center for Internet Security (CIS)
09/16/2021 Security Template - CIS CISCO Firewall Benchmark
Microsoft Windows Server 2016 STIG (Version 2, Release 2) Microsoft Windows Server 2016
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - July 2021
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 2
Windows Server 2012 / 2012 R2 STIG (Version 3, Release 2) Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark - Ver 3, Rel 1
SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark - Ver 3, Rel 1
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 DC STIG- Ver 3, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 MS STIG - Ver 3, Rel 2
Canonical Ubuntu 18.04 LTS STIG (Ver 2, Rel 4) Canonical Ubuntu Linux 18.04 LTS
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Canonical Ubuntu 18.04 LTS STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.4.2 Ubuntu 16 AMD64
Automated Content - SCC 5.4.2 Ubuntu 16 i686
Automated Content - SCC 5.4.2 Ubuntu 18 AMD64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 18.04 LTS STIG - Ver 2, Rel 4
Canonical Ubuntu 16.04 STIG (Ver 2, Rel 3) Canonical Ubuntu 16.04 LTS (Long Term Support)
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Sunset - Canonical Ubuntu 16.04 LTS STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.4.2 Ubuntu 16 AMD64
Automated Content - SCC 5.4.2 Ubuntu 16 i686
Automated Content - SCC 5.4.2 Ubuntu 18 AMD64
Standalone XCCDF 1.1.4 - Sunset - Canonical Ubuntu 16.04 LTS STIG - Ver 2, Rel 3
Windows 10 STIG (Version 2, Release 2) Microsoft Windows 10
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Microsoft Windows 10 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 2, Rel 2
* This checklist is still undergoing review for inclusion into the NCP.