U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 567 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
CA IDMS STIG (Ver 1, Rel 1) Broadcom CA IDMS
Defense Information Systems Agency
12/06/2021 Standalone XCCDF 1.1.4 - CA IDMS STIG - Ver 1, Rel 1
Apple OS/iPad OS 15 STIG (Ver 1, Rel 1) Apple OS/iPad OS 15
Defense Information Systems Agency
12/06/2021 Standalone XCCDF 1.1.4 - Apple OS/iPad OS 15 STIG - Ver 1, Rel 1
Ivanti MobileIron Sentry 9.x STIG (Ver 1 Rel 1) Ivanti MobileIron Sentry 9.x
Defense Information Systems Agency
12/06/2021 Standalone XCCDF 1.1.4 - Ivanti MobileIron Sentry 9.x STIG - Ver 1 Rel 1
Fortinet Fortigate Firewall STIG (Ver 1, Rel 1) Fortinet Fortigate Firewall
Defense Information Systems Agency
12/06/2021 Standalone XCCDF 1.1.4 - Fortinet Fortigate Firewall STIG - Ver 1, Rel 1
Google Android 12 STIG (Ver 1, Rel 1) Google Android 12
Defense Information Systems Agency
12/06/2021 Standalone XCCDF 1.1.4 - Google Android 12 STIG - Ver 1, Rel 1
Windows 10 STIG (Version 2, Release 2) Microsoft Windows 10
Defense Information Systems Agency
12/06/2021 SCAP 1.2 Content - Microsoft Windows 10 STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - October 2021
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 2, Rel 3
Microsoft Windows 2012 Server DNS STIG (Ver 2, Rel 4) Microsoft Windows Server 2012 R2
Defense Information Systems Agency
11/26/2021 Standalone XCCDF 1.1.4 - Microsoft Windows 2012 Server Domain Name System STIG - Ver 2, Rel 4
Microsoft Windows Privileged Access Workstation (PAW) STIG (Ver 2, Rel 1) Microsoft Windows Dedicated Administrative Workstation
Defense Information Systems Agency
11/26/2021 Standalone XCCDF 1.1.4 - Microsoft Windows Privileged Access Workstation (PAW) STIG - Ver 2, Rel 1
Microsoft One Drive for Business 2016 STIG (Version 2, Release 2) Microsoft One Drive for Business 2016
Defense Information Systems Agency
11/26/2021 Standalone XCCDF 1.1.4 - Microsoft OneDrive - Ver 2, Rel 2
Microsoft Windows Server 2016 STIG (Version 2, Release 3) Microsoft Windows Server 2016
Defense Information Systems Agency
11/26/2021 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - October 2021
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 2
Microsoft Windows 2012 and 2012 R2 DC STIG (Ver 3, Rel 3) Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Defense Information Systems Agency
11/26/2021 SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark - Ver 3, Rel 2
SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark - Ver 3, Rel 2
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - October 2021
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 DC STIG- Ver 3, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 MS STIG - Ver 3, Rel 3
Active Directory Domain STIG (Ver 3, Rel 1) Microsoft Active Directory
Defense Information Systems Agency
11/26/2021 Standalone XCCDF 1.1.4 - Active Directory Domain STIG - Ver 3, Rel 1
Microsoft Windows Defender Antivirus STIG (Ver 2, Rel 3) Microsoft Windows Defender
Defense Information Systems Agency
11/26/2021 SCAP 1.2 Content - Microsoft Windows Defender Antivirus STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - October 2021
Standalone XCCDF 1.1.4 - Microsoft Windows Defender Antivirus STIG - Ver 2, Rel 3
Microsoft Windows Server 2019 (Ver 2, Rel 2) Microsoft Windows Server 2019
Defense Information Systems Agency
11/26/2021 SCAP 1.2 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - October 2021
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 2, Rel 3
Windows Firewall STIG and Advanced Security STIG (Ver 2, Rel 1) windows firewall
Defense Information Systems Agency
11/26/2021 SCAP 1.2 Content - Microsoft Windows Firewall STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - October 2021
Standalone XCCDF 1.1.4 - Microsoft Windows Firewall STIG and Advanced Security STIG - Ver 2, Rel 1
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.44/71,6.45/72 and 6.46/73) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
11/24/2021 ZIP - Vanguard z/OS RACF Checklist 6.44/7.1 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.45/7.2 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.46/7.3 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.44/7.1 XML version
ZIP - Vanguard z/OS RACF Checklist 6.45/7.2 XML version
ZIP - Vanguard z/OS RACF Checklist 6.46/7.3 XML version
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.47-8.1) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
11/24/2021 ZIP - Vanguard z/OS RACF Checklist 6.47/8.1 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.47/8.1 XML version
Vanguard Compliance Manager z/OS RACF Checklist for completing a automated SRR Audit for Stig (6.44/71,6.45/72 and 6.46/73) IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
11/24/2021 ZIP - Vanguard z/OS RACF Checklist 6.44-6.46/7.1-7.3(For Z/OS V2R4 release)
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.48-8.2) IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
11/24/2021 ZIP - Vanguard z/OS RACF Checklist 6.48/8.2 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.47/8.1 XML version
Vanguard Compliance Manager z/OS RACF Checklist for completing a automated SRR Audit for Stig (6.43) IBM z/OS Version 2, Release 2
IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
11/24/2021 ZIP - Vanguard z/OS RACF Checklist 6.43(For Z/OS V2R2 release)
ZIP - Vanguard z/OS RACF Checklist 6.43(For Z/OS V2R3 release)
ZIP - Vanguard z/OS RACF Checklist 6.43(For Z/OS V2R4 release)
* This checklist is still undergoing review for inclusion into the NCP.