Checklist Repository
The National Checklist Program (NCP), defined by the NIST
SP 800-70, is the U.S. government repository of publicly available
security checklists (or benchmarks) that provide detailed low level
guidance on setting the security configuration of operating systems
and applications.
NCP provides metadata and links to checklists of various formats
including checklists that conform to the Security
Content Automation Protocol (SCAP). SCAP enables validated
security products to automatically perform configuration checking
using NCP checklists. For more information relating to the NCP please
visit the information page or
the glossary of terms.
Search for Checklists using the fields below. The keyword
search will search across the name, and summary.
There are 879
matching records. Displaying matches 161 through 180.
| Name (Version) |
Target |
Authority |
Last Modified |
Resources |
| Apple iOS/iPadOS 16 BYOAD STIG (Ver 1, Rel 1) |
Apple iOS/iPadOS 16
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - Apple iOS/iPadOS 16 BYOAD STIG - Ver 1, Rel 1
|
| Citrix Virtual Apps and Desktops (VAD) 7.x STIG (Version 1, Release 1) |
Citrix StoreFront
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - Citrix Virtual Apps and Desktops (VAD) 7.x STIG
|
| Sunset - Citrix XenDesktop 7.x STIG (1.0) |
Citrix XenDesktop 7.x
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - Citrix XenDesktop 7.x STIG
Standalone XCCDF 1.1.4 - Sunset - Citrix XenDesktop 7.x STIG
|
| Sunset - Splunk Enterprise 8.x for Linux (Ver 2, Rel 3) |
Splunk Enterprise 8.0.0
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - Sunset - Splunk Enterprise 8.x for Linux STIG - Ver 2, Rel 3
Standalone XCCDF 1.1.4 - Splunk Enterprise 8.x for Linux STIG - Ver 2, Rel 2
|
| Sunset - Splunk Enterprise 7.x for Windows STIG (Ver 3, Rel 2) |
Splunk Enterprise 7.0
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - Splunk Enterprise 7.x for Windows STIG - Ver 3, Rel 1
Standalone XCCDF 1.1.4 - Sunset - Splunk Enterprise 7.x for Windows STIG - Ver 3, Rel 2
|
| VMware vSphere 8.0 STIG (Y25M07) |
VMware vSphere 8.0
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - VMware vSphere 8.0 STIG
|
| Microsoft Exchange 2019 STIG (Y25M07) |
Microsoft Exchange Server 2019
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - Microsoft Exchange 2019 STIG
|
| Forescout STIG (Y26M04) |
Forescout Enterprise Manager
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - Forescout STIG
|
| F5 BIG-IP TMOS STIG (Y25M07) |
F5 BIG-IP Access Policy Manager (APM)
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - F5 BIG-IP TMOS STIG
|
| HP FlexFabric Switch Router STIG (Y25M07) |
HP FlexFabric
|
Defense Information Systems Agency
|
08/20/2025 |
Standalone XCCDF 1.1.4 - HP FlexFabric Switch STIG
|
| Alibaba Cloud Foundation (2.0.0) |
Alibaba Cloud
|
Center for Internet Security (CIS)
|
08/13/2025 |
Prose - Alibaba Cloud Foundation, v2.0.0
|
| Microsoft Exchange Online - SCuBA (1.6.0) |
Microsoft Exchange Online
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Exchange Online - GitHub Markdown
Prose - BOD 25-01: Implementation Guidance for Implementing Secure Practices for Cloud Services
Prose - Microsoft Exchange Online
|
| Entra ID - SCuBA (1.6) |
Microsoft Azure Active Directory
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Entra ID - GitHub
Prose - Microsoft Entra ID - SCuBA
|
| Microsoft Power BI - SCuBA (1.6.0) |
Microsoft Power Apps
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Power BI GitHub Mark down
Prose - Microsoft Power BI
|
| Microsoft Defender for Office 365 - SCuBA (1.6.0) |
Microsoft Windows Defender
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Prose - CISA GitHub for ScubaGear - MSFT Defender
Prose - Microsoft Defender for Office 365
|
| Microsoft Power Platform - SCuBA (1.6.0) |
Microsoft Power Apps
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Power Platform - GitHub
Prose - BOD 25-01: Implementation Guidance for Implementing Secure Practices for Cloud Services
Prose - Microsoft Power Platform
|
| SharePoint and OneDrive - SCuBA (1.6.0) |
Microsoft OneDrive Microsoft SharePoint Online
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft SharePoint & OneDrive GitHub
Prose - Microsoft SharePoint & OneDrive
|
| Microsoft Teams - SCuBA (1.6.0) |
Microsoft Teams
|
Cybersecurity and Infrastructure Security Agency (CISA)
|
08/13/2025 |
Machine-Readable Format - Microsoft Teams GitHub
Prose - Microsoft Teams
|
| CIS Cisco Firepower Threat Defense Benchmark (1.0.0) |
Cisco Firepower Threat Defense 6.0.0 Cisco Firepower Threat Defense 7.0.0
|
Center for Internet Security (CIS)
|
08/05/2025 |
Prose - CIS Cisco Firepower Threat Defense Benchmark, v1.0.0
|
| Ubuntu Linux 20.04 LTS Benchmark (3.0.0) |
Canonical Ubuntu 20.04 LTS
|
Center for Internet Security (CIS)
|
08/04/2025 |
Prose - CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0
|
* This checklist is still undergoing review for
inclusion into the NCP.