U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 805 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
CIS Microsoft Azure Storage Services Benchmark (1.0.0) Microsoft Azure
Center for Internet Security (CIS)
11/20/2024 Prose - CIS Microsoft Azure Storage Services Benchmark v1.0.0
Microsoft SQL Server 2016 (Y24M10) Microsoft SQL Server 2016
Defense Information Systems Agency
11/19/2024 Standalone XCCDF 1.1.4 - Microsoft SQL Server 2016
Microsoft Office System 2016 STIG (Version 2, Release 3) Microsoft Office 2016
Defense Information Systems Agency
11/14/2024 GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Microsoft Office System 2016 STIG - Ver 2, Rel 3
SUSE Linux Enterprise Server (SLES) 12 STIG (Ver 3, Rel 1) SUSE Linux Enterprise Server 12.0
Defense Information Systems Agency
11/14/2024 SCAP 1.3 Content - SLES 12 STIG Benchmark - Ver 3, Rel 1
Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Server 12 STIG - Ver 3, Rel 1
CIS Microsoft SQL Server 2019 (1.3.0) Microsoft SQL Server 2019
Center for Internet Security (CIS)
11/14/2024 Prose - CIS Microsoft SQL Server 2019 Benchmark v1.3.0
Red Hat Jboss Enterprise Application Platform (EAP) 6.3 STIG (Ver 2, Rel 5) Red Hat JBoss Enterprise Application Platform 6.3.0
Defense Information Systems Agency
11/14/2024 Standalone XCCDF 1.1.4 - JBoss Enterprise Application Platform (EAP) 6.3 STIG - Ver 2, Rel 5
Microsoft Edge STIG (Ver 2, Rel 2) Microsoft Edge
Defense Information Systems Agency
11/08/2024 SCAP 1.3 Content - Microsoft Edge STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Microsoft Edge STIG Benchmark - Ver 1, Rel 3
GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Microsoft Edge STIG - Ver 2, Rel 2
Microsoft Windows Server 2016 STIG (Version 2, Release 9) Microsoft Windows Server 2016
Defense Information Systems Agency
11/08/2024 SCAP 1.3 Content - Microsoft Windows Server 2016 STIG SCAP Benchmark - Ver 2, Rel 7
SCAP 1.2 Content - Sunset - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 5
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - October 2024
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 9
Google Chrome Browser STIG for Windows (Version 2, Release 10) Google Chrome 33
Defense Information Systems Agency
11/08/2024 SCAP 1.3 Content - Google Chrome STIG Benchmark - Ver 2, Rel 10
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Google Chrome STIG - Ver 2, Rel 10
Kubernetes STIG (Ver 2, Rel 2) Kubernetes
Defense Information Systems Agency
11/06/2024 SCAP 1.3 Content - Kubernetes STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Kubernetes STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Kubernetes STIG - Ver 2, Rel 2
Rancher Government Solutions RKE2 STIG (Ver 2, Rel 2) Rancher RKE2
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Rancher Government Solutions RKE2 STIG - Ver 2, Rel 2
NetApp ONTAP DSC 9.X STIG (Ver 2, Rel 2) NetApp ONTAP DSC 9.x
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - NetApp ONTAP DSC 9.x STIG - Ver 2, Rel 2
Oracle 12c Database STIG (Ver 3, Rel 2) Oracle Database 12c
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Oracle Database 12c STIG - Ver 3, Rel 2
Microsoft IIS 10.0 Server STIG (Y24M10) Microsoft IIS 10
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Microsoft IIS 10.0 STIG
Microsoft Windows 11 STIG (Ver 2, Rel 2) Microsoft Windows 11
Defense Information Systems Agency
11/05/2024 SCAP 1.3 Content - Microsoft Windows 11 STIG SCAP Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Microsoft Windows 11 STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG for Chef - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG - Ver 2, Rel 2
Microsoft Azure SQL Database STIG (Ver 2, Rel 2) Microsoft Azure
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Microsoft Azure SQL Database STIG - Ver 2, Rel 2
MariaDB Enterprise 10.x STIG (Ver 2, Rel 2) MariaDB Enterprise Server 10.x
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - MariaDB Enterprise 10.x STIG - Ver 2, Rel 2
Microsoft Windows Server Domain Name System STIG (Ver 2, Rel 2) Microsoft Active Directory
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Microsoft Windows Server Domain Name System STIG - Ver 2, Rel 2
MarkLogic Server v9 STIG (Ver 3, Rel 2) MarkLogic Server v9
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - MarkLogic Server v9 STIG - Ver 3, Rel 2
CA IDMS STIG (Ver 2, Rel 1) Broadcom CA IDMS
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - CA IDMS STIG - Ver 2, Rel 1
* This checklist is still undergoing review for inclusion into the NCP.