U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 868 matching records. Displaying matches 281 through 300.

Name (Version) Target Authority Last Modified Resources
CA IDMS STIG (Ver 2, Rel 1) Broadcom CA IDMS
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - CA IDMS STIG - Ver 2, Rel 1
ISEC7 Sphere STIG (Ver 3, Rel 1) iSEC7 Enterprise Mobility Management 6.0
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - ISEC7 Sphere STIG - Ver 3, Rel 1
IBM AIX 7.X STIG (Ver 3, Rel 1) IBM AIX 7.1
IBM AIX 7.2
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - IBM AIX 7.x STIG - Ver 3, Rel 1
IBM Hardware Management Console (HMC) STIG (Ver 2, Rel 1) IBM z/OS Version 1 Release 10
IBM z/OS Version 1 Release 11
IBM z/OS Version 1 Release 12
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - IBM Hardware Management Console (HMC) STIG - Ver 2, Rel 1
Active Directory Domain STIG (Ver 3, Rel 5) Microsoft Active Directory
Defense Information Systems Agency
11/05/2024 Standalone XCCDF 1.1.4 - Active Directory Domain STIG - Ver 3, Rel 5
Redis Enterprise 6.x STIG (Ver 2, Rel 2) Redis Enterprise 6.0
Defense Information Systems Agency
11/04/2024 Standalone XCCDF 1.1.4 - Redis Enterprise 6.x STIG - Ver 2, Rel 2
Oracle MySQL 8.0 STIG (Ver 2, Rel 2) Oracle MySQL 8.0
Defense Information Systems Agency
11/04/2024 Standalone XCCDF 1.1.4 - Oracle MySQL 8.0 STIG - Ver 2, Rel 2
CIS MariaDB 10.6 Benchmark (1.1.0) MariaDB Enterprise Server 10.x
Center for Internet Security (CIS)
11/04/2024 Prose - CIS MariaDB 10.6 Benchmark v1.1.0
CIS Microsoft SQL Server 2019 (1.4.0) Microsoft SQL Server 2019
Center for Internet Security (CIS)
11/04/2024 Prose - CIS Microsoft SQL Server 2019 Benchmark v1.4.0
CIS MariaDB 10.11 Benchmark (1.0.0) MariaDB Enterprise Server 10.x
Center for Internet Security (CIS)
11/04/2024 Prose - CIS MariaDB 10.11 Benchmark v1.0.0
Cisco ISE STIG (Y24M10) Cisco Identity Services Engine
Defense Information Systems Agency
10/29/2024 Standalone XCCDF 1.1.4 - Cisco ISE STIG
Crunchy Data Postgres 16 STIG (Ver 1, Rel 1) Crunchy Data Crunchy Postgres 16.0
Crunchy Data Crunchy Postgres 16.1
Crunchy Data Crunchy Postgres 16.2
Crunchy Data Crunchy Postgres 16.3
Crunchy Data Crunchy Postgres 16.4
Defense Information Systems Agency
10/16/2024 Standalone XCCDF 1.1.4 - Crunchy Data Postgres 16 STIG - Ver 1, Rel 1
CIS Microsoft Azure Database Services Benchmark (1.0.0) Microsoft Azure
Center for Internet Security (CIS)
10/01/2024 Prose - CIS Microsoft Azure Database Services Benchmark v1.0.0
Palo Alto Networks STIG for Ansible (Ver 1, Rel 4) Palo Alto Networks Network Device Management (NDM)
Defense Information Systems Agency
09/24/2024 Standalone XCCDF 1.1.4 - Palo Alto Networks STIG for Ansible - Ver 1, Rel 4
OpenShift 3.x on Azure for Government (FedRAMP Moderate) (v1) Red Hat OpenShift Container Platform 3.10
Red Hat OpenShift Container Platform 3.11
Red Hat OpenShift Container Platform 3.5
Red Hat OpenShift Container Platform 3.6
Red Hat OpenShift Container Platform 3.7
Red Hat OpenShift Container Platform 3.8
Red Hat OpenShift Container Platform 3.9
Red Hat
09/06/2024 Security Template - Ansible Playbooks supporting the creation of either a multi-node full HA production cluster or a single node designed for exploration of OpenShift on Azure.
Prose - Deploying Red Hat OpenShift Container Platform 3 on Microsoft Azure
Vanguard Compliance Manager z/OS RACF Checklist for completing a manual SRR Audit for Stig (6.60-14) IBM z/OS Version 2, Release 4
IBM z/OS Version 2, Release 5
Vanguard Integrity Professionals, Inc.
09/05/2024 ZIP - Vanguard z/OS RACF Checklist 6.60/14 PDF Version
ZIP - Vanguard z/OS RACF Checklist 6.60/14 XML version
NIST National Checklist for Red Hat Enterprise Linux 7.x (content v0.1.50) Red Hat Enterprise Linux 7.0
Red Hat Enterprise Linux 7.1
Red Hat Enterprise Linux 7.2
Red Hat Enterprise Linux 7.3
Red Hat Enterprise Linux 7.4
Red Hat Enterprise Linux 7.5
Red Hat Enterprise Linux 7.6
Red Hat Enterprise Linux 7.7
Red Hat
08/30/2024 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 7.x, SCAP 1.3
Ansible Playbook - CIA Commercial Cloud Services (CIA C2S)
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for Red Hat Enterprise Linux 7.x
Ansible Playbook - PCI-DSS
Ansible Playbook - DoD STIG
NIST National Checklist for HyperSphere Technologies (0.1) Hypersphere Technologies Vault 1.0
Mission IT
08/30/2024 Machine-Readable Format - OpenControl content for HyperSphere Technologies
NIST National Checklist for Red Hat Enterprise Linux 8.x (content v0.1.50) Red Hat Enterprise Linux 8.0
Red Hat Enterprise Linux 8.1
Red Hat Enterprise Linux 8.2
Red Hat
08/30/2024 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 8.x
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for RHEL 8.x
Ansible Playbook - PCI-DSS
FedRAMP Low for Red Hat Ansible Tower 3.2.x (v1) Red Hat Ansible Tower 3.2.0
Red Hat Ansible Tower 3.2.1
Red Hat Ansible Tower 3.2.2
Red Hat Ansible Tower 3.2.3
Red Hat Ansible Tower 3.2.4
Red Hat Ansible Tower 3.2.5
Red Hat Ansible Tower 3.2.6
Red Hat
08/27/2024 Security Template - NIST 800-53 Control Applicability Guide for Red Hat Ansible Tower 3.2.x
Security Template - FedRAMP Template for Red Hat Ansible Tower 3.x
Prose - Section 508 Voluntary Product Accessibility Template (VPAT) and Web Content Accessibility Guidelines (WCAG) 2.0 for Ansible Tower
* This checklist is still undergoing review for inclusion into the NCP.