U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 631 matching records. Displaying matches 161 through 180.

Name (Version) Target Authority Last Modified Resources
SPEC Innovations Innoslate 4.x STIG (Ver 1, Rel 1) SPEC Innovations Innoslate 4.x STIG
Defense Information Systems Agency
11/15/2022 Standalone XCCDF 1.1.4 - SPEC Innovations Innoslate 4.x STIG - Ver 1, Rel 1
McAfee Application Control STIG (Ver 2, Rel 1) McAfee Application Control 7.0.0
Defense Information Systems Agency
11/07/2022 Standalone XCCDF 1.1.4 - McAfee Application Control 7.x STIG - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - McAfee Application Control 8.x STIG - Ver 2, Rel 1
Palo Alto Networks Intrusion Detection and Prevention System (IDPS) STIG (Y22M10) Palo Alto Networks Intrusion Detection and Prevention System
Defense Information Systems Agency
10/31/2022 Standalone XCCDF 1.1.4 - Palo Alto Networks STIG
Palo Alto Networks Network Device Management (NDM) STIG (Y22M10) Palo Alto Networks Network Device Management (NDM)
Defense Information Systems Agency
10/28/2022 Standalone XCCDF 1.1.4 - Palo Alto Networks STIG
Apple OS/iPad OS 14 STIG (Ver 1, Rel 3) Apple iPad OS/iOS 14.0
Defense Information Systems Agency
10/28/2022 Standalone XCCDF 1.1.4 - Sunset - Apple iOS/iPadOS 14 STIG - Ver 1, Rel 3
Google Android 9.x STIG (Ver 2 Rel 1) Google Android 10.0
Defense Information Systems Agency
10/28/2022 Standalone XCCDF 1.1.4 - Sunset - Google Android 9 STIG - Ver 2, Rel 1
Palo Alto Networks Application Layer Gateway (ALG) STIG (M22Y10) Palo Alto Networks Application Layer Gateway (ALG)
Defense Information Systems Agency
10/28/2022 Standalone XCCDF 1.1.4 - Palo Alto Networks STIG
Apple iOS 12 STIG (Ver 2, Rel 1) Apple iOS 12
Defense Information Systems Agency
10/28/2022 Standalone XCCDF 1.1.4 - Sunset - Apple iOS 12 STIG - Ver 2, Rel 1
Juniper SRX Services Gateway (SG) STIG (Y22M10) Juniper SRX Services Gateway (SG)
Defense Information Systems Agency
10/27/2022 Standalone XCCDF 1.1.4 - Juniper SRX SG STIG for Ansible - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Juniper SRX Services Gateway STIG
IBM WebSphere Liberty Server STIG (Ver 1 Rel 2) IBM WebSphere Liberty Server
Defense Information Systems Agency
10/27/2022 Standalone XCCDF 1.1.4 - IBM WebSphere Liberty Server STIG - Ver 1, Rel 2
McAfee Antivirus 8.8 STIG (Version 6, Release 1) Mcafee Virusscan Enterprise 8.8.0
Defense Information Systems Agency
10/27/2022 SCAP 1.2 Content - Sunset - McAfee VirusScan 8.8 Local Client STIG Benchmark - Version 1, Release 4
SCAP 1.2 Content - Sunset-McAfee VirusScan 8.8 Managed Client STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Sunset - McAfee VirusScan 8.8 Local Client STIG - Ver 6, Rel 1
Standalone XCCDF 1.1.4 - Sunset - McAfee VirusScan 8.8 Managed Client STIG - Ver 6, Rel 1
IBM zVM Using CA VMSecure STIG (Ver 2, Rel 2) IBM zVM Using CA VMSecure
Defense Information Systems Agency
10/27/2022 Standalone XCCDF 1.1.4 - IBM zVM Using CA VMSecure STIG - Ver 2, Rel 2
MongoDB Enterprise Advanced 4.x STIG (Ver 1, Rel 2) MongoDB 4.0
Defense Information Systems Agency
10/27/2022 Standalone XCCDF 1.1.4 - MongoDB Enterprise Advanced 4.x STIG - Ver 1, Rel 2
MarkLogic Server v9 STIG (Ver 2, Rel 1) MarkLogic Server v9
Defense Information Systems Agency
10/27/2022 Standalone XCCDF 1.1.4 - MarkLogic Server v9 STIG - Ver 2, Rel 1
CA IDMS STIG (Ver 1, Rel 1) Broadcom CA IDMS
Defense Information Systems Agency
10/27/2022 Standalone XCCDF 1.1.4 - CA IDMS STIG - Ver 1, Rel 2
Motorola Android 9.x STIG (Y22M10) Google Android 9.x
Defense Information Systems Agency
10/27/2022 Standalone XCCDF 1.1.4 - Sunset - Motorola Android 9 STIG
Microsoft SQL Server 2014 STIG (Y22M10) Microsoft SQL Server 2014
Defense Information Systems Agency
10/26/2022 Standalone XCCDF 1.1.4 - MS SQL Server 2014 STIG
Redis Enterprise 6.x STIG (Ver 1, Rel 2) Redis Enterprise 6.0
Defense Information Systems Agency
10/26/2022 Standalone XCCDF 1.1.4 - Redis Enterprise 6.x STIG - Ver 1, Rel 2
Zebra Android 10 STIG (Y22M10) Google Android 10.0
Defense Information Systems Agency
10/26/2022 Standalone XCCDF 1.1.4 - Sunset - Zebra Android 10 STIG
Sunset - Video Services Policy STIG (Version 1, Release 12) PolyCom CMA 5000
Defense Information Systems Agency
10/14/2022 Standalone XCCDF 1.1.4 - Sunset - Video Services Policy STIG - Ver 1, Rel 12
* This checklist is still undergoing review for inclusion into the NCP.