Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 558 matching records. Displaying matches 21 through 40.

Name (Version) Target Authority Last Modified Resources
Red Hat 6 STIG (Version 2, Release 2) Red Hat Enterprise Linux 6
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Sunset - Red Hat Enterprise Linux 6 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4.2 RHEL 6 i686
Automated Content - SCC 5.4.2 RHEL 6 x86 64
Automated Content - SCC 5.4.2 RHEL 7/Oracle Linux 7/SLES12 x86 64
Automated Content - SCC 5.4.2 RHEL 8 x86 64
Standalone XCCDF 1.1.4 - Sunset - Red Hat Enterprise Linux 6 STIG - Ver 2, Rel 2
Microsoft Windows Defender Antivirus STIG (Ver 2, Rel 2) Microsoft Windows Defender
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Microsoft Windows Defender Antivirus STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Microsoft Windows Defender Antivirus STIG - Ver 2, Rel 2
Microsoft .NET Framework 4 (Version 2, Release 1) Microsoft .NET Framework 4.0
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Microsoft .Net Framework 4 STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.4.2 Windows
Standalone XCCDF 1.1.4 - Microsoft .Net Framework 4.0 STIG - Ver 2, Rel 1
McAfee Antivirus 8.8 STIG (Version 5, Release 21) Mcafee Virusscan Enterprise 8.8.0
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - McAfee VirusScan 8.8 Local Client STIG Benchmark - Ver 1, Rel 3
SCAP 1.2 Content - McAfee VirusScan 8.8 Managed Client STIG Benchmark - Ver 1, Rel 3
Automated Content - SCC 5.4.2 Windows
Standalone XCCDF 1.1.4 - McAfee Virus Scan 8.8 Local Client STIG - Ver 5, Rel 16
Standalone XCCDF 1.1.4 - McAfee VirusScan 8.8 Managed Client STIG - Ver 5, Rel 21
Mozilla Firefox STIG (Version 5, Release 3) Mozilla Firefox
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Mozilla Firefox STIG for RHEL Benchmark - Ver 5, Rel 3
SCAP 1.2 Content - Mozilla Firefox STIG for Windows Benchmark - Ver 5, Rel 3
Automated Content - SCC 5.4.2 Windows
Automated Content - SCC 5.4.2 RHEL 6 i686
Automated Content - SCC 5.4.2 RHEL 6 x86 64
Automated Content - SCC 5.4.2 RHEL 7/Oracle Linux 7/SLES12 x86 64
Automated Content - SCC 5.4.2 RHEL 8 x86 64
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 5, Rel 2
ZIP - Mozilla Firefox STIG Configuration Files - Ver 5, Rel 1
Internet Explorer 11 STIG (Version 1, Release 19) Microsoft Internet Explorer 11
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - MS Internet Explorer 11 STIG Benchmark - Ver 1, Rel 16
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Microsoft Internet Explorer 11 STIG - Ver 1, Rel 19
Google Chrome Browser STIG for Windows (Version 2, Release 4) Google Chrome 33
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Google Chrome Current Windows STIG Benchmark - Ver 2, Rel 4
Automated Content - SCC 5.4.2 Windows
GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Google Chrome STIG - Ver 2, Rel 4
Solaris 10 (SPARC and x86) Manual STIG (Version 2, Release 2) Oracle Solaris 10.0
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Solaris 10 SPARC STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Solaris 10 x86 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4.2 Solaris 10 i386
Automated Content - SCC 5.4.2 Solaris 10 SPARC
Automated Content - SCC 5.4.2 Solaris 11 i386
Automated Content - SCC 5.4.2 Solaris 11 SPARC
Standalone XCCDF 1.1.4 - Solaris 10 SPARC STIG - Ver 2, Rel 2
Standalone XCCDF 1.1.4 - Solaris 10 X86 STIG - Ver 2, Rel 2
Solaris 11 (SPARC and x86) Manual STIG (Version 2, Release 4) Sun Solaris
Defense Information Systems Agency
09/16/2021 SCAP 1.2 Content - Solaris 11 SPARC STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Solaris 11 X86 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.4.2 Solaris 10 i386
Automated Content - SCC 5.4.2 Solaris 10 SPARC
Automated Content - SCC 5.4.2 Solaris 11 i386
Automated Content - SCC 5.4.2 Solaris 11 SPARC
Standalone XCCDF 1.1.4 - Solaris 11 SPARC STIG - Ver 2, Rel 4
Standalone XCCDF 1.1.4 - Solaris 11 x86 STIG - Ver 2, Rel 4
VMware ESX 3 Server STIG (Ver 1, Rel 2) VMware ESX Server 3.0.0
Defense Information Systems Agency
08/30/2021 Standalone XCCDF 1.1.4 - Sunset - VMWare ESX 3 Policy STIG - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Sunset - VMware ESX 3 Server STIG - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Sunset - VMware ESX 3 Virtual Center STIG - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Sunset - VMware ESX 3 Virtual Machine STIG - Ver 1, Rel 2
Adobe Acrobat Professional DC Continuous Track STIG (Ver 2, Rel 1) Adobe Acrobat Pro DC Continuous Track
Defense Information Systems Agency
08/24/2021 GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Adobe Acrobat Professional DC Continuous Track STIG - Ver 2, Rel 1
Microsoft Office System 2016 STIG (Version 2, Release 1) Microsoft Office 2016
Defense Information Systems Agency
08/24/2021 GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Microsoft Office System 2016 STIG - Ver 2, Rel 1
Microsoft Office System 2013 STIG (Version 2, Release 1) Office System 2013
Defense Information Systems Agency
08/24/2021 GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Microsoft Office System 2013 STIG - Ver 2, Rel 1
Microsoft Office 365 ProPlus STIG (Ver 2, Rel 3) Microsoft Office 365 ProPlus
Defense Information Systems Agency
08/24/2021 GPOs - Group Policy Objects (GPOs) - July 2021
Standalone XCCDF 1.1.4 - Microsoft Office 365 ProPlus STIG - Ver 2, Rel 3
Cisco IOS Router STIG (Version 2, Release 1) Cisco IOS
Defense Information Systems Agency
08/19/2021 SCAP 1.3 Content - Cisco IOS-XE Router NDM STIG Benchmark - Ver 1, Rel 1
SCAP 1.3 Content - Cisco IOS-XE Router RTR STIG Benchmark - Ver 1, Rel 1
Machine-Readable Format - Cisco IOS XE Router STIG for Ansible - Ver 2, Rel 1
Standalone XCCDF 1.1.4 - Cisco IOS-XE Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS-XR Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS Router STIG
NIST National Checklist for Red Hat Enterprise Linux 8.x (content v0.1.50) Red Hat Enterprise Linux 8.0
Red Hat Enterprise Linux 8.1
Red Hat Enterprise Linux 8.2
Red Hat
08/18/2021 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 8.x
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for RHEL 8.x
Ansible Playbook - PCI-DSS
NIST National Checklist for Red Hat Enterprise Linux 7.x (content v0.1.50) Red Hat Enterprise Linux 7.0
Red Hat Enterprise Linux 7.1
Red Hat Enterprise Linux 7.2
Red Hat Enterprise Linux 7.3
Red Hat Enterprise Linux 7.4
Red Hat Enterprise Linux 7.5
Red Hat Enterprise Linux 7.6
Red Hat Enterprise Linux 7.7
Red Hat
08/18/2021 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 7.x, SCAP 1.3
Ansible Playbook - CIA Commercial Cloud Services (CIA C2S)
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for Red Hat Enterprise Linux 7.x
Ansible Playbook - PCI-DSS
Ansible Playbook - DoD STIG
Splunk Enterprise 7.x for Windows STIG (Ver 2, Rel 3) Splunk Enterprise 7.0
Defense Information Systems Agency
08/10/2021 Standalone XCCDF 1.1.4 - Splunk Enterprise 7.x for Windows STIG - Ver 2, Rel 3
Vanguard Compliance Manager z/OS RACF ACF2 TSS Checklist for completing a manual SRR Audit for Stig (6.43) IBM z/OS Version 2, Release 2
IBM z/OS Version 2, Release 3
IBM z/OS Version 2, Release 4
Vanguard Integrity Professionals, Inc.
08/06/2021 ZIP - Vanguard z/OS RACF Checklist 6.43 PDF version
ZIP - Vanguard z/OS RACF Checklist 6.43 XML version
ZIP - Vanguard z/OS RACF Checklist 6.43 PDF version for ACF2
ZIP - Vanguard z/OS RACF Checklist 6.43 PDF version for TSS
ZIP - Vanguard z/OS RACF Checklist 6.43 XML version for ACF2
ZIP - Vanguard z/OS RACF Checklist 6.43 XML version for TSS
zOS TSS STIG (Version 6, Release 50) IBM OS390
Defense Information Systems Agency
08/06/2021 Standalone XCCDF 1.1.4 - IBM zOS STIG
Standalone XCCDF 1.1.4 - z/OS TSS Products - Ver 6, Rel 50
* This checklist is still undergoing review for inclusion into the NCP.