U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 805 matching records. Displaying matches 21 through 40.

Name (Version) Target Authority Last Modified Resources
Apple macOS (Sonoma) 14 STIG (Ver 2, Rel 2) Apple macOS 14.0
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Apple macOS 14 (Sonoma) STIG - Ver 2, Rel 2
ISEC7 Sphere STIG (Ver 3, Rel 1) iSEC7 Enterprise Mobility Management 6.0
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - ISEC7 Sphere STIG - Ver 3, Rel 1
Active Directory Forest STIG (Ver 2, Rel 8) Microsoft Active Directory
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Active Directory Forest STIG - Ver 3, Rel 1
Canonical Ubuntu 22.04 LTS STIG (Ver 2, Rel 2) Canonical Ubuntu 22.04 LTS
Defense Information Systems Agency
11/05/2024 Automated Content - SCC 5.10 Ubuntu 22 AMD64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 22.04 LTS STIG - Ver 2, Rel 2
IBM AIX 7.X STIG (Ver 3, Rel 1) IBM AIX 7.1
IBM AIX 7.2
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - IBM AIX 7.x STIG - Ver 3, Rel 1
IBM WebSphere Liberty Server STIG (Ver 2, Rel 1) IBM WebSphere Liberty Server
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - IBM WebSphere Liberty Server STIG - Ver 2, Rel 1
IBM Hardware Management Console (HMC) STIG (Ver 2, Rel 1) IBM z/OS Version 1 Release 10
IBM z/OS Version 1 Release 11
IBM z/OS Version 1 Release 12
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - IBM Hardware Management Console (HMC) STIG - Ver 2, Rel 1
Active Directory Domain STIG (Ver 3, Rel 5) Microsoft Active Directory
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Active Directory Domain STIG - Ver 3, Rel 5
Suse Linux Enterprise Server (SLES) 15 STIG (Version 2, Release 2) SUSE Enterprise Linux 15
Defense Information Systems Agency
11/05/2024 SCAP 1.3 Content - SUSE Linux Enterprise Server 15 STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - SUSE Linux Enterprise Server 15 STIG Benchmark - Ver 1, Rel 6
Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Server 15 STIG - Ver 2, Rel 2
Microsoft Windows Server 2022 (Ver 2, Rel 2) Microsoft Windows Server 2022
Defense Information Systems Agency
11/05/2024 SCAP 1.3 Content - Microsoft Windows Server 2022 STIG SCAP Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Microsoft Windows Server 2022 STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG for Chef - Ver 1, Rel 1
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2022 STIG - Ver 2, Rel 2
Solaris 11 (SPARC and x86) Manual STIG (Ver 3, Rel 2) Sun Solaris
Defense Information Systems Agency
11/05/2024 SCAP 1.3 Content - Solaris 11 SPARC STIG Benchmark - Ver 3, Rel 2
SCAP 1.3 Content - Solaris 11 x86 STIG Benchmark - Ver 3, Rel 2
SCAP 1.2 Content - Sunset - Solaris 11 SPARC STIG Benchmark - Ver 2, Rel 4
SCAP 1.2 Content - Sunset - Solaris 11 X86 STIG Benchmark - Ver 2, Rel 4
Automated Content - SCC 5.10 Solaris 11 i386
Automated Content - SCC 5.10 Solaris 11 SPARC
Standalone XCCDF 1.1.4 - Solaris 11 SPARC STIG - Ver 3, Rel 1
Standalone XCCDF 1.1.4 - Solaris 11 x86 STIG - Ver 3, Rel 1
Red Hat 8 STIG (Ver 2, Rel 1) Red Hat Enterprise Linux 8.0
Defense Information Systems Agency
11/04/2024 SCAP 1.3 Content - Red Hat Enterprise Linux 8 STIG Benchmark - Ver 2, Rel 1
SCAP 1.2 Content - Red Hat Enterprise Linux 8 STIG Benchmark - Ver 1, Rel 12
Automated Content - SCC 5.10 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.10 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.10 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.10 RHEL 9 x86 64
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 8 STIG for Ansible - Ver 1, Rel 13
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 8 STIG for Chef - Ver 1, Rel 13
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 8 STIG - Ver 2, Rel 1
Redis Enterprise 6.x STIG (Ver 2, Rel 2) Redis Enterprise 6.0
Defense Information Systems Agency
11/04/2024 Standalone XCCDF 1.1.4 - Redis Enterprise 6.x STIG - Ver 2, Rel 2
Oracle MySQL 8.0 STIG (Ver 2, Rel 2) Oracle MySQL 8.0
Defense Information Systems Agency
11/04/2024 Standalone XCCDF 1.1.4 - Oracle MySQL 8.0 STIG - Ver 2, Rel 2
Red Hat Enterprise Linux 9 (Ver 2, Rel 2) Red Hat Enterprise Linux 9.0
Defense Information Systems Agency
11/04/2024 SCAP 1.3 Content - Red Hat Enterprise Linux 9 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.10 RHEL 9 x86 64
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 9 STIG for Ansible- Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 9 STIG for Chef- Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 9 STIG - Ver 2, Rel 2
Oracle Linux 7 STIG (Ver 3, Rel 1) Oracle Linux 7
Defense Information Systems Agency
11/04/2024 SCAP 1.3 Content - Oracle Linux 7 STIG Benchmark - Ver 3, Rel 1
Standalone XCCDF 1.1.4 - Oracle Linux 7 STIG - Ver 3, Rel 1
Oracle Linux 8 STIG (Ver 2, Rel 2) Oracle Linux 8.0
Defense Information Systems Agency
11/04/2024 SCAP 1.3 Content - Oracle Linux 8 STIG Benchmark - Ver 2, Rel 2
SCAP 1.2 Content - Sunset - Oracle Linux 8 STIG Benchmark - Ver 1, Rel 8
Automated Content - SCC 5.10 RHEL 8/Oracle Linux 8 x86 64
Standalone XCCDF 1.1.4 - Oracle Linux 8 STIG for Ansible - Ver 1, Rel 9
Standalone XCCDF 1.1.4 - Oracle Linux 8 STIG - Ver 2, Rel 2
Canonical Ubuntu 20.04 LTS STIG (Ver 2, Rel 1) Canonical Ubuntu 22.04 LTS
Defense Information Systems Agency
11/04/2024 SCAP 1.3 Content - Canonical Ubuntu 20.04 LTS STIG Benchmark - Ver 2, Rel 1
SCAP 1.2 Content - Sunset - Canonical Ubuntu 20.04 LTS STIG Benchmark - Ver 1, Rel 9
Automated Content - SCC 5.10 Ubuntu 18/20 AMD64
Automated Content - SCC 5.10 Ubuntu 20/Raspios-bulleye Aarch64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 20.04 LTS STIG for Ansible - Ver 1, Rel 11
Standalone XCCDF 1.1.4 - Canonical Ubuntu 20.04 LTS STIG - Ver 2, Rel 1
CIS MariaDB 10.6 Benchmark (1.1.0) MariaDB Enterprise Server 10.x
Center for Internet Security (CIS)
11/04/2024 Prose - CIS MariaDB 10.6 Benchmark v1.1.0
visionOS 2.0 Guidance (Revision 1.0) Apple VisionOS 2.0
NIST, macOS Security Compliance Project
11/04/2024 ZIP - visionOS 2.0 Guidance, Revision 1.0
* This checklist is still undergoing review for inclusion into the NCP.