U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 804 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
CIS MariaDB 10.11 Benchmark (1.0.0) MariaDB Enterprise Server 10.x
Center for Internet Security (CIS)
10/01/2024 Prose - CIS MariaDB 10.11 Benchmark v1.0.0
Sequoia Guidance (Revision 1.0) Apple MacOS 15.0
NIST, macOS Security Compliance Project
10/01/2024 SCAP 1.3 Content - Sequoia Guidance, Revision 1.0
CIS Microsoft SQL Server 2019 (1.3.0) Microsoft SQL Server 2019
Center for Internet Security (CIS)
10/01/2024 Prose - CIS Microsoft SQL Server 2019 Benchmark v1.3.0
CIS Microsoft SQL Server 2019 (1.4.0) Microsoft SQL Server 2019
Center for Internet Security (CIS)
10/01/2024 Prose - CIS Microsoft SQL Server 2019 Benchmark v1.4.0
visionOS 2.0 Guidance (Revision 1.0) Apple VisionOS 2.0
NIST, macOS Security Compliance Project
10/01/2024 ZIP - visionOS 2.0 Guidance, Revision 1.0
CIS Microsoft Azure Foundations Benchmark (3.0.0) Microsoft Azure
Center for Internet Security (CIS)
10/01/2024 Prose - CIS Microsoft Azure Foundations Benchmark v3.0.0
CIS Microsoft Azure Database Services Benchmark (1.0.0) Microsoft Azure
Center for Internet Security (CIS)
10/01/2024 Prose - CIS Microsoft Azure Database Services Benchmark v1.0.0
CIS MariaDB 10.6 Benchmark (1.1.0) MariaDB Enterprise Server 10.x
Center for Internet Security (CIS)
10/01/2024 Prose - CIS MariaDB 10.6 Benchmark v1.1.0
Ventura Guidance (Revision 5.0) Apple macOS 13.0 (Ventura)
NIST, macOS Security Compliance Project
10/01/2024 SCAP 1.3 Content - Ventura Guidance, Revision 5.0
Sonoma Guidance (Revision 3.0) Apple macOS 14.0
NIST, macOS Security Compliance Project
09/30/2024 SCAP 1.3 Content - Sonoma Guidance, Revision 3.0
Palo Alto Networks STIG for Ansible (Ver 1, Rel 4) Palo Alto Networks Network Device Management (NDM)
Defense Information Systems Agency
09/24/2024 Standalone XCCDF 1.1.4 - Palo Alto Networks STIG for Ansible - Ver 1, Rel 4
SUSE Linux Enterprise Micro 5 STIG (Ver 1, Rel 1) SUSE Linux Enterprise Micro 5.1
SUSE Linux Enterprise Micro 5.2
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Micro 5.4
SUSE Linux Enterprise Micro 5.5
Defense Information Systems Agency
09/23/2024 Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Micro 5 STIG - Ver 1, Rel 1
Samsung Android 14 BYOAD STIG (Y24M03) Samsung Android 14.0
Defense Information Systems Agency
09/23/2024 Standalone XCCDF 1.1.4 - Samsung Android 14 BYOAD STIG
iOS/iPadOS 18 Guidance (Revision 1.0) Apple iPhone OS 18.0
NIST, macOS Security Compliance Project
09/20/2024 ZIP - iOS/iPadOS 18 Guidance, Revision 1.0
iOS/iPadOS 17 Guidance (Revision 3.0) Apple iOS 17.0
NIST, macOS Security Compliance Project
09/16/2024 ZIP - iOS/iPadOS 17 Guidance, Revision 3
iOS/iPadOS 16 Guidance (Revision 3.0) Apple iOS/iPadOS 16
NIST, macOS Security Compliance Project
09/16/2024 ZIP - iOS/iPadOS 16 Guidance, Revision 3.0
Crunchy Data Postgres 16 STIG (Ver 1, Rel 1) Crunchy Data Crunchy Postgres 16.0
Crunchy Data Crunchy Postgres 16.1
Crunchy Data Crunchy Postgres 16.2
Crunchy Data Crunchy Postgres 16.3
Crunchy Data Crunchy Postgres 16.4
Defense Information Systems Agency
09/14/2024 Standalone XCCDF 1.1.4 - Crunchy Data Postgres 16 STIG - Ver 1, Rel 1
McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client STIG (Version 1, Release 3) McAfee VirusScan Enterprise for Linux 1.9
McAfee VirusScan Enterprise for Linux 2.0
Defense Information Systems Agency
09/10/2024 Standalone XCCDF 1.1.4 - McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client STIG - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Sunset-McAfee VSEL 1.9/2.0 STIG
OpenShift 3.x on Azure for Government (FedRAMP Moderate) (v1) Red Hat OpenShift Container Platform 3.10
Red Hat OpenShift Container Platform 3.11
Red Hat OpenShift Container Platform 3.5
Red Hat OpenShift Container Platform 3.6
Red Hat OpenShift Container Platform 3.7
Red Hat OpenShift Container Platform 3.8
Red Hat OpenShift Container Platform 3.9
Red Hat
09/06/2024 Security Template - Ansible Playbooks supporting the creation of either a multi-node full HA production cluster or a single node designed for exploration of OpenShift on Azure.
Prose - Deploying Red Hat OpenShift Container Platform 3 on Microsoft Azure
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.60-14) IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
09/05/2024 ZIP - Vanguard z/OS RACF Checklist 6.60/14 PDF Version
ZIP - Vanguard z/OS RACF Checklist 6.60/14 XML version
* This checklist is still undergoing review for inclusion into the NCP.