Checklist Repository
The National Checklist Program (NCP), defined by the NIST
SP 800-70, is the U.S. government repository of publicly available
security checklists (or benchmarks) that provide detailed low level
guidance on setting the security configuration of operating systems
and applications.
NCP provides metadata and links to checklists of various formats
including checklists that conform to the Security
Content Automation Protocol (SCAP). SCAP enables validated
security products to automatically perform configuration checking
using NCP checklists. For more information relating to the NCP please
visit the information page or
the glossary of terms.
Please note that the current search fields have been adjusted to
reflect NIST SP 800-70 Revision 4.
Search for Checklists using the fields below. The keyword
search will search across the name, and summary.
There are 843
matching records. Displaying matches 1 through 20.
Name (Version) |
Target |
Authority |
Last Modified |
Resources |
CIS DigitalOcean Foundations Benchmark (1.0.0) |
DigitalOcean
|
Center for Internet Security (CIS)
|
08/13/2025 |
Prose - CIS DigitalOcean Foundations Benchmark v1.0.0
|
Alibaba Cloud Foundation (2.0.0) |
Alibaba Cloud
|
Center for Internet Security (CIS)
|
08/13/2025 |
Prose - Alibaba Cloud Foundation, v2.0.0
|
Microsoft Exchange Online - SCuBA (1.6.0) |
Microsoft Exchange Online
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Exchange Online - GitHub Markdown
Prose - BOD 25-01: Implementation Guidance for Implementing Secure Practices for Cloud Services
Prose - Microsoft Exchange Online
|
Entra ID - SCuBA (1.6) |
Microsoft Azure Active Directory
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Entra ID - GitHub
Prose - Microsoft Entra ID - SCuBA
|
Microsoft Power BI - SCuBA (1.6.0) |
Microsoft Power Apps
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Power BI GitHub Mark down
Prose - Microsoft Power BI
|
Microsoft Defender for Office 365 - SCuBA (1.6.0) |
Microsoft Windows Defender
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Prose - CISA GitHub for ScubaGear - MSFT Defender
Prose - Microsoft Defender for Office 365
|
Microsoft Power Platform - SCuBA (1.6.0) |
Microsoft Power Apps
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Power Platform - GitHub
Prose - BOD 25-01: Implementation Guidance for Implementing Secure Practices for Cloud Services
Prose - Microsoft Power Platform
|
SharePoint and OneDrive - SCuBA (1.6.0) |
Microsoft OneDrive Microsoft SharePoint Online
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft SharePoint & OneDrive GitHub
Prose - Microsoft SharePoint & OneDrive
|
Microsoft Teams - SCuBA (1.6.0) |
Microsoft Teams
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Teams GitHub
Prose - Microsoft Teams
|
CIS Cisco Firepower Threat Defense Benchmark (1.0.0) |
Cisco Firepower Threat Defense 6.0.0 Cisco Firepower Threat Defense 7.0.0
|
Center for Internet Security (CIS)
|
08/05/2025 |
Prose - CIS Cisco Firepower Threat Defense Benchmark, v1.0.0
|
Ubuntu Linux 20.04 LTS Benchmark (3.0.0) |
Canonical Ubuntu 20.04 LTS
|
Center for Internet Security (CIS)
|
08/04/2025 |
Prose - CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0
|
CIS Microsoft Azure Compute Services Benchmark (2.0.0) |
Microsoft Azure
|
Center for Internet Security (CIS)
|
07/28/2025 |
Prose - CIS Microsoft Azure Compute Services Benchmark v2.0.0
|
Microsoft Entra ID STIG (Ver 1, Rel 1) |
Microsoft Entra ID
|
Defense Information Systems Agency
|
07/28/2025 |
Standalone XCCDF 1.1.4 - Microsoft Entra ID STIG Ver 1, Rel 1
|
CIS Google Cloud Platform Foundation Benchmark (4.0.0) |
Google Cloud Platform
|
Center for Internet Security (CIS)
|
07/28/2025 |
Prose - CIS Google Cloud Platform Foundation Benchmark v4.0.0
|
Cisco ACI (Y25M05) |
Cisco Application Centric Infrastructure (ACI)
|
Defense Information Systems Agency
|
07/21/2025 |
Standalone XCCDF 1.1.4 - U_Cisco_ACI_Y25M05_STIG
|
Microsoft SQL Server 2022 (Ver 1, Rel 1) |
Microsoft SQL Server 2022
|
Defense Information Systems Agency
|
07/21/2025 |
Standalone XCCDF 1.1.4 - Microsoft SQL Server 2022 STIG - Ver 1,Rel 1
|
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.61-91) |
IBM z/OS Version 2, Release 4 IBM z/OS Version 2, Release 5
|
Vanguard Integrity Professionals, Inc.
|
07/21/2025 |
ZIP - Vanguard z/OS RACF Checklist 6.61/91 XML version
ZIP - Vanguard z/OS RACF Checklist 6.61/91 PDF version
|
Oracle Linux 9 STIG (Ver 1, Rel 1) |
Oracle Linux 9.0
|
Defense Information Systems Agency
|
07/21/2025 |
Standalone XCCDF 1.1.4 - Oracle Linux 9 STIG - Ver 1, Rel 1
|
Apple iOS/iPadOS 18 STIG (Ver 1, Rel 4) |
Apple iPadOS 18.0 Apple iPhone OS 18.0
|
Defense Information Systems Agency
|
07/14/2025 |
Standalone XCCDF 1.1.4 - Apple iOS/iPadOS 18 STIG - Ver 1, Rel 4
|
iOS/iPadOS 18 Guidance (Revision 2.0) |
Apple iPhone OS 18.0
|
NIST, macOS Security Compliance Project
|
07/09/2025 |
ZIP - iOS/iPadOS 18 Guidance, Revision 2.0
|
* This checklist is still undergoing review for
inclusion into the NCP.