U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 610 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
CIS IBM z/OS V2R5 with RACF Benchmark (v1.0.0) IBM RACF
IBM z/OS
IBM Corporation
03/20/2023 Prose - CIS IBM z/OS V2R5 with RACF Benchmark
CIS IBM Db2 13 for z/OS Benchmark (V1.0.0) IBM Db2 13.0 for z/OS
IBM Corporation
03/20/2023 Prose - CIS IBM Db2 13 for z/OS Benchmark v1.0.0
Riverbed NetProfiler STIG (Ver 1, Rel 1) Riverbed NetProfiler
Defense Information Systems Agency
03/20/2023 Standalone XCCDF 1.1.4 - Riverbed NetProfiler STIG - Ver 1, Rel 1
Arista MLS EOS 4.2x STIG (Y23M02) Arista Multi-Layer Switch Extensible Operating System (MLS EOS) 4.2
Defense Information Systems Agency
03/20/2023 Standalone XCCDF 1.1.4 - Arista MLS EOS 4.2x STIG
VMware vSphere 7.0 STIG (Y23M03) VMware vSphere 7.0
Defense Information Systems Agency
03/20/2023 Standalone XCCDF 1.1.4 - VMware vSphere 7.0 STIG
Windows Server 2022 STIG with Ansible (Ver 1, Rel 1) Microsoft Windows Server 2022
Defense Information Systems Agency
03/13/2023 Standalone XCCDF 1.1.4 - Windows Server 2022 STIG with Ansible - Ver 1, Rel 1
AvePoint Compliance Guardian STIG (Ver 1, Rel 1) AvePoint Compliance Guardian
Defense Information Systems Agency
03/09/2023 Standalone XCCDF 1.1.4 - AvePoint Compliance Guardian STIG - Ver 1, Rel 1
Adobe Acrobat Reader DC Continuous Track STIG (Ver 2, Rel 2) Adobe Acrobat Reader
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Adobe Acrobat Reader DC Continuous Track STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - January 2023
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Continuous Track STIG - Ver 2, Rel 1
Red Hat 8 STIG (Ver 1, Rel 9) Red Hat Enterprise Linux 8.0
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Red Hat Enterprise Linux 8 STIG Benchmark - Ver 1, Rel 8
Automated Content - SCC 5.7.1 RHEL 6 i686
Automated Content - SCC 5.7.1 RHEL 6 x86 64
Automated Content - SCC 5.7.1 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.7.1 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 8 STIG - Ver 1, Rel 9
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 8 STIG for Ansible - Ver 1, Rel 9
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 8 STIG for Chef - Ver 1, Rel 9
Mozilla Firefox STIG (Version 6, Release 3) Mozilla Firefox
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Mozilla Firefox for Linux STIG Benchmark - Ver 6, Rel 3
SCAP 1.2 Content - Mozilla Firefox for Windows STIG Benchmark - Ver 6, Rel 3
Automated Content - SCC 5.7.1 Windows
Automated Content - SCC 5.7.1 RHEL 6 i686
Automated Content - SCC 5.7.1 RHEL 6 x86 64
Automated Content - SCC 5.7.1 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.7.1 RHEL 9/Oracle Linux 9 x86 64
GPOs - Group Policy Objects (GPOs) - January 2023
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 6, Rel 4
Canonical Ubuntu 18.04 LTS for Ansible (Version 2, Release 10) Canonical Ubuntu 18.04 LTS for Ansible
Defense Information Systems Agency
03/09/2023 Automated Content - SCC 5.7.1 Ubuntu 16 AMD64
Automated Content - SCC 5.7.1 Ubuntu 16 i686
Automated Content - SCC 5.7.1 Ubuntu 18 AMD64
Automated Content - SCC 5.7.1 Ubuntu 20/Raspios-bulleye Aarch64
Standalone XCCDF 1.1.4 - Canonical Ubuntu 18.04 LTS STIG for Ansible - Ver 2, Rel 10
Apple macOS 11 STIG (Ver 1, Rel 7) Apple macOS 11.0 (Big Sur)
Defense Information Systems Agency
03/09/2023 Automated Content - SCC 5.7.1 Mac OS X x86 64
Standalone XCCDF 1.1.4 - Apple macOS 11 (Big Sur) STIG - Ver 1, Rel 7
Red Hat 6 STIG (Version 2, Release 2) Red Hat Enterprise Linux 6
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Sunset - Red Hat Enterprise Linux 6 STIG Benchmark - Ver 2, Rel 2
Automated Content - SCC 5.7.1 RHEL 6 i686
Automated Content - SCC 5.7.1 RHEL 6 x86 64
Automated Content - SCC 5.7.1 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.7.1 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - Sunset - Red Hat Enterprise Linux 6 STIG - Ver 2, Rel 2
Oracle Linux 7 STIG (Ver 2, Rel 10) Oracle Linux 7
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Oracle Linux 7 STIG Benchmark- Ver 2, Rel 10
Automated Content - SCC 5.7.1 RHEL 6 i686
Automated Content - SCC 5.7.1 RHEL 6 x86 64
Automated Content - SCC 5.7.1 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.7.1 RHEL 9/Oracle Linux 9 x86 64
Standalone XCCDF 1.1.4 - Oracle Linux 7 STIG - Ver 2, Rel 10
Google Chrome Browser STIG for Windows (Version 2, Release 8) Google Chrome 33
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Google Chrome STIG Benchmark - Ver 2, Rel 8
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - January 2023
Standalone XCCDF 1.1.4 - Google Chrome STIG - Ver 2, Rel 8
Microsoft Windows 2012 and 2012 R2 DC STIG (Ver 3, Rel 5) Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark - Ver 3, Rel 4
SCAP 1.2 Content - Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark - Ver 3, Rel 4
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - January 2023
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 DC STIG- Ver 3, Rel 5
Standalone XCCDF 1.1.4 - Microsoft Windows 2012 and 2012 R2 MS STIG - Ver 3, Rel 5
Windows Firewall STIG and Advanced Security STIG (Ver 2, Rel 1) windows firewall
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Microsoft Windows Firewall STIG Benchmark - Ver 2, Rel 1
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - January 2023
Standalone XCCDF 1.1.4 - Microsoft Windows Firewall STIG and Advanced Security STIG - Ver 2, Rel 1
Microsoft Windows Server 2019 (Ver 2, Rel 5) Microsoft Windows Server 2019
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Microsoft Windows Server 2019 STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - January 2023
Machine-Readable Format - Microsoft Windows Server 2019 STIG for Chef - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2019 STIG - Ver 2, Rel 5
Microsoft Windows Server 2016 STIG (Version 2, Release 5) Microsoft Windows Server 2016
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 2, Rel 3
Automated Content - SCC 5.7.1 Windows
GPOs - Group Policy Objects (GPOs) - January 2023
Machine-Readable Format - Microsoft Windows Server 2016 STIG for Chef - Ver 1, Rel 3
Machine-Readable Format - Microsoft Windows Server 2016 STIG for PowerShell DSC - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 2, Rel 5
Red Hat 7 STIG (Ver 3, Rel 10) Red Hat Enterprise Linux 7.0
Defense Information Systems Agency
03/09/2023 SCAP 1.2 Content - Red Hat Enterprise Linux 7 STIG Benchmark - Ver 3, Rel 10
Automated Content - SCC 5.7.1 RHEL 6 i686
Automated Content - SCC 5.7.1 RHEL 6 x86 64
Automated Content - SCC 5.7.1 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.7.1 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.7.1 RHEL 9/Oracle Linux 9 x86 64
Machine-Readable Format - Red Hat Enterprise Linux 7 STIG for Ansible - Ver 3, Rel 10
Machine-Readable Format - Red Hat Enterprise Linux 7 STIG for Chef - Ver 3, Rel 8
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 7 STIG - Ver 3, Rel 10
* This checklist is still undergoing review for inclusion into the NCP.