U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 796 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client STIG (Version 1, Release 3) McAfee VirusScan Enterprise for Linux 1.9
McAfee VirusScan Enterprise for Linux 2.0
Defense Information Systems Agency
09/10/2024 Standalone XCCDF 1.1.4 - McAfee Virus Scan Enterprise for Linux 1.9x/2.0x Managed Client STIG - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Sunset-McAfee VSEL 1.9/2.0 STIG
CIS Microsoft Azure Database Services Benchmark (1.0.0) Microsoft Azure
Center for Internet Security (CIS)
09/10/2024 Prose - CIS Microsoft Azure Database Services Benchmark v1.0.0
CIS Microsoft Azure Foundations Benchmark (3.0.0) Microsoft Azure
Center for Internet Security (CIS)
09/10/2024 Prose - CIS Microsoft Azure Foundations Benchmark v3.0.0
OpenShift 3.x on Azure for Government (FedRAMP Moderate) (v1) Red Hat OpenShift Container Platform 3.10
Red Hat OpenShift Container Platform 3.11
Red Hat OpenShift Container Platform 3.5
Red Hat OpenShift Container Platform 3.6
Red Hat OpenShift Container Platform 3.7
Red Hat OpenShift Container Platform 3.8
Red Hat OpenShift Container Platform 3.9
Red Hat
09/06/2024 Security Template - Ansible Playbooks supporting the creation of either a multi-node full HA production cluster or a single node designed for exploration of OpenShift on Azure.
Prose - Deploying Red Hat OpenShift Container Platform 3 on Microsoft Azure
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.60-14) IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
09/05/2024 ZIP - Vanguard z/OS RACF Checklist 6.60/14 PDF Version
ZIP - Vanguard z/OS RACF Checklist 6.60/14 XML version
Teams - SCuBA (1.0) Microsoft Teams
Cybersecurity and Infrastructure Security Agency (CISA)
08/30/2024 Machine-Readable Format - Microsoft Teams GitHub
Prose - Microsoft Teams
NIST National Checklist for Red Hat Enterprise Linux 7.x (content v0.1.50) Red Hat Enterprise Linux 7.0
Red Hat Enterprise Linux 7.1
Red Hat Enterprise Linux 7.2
Red Hat Enterprise Linux 7.3
Red Hat Enterprise Linux 7.4
Red Hat Enterprise Linux 7.5
Red Hat Enterprise Linux 7.6
Red Hat Enterprise Linux 7.7
Red Hat
08/30/2024 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 7.x, SCAP 1.3
Ansible Playbook - CIA Commercial Cloud Services (CIA C2S)
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for Red Hat Enterprise Linux 7.x
Ansible Playbook - PCI-DSS
Ansible Playbook - DoD STIG
NIST National Checklist for HyperSphere Technologies (0.1) Hypersphere Technologies Vault 1.0
Mission IT
08/30/2024 Machine-Readable Format - OpenControl content for HyperSphere Technologies
Power BI - SCuBA (1.0) Microsoft SharePoint Online
Cybersecurity and Infrastructure Security Agency (CISA)
08/30/2024 Machine-Readable Format - Microsoft Power BI GitHub Mark down
Prose - Microsoft Power BI
NIST National Checklist for Red Hat Enterprise Linux 8.x (content v0.1.50) Red Hat Enterprise Linux 8.0
Red Hat Enterprise Linux 8.1
Red Hat Enterprise Linux 8.2
Red Hat
08/30/2024 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 8.x
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for RHEL 8.x
Ansible Playbook - PCI-DSS
FedRAMP Low for Red Hat Ansible Tower 3.2.x (v1) Red Hat Ansible Tower 3.2.0
Red Hat Ansible Tower 3.2.1
Red Hat Ansible Tower 3.2.2
Red Hat Ansible Tower 3.2.3
Red Hat Ansible Tower 3.2.4
Red Hat Ansible Tower 3.2.5
Red Hat Ansible Tower 3.2.6
Red Hat
08/27/2024 Security Template - NIST 800-53 Control Applicability Guide for Red Hat Ansible Tower 3.2.x
Security Template - FedRAMP Template for Red Hat Ansible Tower 3.x
Prose - Section 508 Voluntary Product Accessibility Template (VPAT) and Web Content Accessibility Guidelines (WCAG) 2.0 for Ansible Tower
FedRAMP Moderate for Red Hat OpenStack Platform 13 (v1) Red Hat OpenStack Platform 13.0
Red Hat
08/27/2024 Security Template - NIST 800-53 Control Applicability Guide for Red Hat OpenStack Platform 13
Security Template - FedRAMP Moderate Template SSP for Red Hat OpenStack Platform 13
Google Chrome Browser STIG for Windows (Version 2, Release 9) Google Chrome 33
Defense Information Systems Agency
08/27/2024 SCAP 1.2 Content - Google Chrome STIG Benchmark - Ver 2, Rel 9
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - April 2024
Standalone XCCDF 1.1.4 - Google Chrome STIG - Ver 2, Rel 9
Mozilla Firefox STIG (Version 6, Release 5) Mozilla Firefox
Defense Information Systems Agency
08/27/2024 SCAP 1.2 Content - Mozilla Firefox Linux STIG Benchmark - Ver 6, Rel 4
SCAP 1.2 Content - Mozilla Firefox Windows STIG Benchmark - Ver 6, Rel 5
Automated Content - SCC 5.10 Windows
Automated Content - SCC 5.10 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.10 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.10 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.10 RHEL 9 x86 64
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 6, Rel 5
Internet Explorer 11 STIG (Ver 2, Rel 5) Microsoft Internet Explorer 11
Defense Information Systems Agency
08/27/2024 SCAP 1.2 Content - Microsoft Internet Explorer 11 STIG Benchmark - Ver 2, Rel 6
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - April 2024
Standalone XCCDF 1.1.4 - Microsoft Internet Explorer 11 STIG - Ver 2, Rel 5
Microsoft .NET Framework 4 (Version 2, Release 4) Microsoft .NET Framework 4.0
Defense Information Systems Agency
08/27/2024 SCAP 1.2 Content - Microsoft .NET Framework 4 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.10 Windows
Standalone XCCDF 1.1.4 - Microsoft .Net Framework 4.0 STIG - Ver 2, Rel 4
Adobe Acrobat Reader DC Continuous Track STIG (Ver 2, Rel 2) Adobe Acrobat Reader
Defense Information Systems Agency
08/27/2024 SCAP 1.2 Content - Adobe Acrobat Reader DC Continuous Track STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - April 2024
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Continuous Track STIG - Ver 2, Rel 1
Windows Firewall STIG and Advanced Security STIG (Ver 2, Rel 2) windows firewall
Defense Information Systems Agency
08/27/2024 SCAP 1.2 Content - Microsoft Windows Defender Firewall with Advanced Security STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - April 2024
Standalone XCCDF 1.1.4 - Microsoft Windows Defender Firewall with Advanced Security STIG - Ver 2, Rel 2
Microsoft Windows Defender Antivirus STIG (Ver 2, Rel 5) Microsoft Windows Defender
Defense Information Systems Agency
08/27/2024 SCAP 1.2 Content - Microsoft Defender Antivirus STIG Benchmark - Ver 2, Rel 5
SCAP 1.2 Content - Microsoft Windows Defender Firewall with Advanced Security STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - April 2024
Standalone XCCDF 1.1.4 - Microsoft Defender Antivirus STIG - Ver 2, Rel 4
Standalone XCCDF 1.1.4 - Microsoft Windows Defender Firewall with Advanced Security STIG - Ver 2, Rel 2
Microsoft Windows Server 2019 (Ver 3, Rel 1) Microsoft Windows Server 2019
Defense Information Systems Agency
08/27/2024 SCAP 1.3 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 3, Rel 1
SCAP 1.2 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 2, Rel 5
Automated Content - SCC 5.10 Windows
GPOs - Group Policy Objects (GPOs) - April 2024
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 3, Rel 1
* This checklist is still undergoing review for inclusion into the NCP.