U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 571 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.51-8.5) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
01/21/2022 ZIP - Vanguard z/OS RACF Checklist 6.51/8.5 PDF version
ZIP - anguard z/OS RACF Checklist 6.51/8.5 XML version
Redis Enterprise 6.x STIG (Ver 1, Rel 1) Redis Enterprise 6.0
Defense Information Systems Agency
01/21/2022 Standalone XCCDF 1.1.4 - Redis Enterprise 6.x STIG - Ver 1, Rel 1
Ivanti MobileIron Core MDM Server STIG (Ver 1, Rel 1) Ivanti MobileIron Core
Defense Information Systems Agency
01/21/2022 Standalone XCCDF 1.1.4 - Ivanti MobileIron Core MDM Server STIG - Ver 1, Rel 1
Microsoft Exchange Server 2016 STIG (Y21M12) Microsoft Exchange Server 2016
Defense Information Systems Agency
01/14/2022 Standalone XCCDF 1.1.4 - Microsoft Exchange 2016 STIG
Microsoft Exchange Server 2013 (Y21M12) Microsoft Exchange Server 2013
Defense Information Systems Agency
01/14/2022 Standalone XCCDF 1.1.4 - Microsoft Exchange 2013 STIG
Microsoft Outlook 2016 STIG (Version 2, Release 2) Microsoft Outlook 2016
Defense Information Systems Agency
01/14/2022 Standalone XCCDF 1.1.4 - Microsoft Outlook 2016 STIG - Ver 2 Rel 2
Solaris 11 (SPARC and x86) Manual STIG (Version 2, Release 5) Sun Solaris
Defense Information Systems Agency
01/12/2022 SCAP 1.2 Content - Solaris 11 SPARC STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Solaris 11 X86 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4.2 Solaris 10 i386
Automated Content - SCC 5.4.2 Solaris 10 SPARC
Automated Content - SCC 5.4.2 Solaris 11 i386
Automated Content - SCC 5.4.2 Solaris 11 SPARC
Standalone XCCDF 1.1.4 - Palo Alto Networks STIG for Ansible - Ver 1, Rel 4
Standalone XCCDF 1.1.4 - Solaris 11 SPARC STIG - Version 2, Release 5
Standalone XCCDF 1.1.4 - Solaris 11 x86 STIG - Version 2, Release 5
Splunk Enterprise 8.0 for Linux (Ver 1, Rel 1) Splunk Enterprise 8.0.0
Defense Information Systems Agency
01/11/2022 Standalone XCCDF 1.1.4 - Splunk Enterprise 8.0 for Linux - Ver 1 Rel 1
Microsoft One Drive for Business 2016 STIG (Version 2, Release 2) Microsoft One Drive for Business 2016
Defense Information Systems Agency
01/10/2022 Standalone XCCDF 1.1.4 - Microsoft OneDrive STIG - Ver 2, Rel 2
Apple OS/iPad OS 14 STIG (Ver 1, Rel 2) Apple iPad OS/iOS 14.0
Defense Information Systems Agency
01/10/2022 Standalone XCCDF 1.1.4 - Apple iOS/iPad OS 14 STIG - Ver 1, Rel 2
Apple OS/iPad OS 13 STIG (Ver 2, Rel 1) Apple iOS 13.0
Defense Information Systems Agency
01/10/2022 Standalone XCCDF 1.1.4 - Sunset - Apple iOS/iPad OS 13 STIG - Ver 2, Rel 1
Microsoft Windows Server 2016 STIG (Version 2, Release 3) Microsoft Windows Server 2016
Defense Information Systems Agency
01/10/2022 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - October 2021
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 3
Cisco IOS XE Release 3 Router STIG (Version 1 Release 3) Cisco IOS XE
Defense Information Systems Agency
01/10/2022 SCAP 1.3 Content - Cisco IOS XE Router NDM Benchmark - Version 1, Release 2
Standalone XCCDF 1.1.4 - Sunset - Cisco IOS XE Release 3 NDM STIG - Ver 1, Rel 5
Standalone XCCDF 1.1.4 - Sunset - Cisco IOS XE Release 3 RTR STIG - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Cisco IOS-XE Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS XE Router NDM RTR STIG for Ansible - Ver 2, Rel 3
Apple OS/iPad OS 15 STIG (Ver 1, Rel 1) Apple OS/iPad OS 15
Defense Information Systems Agency
01/10/2022 Standalone XCCDF 1.1.4 - Apple iOS/iPad OS 15 STIG - Ver 1, Rel 1
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.50-8.4) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
01/06/2022 ZIP - Vanguard z/OS RACF Checklist 6.50/8.4 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.50/8.4 XML version
CA IDMS STIG (Ver 1, Rel 1) Broadcom CA IDMS
Defense Information Systems Agency
01/06/2022 Standalone XCCDF 1.1.4 - CA IDMS STIG - Ver 1, Rel 1
Mozilla Firefox STIG (Version 6, Release 1) Mozilla Firefox
Defense Information Systems Agency
12/17/2021 Automated Content - SCC 5.4.2 Windows
Automated Content - SCC 5.4.2 RHEL 6 i686
Automated Content - SCC 5.4.2 RHEL 6 x86 64
Automated Content - SCC 5.4.2 RHEL 7/Oracle Linux 7/SLES12 x86 64
Automated Content - SCC 5.4.2 RHEL 8 x86 64
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 6, Rel 1
VMWare Workspace ONE UEM STIG (Ver 2, Rel 1) Workspace ONE Unified Endpoint Management
Defense Information Systems Agency
12/17/2021 Standalone XCCDF 1.1.4 - VMware Workspace ONE UEM STIG- Ver 2, Rel 1
Monterey Gudiance (Revision 1) Apple macOS 12.0 (Monterey)
NIST, macOS Security Compliance Project
12/15/2021 SCAP 1.3 Content - Monterey Guidance
Ivanti MobileIron Sentry 9.x STIG (Ver 1 Rel 1) Ivanti MobileIron Sentry 9.x
Defense Information Systems Agency
12/06/2021 Standalone XCCDF 1.1.4 - Ivanti MobileIron Sentry 9.x STIG - Ver 1 Rel 1
* This checklist is still undergoing review for inclusion into the NCP.