Checklist Repository
The National Checklist Program (NCP), defined by the NIST
SP 800-70, is the U.S. government repository of publicly available
security checklists (or benchmarks) that provide detailed low level
guidance on setting the security configuration of operating systems
and applications.
NCP provides metadata and links to checklists of various formats
including checklists that conform to the Security
Content Automation Protocol (SCAP). SCAP enables validated
security products to automatically perform configuration checking
using NCP checklists. For more information relating to the NCP please
visit the information page or
the glossary of terms.
Search for Checklists using the fields below. The keyword
search will search across the name, and summary.
There are 868
matching records. Displaying matches 141 through 160.
| Name (Version) |
Target |
Authority |
Last Modified |
Resources |
| Red Hat Ansible Automation Controller STIG (Y25M07) |
Red Hat Ansible Automation Controller
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - Red Hat Ansible Automation Controller STIG
|
| F5 BIG-IP TMOS STIG (Y25M07) |
F5 BIG-IP Access Policy Manager (APM)
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - F5 BIG-IP TMOS STIG
|
| HP FlexFabric Switch Router STIG (Y25M07) |
HP FlexFabric
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - HP FlexFabric Switch STIG
|
| Alibaba Cloud Foundation (2.0.0) |
Alibaba Cloud
|
Center for Internet Security (CIS)
|
08/13/2025 |
Prose - Alibaba Cloud Foundation, v2.0.0
|
| Microsoft Exchange Online - SCuBA (1.6.0) |
Microsoft Exchange Online
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Exchange Online - GitHub Markdown
Prose - BOD 25-01: Implementation Guidance for Implementing Secure Practices for Cloud Services
Prose - Microsoft Exchange Online
|
| Entra ID - SCuBA (1.6) |
Microsoft Azure Active Directory
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Entra ID - GitHub
Prose - Microsoft Entra ID - SCuBA
|
| Microsoft Power BI - SCuBA (1.6.0) |
Microsoft Power Apps
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Power BI GitHub Mark down
Prose - Microsoft Power BI
|
| Microsoft Defender for Office 365 - SCuBA (1.6.0) |
Microsoft Windows Defender
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Prose - CISA GitHub for ScubaGear - MSFT Defender
Prose - Microsoft Defender for Office 365
|
| Microsoft Power Platform - SCuBA (1.6.0) |
Microsoft Power Apps
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Power Platform - GitHub
Prose - BOD 25-01: Implementation Guidance for Implementing Secure Practices for Cloud Services
Prose - Microsoft Power Platform
|
| SharePoint and OneDrive - SCuBA (1.6.0) |
Microsoft OneDrive Microsoft SharePoint Online
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft SharePoint & OneDrive GitHub
Prose - Microsoft SharePoint & OneDrive
|
| Microsoft Teams - SCuBA (1.6.0) |
Microsoft Teams
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Teams GitHub
Prose - Microsoft Teams
|
| CIS Cisco Firepower Threat Defense Benchmark (1.0.0) |
Cisco Firepower Threat Defense 6.0.0 Cisco Firepower Threat Defense 7.0.0
|
Center for Internet Security (CIS)
|
08/05/2025 |
Prose - CIS Cisco Firepower Threat Defense Benchmark, v1.0.0
|
| Ubuntu Linux 20.04 LTS Benchmark (3.0.0) |
Canonical Ubuntu 20.04 LTS
|
Center for Internet Security (CIS)
|
08/04/2025 |
Prose - CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0
|
| CIS Microsoft Azure Compute Services Benchmark (2.0.0) |
Microsoft Azure
|
Center for Internet Security (CIS)
|
07/28/2025 |
Prose - CIS Microsoft Azure Compute Services Benchmark v2.0.0
|
| CIS Google Cloud Platform Foundation Benchmark (4.0.0) |
Google Cloud Platform
|
Center for Internet Security (CIS)
|
07/28/2025 |
Prose - CIS Google Cloud Platform Foundation Benchmark v4.0.0
|
| Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.61-91) |
IBM z/OS Version 2, Release 4 IBM z/OS Version 2, Release 5
|
Vanguard Integrity Professionals, Inc.
|
07/21/2025 |
ZIP - Vanguard z/OS RACF Checklist 6.61/91 XML version
ZIP - Vanguard z/OS RACF Checklist 6.61/91 PDF version
|
| visionOS 2.0 Guidance (Revision 2.0) |
Apple VisionOS 2.0
|
NIST, macOS Security Compliance Project
|
07/09/2025 |
ZIP - visionOS 2.0 Guidance, Revision 2.0
|
| Sonoma Guidance (Revision 4.0) |
Apple macOS 14.0
|
NIST, macOS Security Compliance Project
|
07/09/2025 |
SCAP 1.3 Content - Sonoma Guidance, Revision 4.0
|
| Ventura Guidance (Revision 6.0) |
Apple macOS 13.0 (Ventura)
|
NIST, macOS Security Compliance Project
|
07/09/2025 |
SCAP 1.3 Content - Ventura Guidance, Revision 6.0
|
| iOS/iPadOS 17 Guidance (Revision 4.0) |
Apple iOS 17.0
|
NIST, macOS Security Compliance Project
|
07/09/2025 |
ZIP - iOS/iPadOS 17 Guidance, Revision 4
|
* This checklist is still undergoing review for
inclusion into the NCP.