Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status
NVD contains:

Last updated: 9/1/2014 7:41:14 PM

CVE Publication rate: 13.23

Email List

NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index
Vulnerability Workload Index: 5.82
About Us
NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security's National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).

National Checklist Program Repository

 

The National Checklist Program (NCP), defined by the NIST SP 800-70 Rev. 2, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications. NCP is migrating its repository of checklists to conform to the Security Content Automation Protocol (SCAP). SCAP enables standards based security tools to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.

Search for Checklist using the fields below. The keyword search will search across the name, and summary.


There are 248 matching records. Displaying matches 21 through 40.
Tier Target Product Product Category Authority Publication Date Checklist Name (Version) Resources
III*
  • Microsoft Internet Explorer 9
  • Web Browser
Defense Information Systems Agency 07/27/2012 Internet Explorer 9 STIG (Version 1, Release 9)
III
  • Microsoft Office SharePoint Server 2007
  • Enterprise Application
National Security Agency, MITRE 06/15/2011 SharePoint Server 2007 Security Guide (1.0)
III
  • Microsoft Windows 2000
  • Operating System
Defense Information Systems Agency 08/27/2010 Windows 2000 Security Checklist (Version 6, Release 1.19)
III
  • Microsoft Windows 7
  • Operating System
Defense Information Systems Agency 04/26/2010 Microsoft Windows 7 (Version 1, Release 22)
III
  • Microsoft Windows 8 x86 (32-bit)
  • Microsoft Windows 8 x64 (64-bit)
  • Operating System
Defense Information Systems Agency 02/15/2013 Windows 8 STIG (Version 1, Release 7)
III
  • Microsoft Windows Server 2003
  • Microsoft Windows Server 2003 Service Pack 2
  • Microsoft Windows Server 2003 Service Pack 3
  • Microsoft Windows Server 2003 Service Pack 1
  • Operating System
Defense Information Systems Agency 07/27/2012 Windows 2003 DC STIG Benchmark (Version 6, Release 1.36)
III
  • Microsoft Windows Server 2003
  • Microsoft Windows Server 2003 Service Pack 2
  • Microsoft Windows Server 2003 Service Pack 3
  • Microsoft Windows Server 2003 Service Pack 1
  • Operating System
Defense Information Systems Agency 07/27/2012 Windows 2003 MS STIG Benchmark (Version 6, Release 1.36)
III*
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2008 r2 Itanium
  • Microsoft Windows Server 2008 r2 x64
  • Microsoft Windows Server 2008 R2 Service Pack 1
  • Microsoft Windows Server 2008 r2 Service Pack 1 Itanium
  • Microsoft Windows Server 2008 r2 x64 Service Pack 1
  • Operating System
Defense Information Systems Agency 07/27/2012 Microsoft Windows 2008 R2 STIG (Version 1, Release 14)
III*
  • Microsoft Windows Server 2012
  • Operating System
Defense Information Systems Agency 06/04/2014 Windows 2012 (Version 1, Release 2)
III
  • Microsoft Windows XP
  • Operating System
Defense Information Systems Agency 07/27/2012 Windows XP STIG (Version 6, Release 1.34)
III
  • Microsoft Windows XP
  • Operating System
NIST, Computer Security Division 09/30/2007 NIST SP 800-68 (R1.2.0)
III
  • Oracle Weblogic Server
  • Web Server
National Security Agency, MITRE 06/15/2011 Oracle Weblogic Server (11G)
III*
  • Red Hat Enterprise Linux 5
  • Operating System
Defense Information Systems Agency 06/03/2012 Red Hat 5 STIG (Version 1, Release 8)
III
  • Red Hat Enterprise Linux 5
  • Operating System
Department of Defense 09/23/2010 DoD Consensus Security Configuration Checklist for Red Hat Enterprise Linux 5 (2.0)
III
  • Red Hat Enterprise Linux 6
  • Operating System
Defense Information Systems Agency 05/29/2013 Red Hat 6 STIG (Version 1, Release 4)
III
  • Sun Solaris 10 SPARC
  • Sun Solaris 10
  • Operating System
Defense Information Systems Agency 06/04/2012 Solaris 10 (Version 1, Release 7)
III
  • Sun Solaris 9 SPARC
  • Sun Solaris 9
  • Operating System
Defense Information Systems Agency 05/26/2010 Solaris 9 (Version 1, Release 5)
III
  • Microsoft Internet Explorer 10
  • Web Browser
Microsoft Corporation 03/28/2013 Microsoft Security Compliance Manager Internet Explorer 10 (1.0)
III
  • Microsoft Internet Explorer 8
  • Web Browser
Microsoft Corporation 02/23/2011 Microsoft Security Compliance Manager - Internet Explorer 8 (1.0)
III
  • Microsoft Internet Explorer 9
  • Web Browser
Microsoft Corporation 10/19/2011 Microsoft Security Compliance Manager Internet Explorer 9 (1.0)
* This checklist is still undergoing review for inclusion into the NCP at this tier ranking.