Checklist Repository
The National Checklist Program (NCP), defined by the NIST
SP 800-70, is the U.S. government repository of publicly available
security checklists (or benchmarks) that provide detailed low level
guidance on setting the security configuration of operating systems
and applications.
NCP provides metadata and links to checklists of various formats
including checklists that conform to the Security
Content Automation Protocol (SCAP). SCAP enables validated
security products to automatically perform configuration checking
using NCP checklists. For more information relating to the NCP please
visit the information page or
the glossary of terms.
Please note that the current search fields have been adjusted to
reflect NIST SP 800-70 Revision 4.
Search for Checklists using the fields below. The keyword
search will search across the name, and summary.
There are 804
matching records. Displaying matches 1 through 20.
Name (Version) |
Target |
Authority |
Last Modified |
Resources |
Red Hat Jboss Enterprise Application Platform (EAP) 6.3 STIG (Ver 2, Rel 5) |
Red Hat JBoss Enterprise Application Platform 6.3.0
|
Defense Information Systems Agency
|
11/08/2024 |
Standalone XCCDF 1.1.4 - Red Hat JBoss Enterprise Application Platform (EAP) 6.3 STIG - Ver 2, Rel 5
|
Microsoft Edge STIG (Ver 2, Rel 2) |
Microsoft Edge
|
Defense Information Systems Agency
|
11/08/2024 |
SCAP 1.3 Content - Microsoft Edge STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Microsoft Edge STIG Benchmark - Ver 1, Rel 3
GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Microsoft Edge STIG - Ver 2, Rel 2
|
Microsoft Windows Server 2016 STIG (Version 2, Release 9) |
Microsoft Windows Server 2016
|
Defense Information Systems Agency
|
11/08/2024 |
SCAP 1.3 Content - Microsoft Windows Server 2016 STIG SCAP Benchmark - Ver 2, Rel 7
SCAP 1.2 Content - Sunset - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 5
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - October 2024
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 9
|
Google Chrome Browser STIG for Windows (Version 2, Release 10) |
Google Chrome 33
|
Defense Information Systems Agency
|
11/08/2024 |
SCAP 1.3 Content - Google Chrome STIG Benchmark - Ver 2, Rel 10
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - October 2024
Standalone XCCDF 1.1.4 - Google Chrome STIG - Ver 2, Rel 10
|
Kubernetes STIG (Ver 2, Rel 2) |
Kubernetes
|
Defense Information Systems Agency
|
11/06/2024 |
SCAP 1.3 Content - Kubernetes STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Kubernetes STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Kubernetes STIG - Ver 2, Rel 2
|
Microsoft SQL Server 2016 (Y24M10) |
Microsoft SQL Server 2016
|
Defense Information Systems Agency
|
11/06/2024 |
Standalone XCCDF 1.1.4 - Microsoft SQL Server 2016 STIG
|
Rancher Government Solutions RKE2 STIG (Ver 2, Rel 2) |
Rancher RKE2
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - Rancher Government Solutions RKE2 STIG - Ver 2, Rel 2
|
NetApp ONTAP DSC 9.X STIG (Ver 2, Rel 2) |
NetApp ONTAP DSC 9.x
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - NetApp ONTAP DSC 9.x STIG - Ver 2, Rel 2
|
Oracle 12c Database STIG (Ver 3, Rel 2) |
Oracle Database 12c
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - Oracle Database 12c STIG - Ver 3, Rel 2
|
Microsoft IIS 10.0 Server STIG (Y24M10) |
Microsoft IIS 10
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - Microsoft IIS 10.0 STIG
|
Microsoft Windows 11 STIG (Ver 2, Rel 2) |
Microsoft Windows 11
|
Defense Information Systems Agency
|
11/05/2024 |
SCAP 1.3 Content - Microsoft Windows 11 STIG SCAP Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Microsoft Windows 11 STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG for Chef - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows 11 STIG - Ver 2, Rel 2
|
Microsoft Azure SQL Database STIG (Ver 2, Rel 2) |
Microsoft Azure
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - Microsoft Azure SQL Database STIG - Ver 2, Rel 2
|
MariaDB Enterprise 10.x STIG (Ver 2, Rel 2) |
MariaDB Enterprise Server 10.x
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - MariaDB Enterprise 10.x STIG - Ver 2, Rel 2
|
Microsoft Windows Server Domain Name System STIG (Ver 2, Rel 2) |
Microsoft Active Directory
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - Microsoft Windows Server Domain Name System STIG - Ver 2, Rel 2
|
MarkLogic Server v9 STIG (Ver 3, Rel 2) |
MarkLogic Server v9
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - MarkLogic Server v9 STIG - Ver 3, Rel 2
|
CA IDMS STIG (Ver 2, Rel 1) |
Broadcom CA IDMS
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - CA IDMS STIG - Ver 2, Rel 1
|
Apple macOS (Sonoma) 14 STIG (Ver 2, Rel 2) |
Apple macOS 14.0
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - Apple macOS 14 (Sonoma) STIG - Ver 2, Rel 2
|
ISEC7 Sphere STIG (Ver 3, Rel 1) |
iSEC7 Enterprise Mobility Management 6.0
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - ISEC7 Sphere STIG - Ver 3, Rel 1
|
Active Directory Forest STIG (Ver 2, Rel 8) |
Microsoft Active Directory
|
Defense Information Systems Agency
|
11/05/2024 |
Standalone XCCDF 1.1.4 - Active Directory Forest STIG - Ver 3, Rel 1
|
Canonical Ubuntu 22.04 LTS STIG (Ver 2, Rel 2) |
Canonical Ubuntu 22.04 LTS
|
Defense Information Systems Agency
|
11/05/2024 |
Automated Content - SCC 5.10 Ubuntu 22 AMD64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 22.04 LTS STIG - Ver 2, Rel 2
|
* This checklist is still undergoing review for
inclusion into the NCP.