National Checklist Program Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 518 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
NIST National Checklist for Red Hat Virtualization Host 4.x (content v0.1.48) Red Hat Virtualization Host 4.3
Red Hat
06/30/2020 SCAP 1.3 Content - NIST National Checklist for Red Hat Virtualization Host 4.x
Ansible Playbook - [DRAFT] DISA STIG for Red Hat Virtualization Host (RHVH)
Ansible Playbook - VPP - Protection Profile for Virtualization v. 1.0 for Red Hat Virtualization Hypervisor (RHVH)
Machine-Readable Format - OpenControl-formatted NIST 800-53 responses for Red Hat Virtualization Host 4.x
NIST National Checklist for Red Hat Enterprise Linux 7.x (content v0.1.50) Red Hat Enterprise Linux 7.0
Red Hat Enterprise Linux 7.1
Red Hat Enterprise Linux 7.2
Red Hat Enterprise Linux 7.3
Red Hat Enterprise Linux 7.4
Red Hat Enterprise Linux 7.5
Red Hat Enterprise Linux 7.6
Red Hat Enterprise Linux 7.7
Red Hat
06/30/2020 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 7.x, SCAP 1.3
Ansible Playbook - CIA Commercial Cloud Services (CIA C2S)
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for Red Hat Enterprise Linux 7.x
Ansible Playbook - PCI-DSS
Ansible Playbook - DoD STIG
NIST National Checklist for Red Hat Enterprise Linux 8.x (content v0.1.50) Red Hat Enterprise Linux 8.0
Red Hat Enterprise Linux 8.1
Red Hat Enterprise Linux 8.2
Red Hat
06/30/2020 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 8.x
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for RHEL 8.x
Ansible Playbook - PCI-DSS
Microsoft Office System 2016 STIG (Version 1, Release 4) Microsoft Office 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft Office System 2016 STIG Benchmark - Ver 1, Rel 4
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft Office System 2016 STIG - Ver 1, Rel 1
Microsoft Access 2016 STIG (Version 1, Release 2) Microsoft Access 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft Access 2016 STIG Benchmark - Ver 1, Rel 2
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft Access 2016 STIG - Ver 1, Rel 1
Microsoft OneNote 2016 STIG (Version 1, Release 3) Microsoft OneNote 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft OneNote 2016 STIG Benchmark - Ver 1, Rel 3
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft OneNote 2016 STIG - Ver 1, Rel 2
Microsoft Outlook 2016 STIG (Version 1, Release 4) Microsoft Outlook 2016
Defense Information Systems Agency
08/11/2020 SCAP 1.3 Content - Microsoft Outlook 2016 STIG Benchmark, Ver 1, Rel 4
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft Outlook 2016 STIG - Ver 1, Rel 2
Microsoft PowerPoint 2016 STIG (Version 1, Release 2) Microsoft PowerPoint 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft PowerPoint 2016 STIG Benchmark - Ver 1, Rel 2
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft PowerPoint 2016 STIG - Ver 1, Rel 1
Microsoft Project 2016 STIG (Version 1, Release 2) Microsoft Project 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft Project 2016 STIG Benchmark - Ver 1, Rel 2
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft Project 2016 STIG - Ver 1, Rel 1
Microsoft Publisher 2016 STIG (Version 1, Release 4) Microsoft Publisher 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft Publisher 2016 STIG Benchmark - Ver 1, Rel 4
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft Publisher 2016 STIG - Ver 1, Rel 3
Microsoft Skype for Business 2016 STIG (Version 1, Release 2) Microsoft Skype for Business 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft Skype for Business 2016 STIG Benchmark - Ver 1, Rel 2
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft Skype for Business 2016 STIG - Ver 1, Rel 1
Microsoft Visio 2016 STIG (Version 1, Release 2) Microsoft Visio 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft Visio 2016 STIG Benchmark - Ver 1, Rel 2
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft Visio 2016 STIG - Ver 1, Rel 1
Microsoft Word 2016 STIG (Version 1, Release 2) Microsoft Word 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft Word 2016 STIG Benchmark - Ver 1, Rel 2
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft Word 2016 STIG - Ver 1, Rel 1
Microsoft One Drive for Business 2016 STIG (Version 1, Release 3) Microsoft One Drive for Business 2016
Defense Information Systems Agency
08/11/2020 SCAP 1.3 Content - Microsoft OneDrive for Business 2016 STIG Benchmark - Ver 1, Rel 3
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Microsoft OneDrive for Business 2016 STIG - Ver 1, Rel 3
Microsoft Excel 2016 STIG (Version 1, Release 3) Microsoft Excel 2016
Defense Information Systems Agency
08/12/2020 SCAP 1.3 Content - Microsoft Excel 2016 STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Microsoft Excel 2016 STIG - Ver 1, Rel 2
NIST National Checklist for Red Hat OpenShift Container Platform 3.x (content v0.1.48) Red Hat OpenShift Container Platform 3.10
Red Hat OpenShift Container Platform 3.11
Red Hat OpenShift Container Platform 3.5
Red Hat OpenShift Container Platform 3.6
Red Hat OpenShift Container Platform 3.7
Red Hat OpenShift Container Platform 3.8
Red Hat OpenShift Container Platform 3.9
Red Hat
06/30/2020 SCAP 1.3 Content - NIST National Checklist for Red Hat OpenShift Container Platform 3.x
Machine-Readable Format - OpenControl-formatted NIST 800-53/FISMA Applicability Guide for OpenShift 3.x
Adobe Acrobat Reader DC Classic Track (Version 1, Release 6) Adobe Acrobat Reader
Defense Information Systems Agency
08/05/2020 SCAP 1.2 Content - Adobe Acrobat Reader DC Classic Track STIG Benchmark - Ver 1, Rel 6
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Classic Track STIG - Ver 1, Rel 5
Adobe Acrobat Reader DC Continuous Track STIG (Ver 1, Rel 6) Adobe Acrobat Reader
Defense Information Systems Agency
08/05/2020 SCAP 1.2 Content - Adobe Acrobat Reader DC Continuous Track STIG Benchmark - Ver 1, Rel 5
GPOs - Group Policy Objects (GPOs) - July 2020
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Continuous Track STIG - Ver 1, Rel 6
APT-Suspicious file names and file locations (v0.4) Microsoft Windows 7
Microsoft Windows XP
CyberESI
05/06/2017 SCAP 1.2 Content - APT - Suspicious file names and file locations
Canonical Ubuntu 16.04 STIG (Ver 1, Rel 5) Canonical Ubuntu 16.04 LTS (Long Term Support)
Defense Information Systems Agency
08/04/2020 SCAP 1.2 Content - Canonical Ubuntu 16.04 STIG Benchmark - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - Canonical Ubuntu 16.04 LTS STIG - Ver 1, Rel 5
* This checklist is still undergoing review for inclusion into the NCP.