National Checklist Program Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 530 matching records. Displaying matches 81 through 100.

Name (Version) Target Authority Last Modified Resources
Apple OS X 10.13 STIG (Ver 2, Rel 1) Apple macOS 10.13
Defense Information Systems Agency
10/27/2020 Standalone XCCDF 1.1.4 - Apple OS X 10.13 STIG - Ver 2, Rel 1
Solaris 10 (SPARC and x86) Manual STIG (Version 2, Release 1) Oracle Solaris 10.0
Defense Information Systems Agency
10/27/2020 SCAP 1.2 Content - Solaris 10 SPARC STIG Benchmark - Ver 2, Rel 1
SCAP 1.2 Content - Solaris 10 x86 STIG Benchmark - Ver 2, Rel 1
Standalone XCCDF 1.1.4 - Solaris 10 SPARC STIG - Ver 2, Rel 1
Standalone XCCDF 1.1.4 - Solaris 10 X86 STIG - Ver 2, Rel 1
zOS ACF2 STIG (Version 6, Release 47) IBM OS390
Defense Information Systems Agency
10/27/2020 Standalone XCCDF 1.1.4 - z/OS STIG - Ver 8, Rel 1
Standalone XCCDF 1.1.4 - z/OS ACF2 Products - Ver 6, Rel 47
Solaris 11 (SPARC and x86) Manual STIG (Version 2, Release 1) Sun Solaris
Defense Information Systems Agency
10/27/2020 SCAP 1.2 Content - Solaris 11 SPARC STIG Benchmark - Ver 2, Rel 1
SCAP 1.2 Content - Solaris 11 X86 STIG Benchmark - Ver 2, Rel 1
Standalone XCCDF 1.1.4 - Solaris 11 SPARC STIG - Ver 2, Rel 1
Standalone XCCDF 1.1.4 - Solaris 11 X86 STIG - Ver 2, Rel 1
Oracle Linux 7 STIG (Ver 2, Rel 1) Oracle Linux 7
Defense Information Systems Agency
10/27/2020 SCAP 1.2 Content - Oracle Linux 7 STIG Benchmark - Ver 2, Rel 1
Standalone XCCDF 1.1.4 - Oracle Linux 7 STIG - Ver 2, Rel 1
Adobe Acrobat Reader DC Classic Track (Version 2, Release 1) Adobe Acrobat Reader
Defense Information Systems Agency
10/27/2020 SCAP 1.2 Content - Adobe Acrobat Reader DC Classic Track STIG Benchmark - Ver 2, Rel 1
Standalone XCCDF 1.1.4 - Sunset - Adobe Acrobat Reader DC Classic Track STIG - Ver 2, Rel 1
zOS RACF STIG (Version 6, Release 47) IBM OS390
Defense Information Systems Agency
10/27/2020 Standalone XCCDF 1.1.4 - z/OS STIG - Ver 8, Rel 1
Standalone XCCDF 1.1.4 - z/OS RACF Products - Ver 6, Rel 47
SUSE Linux Enterprise Server (SLES) 12 STIG (Ver 1, Rel 6) SUSE Linux Enterprise Server 12.0
Defense Information Systems Agency
10/27/2020 SCAP 1.2 Content - SUSE Linux Enterprise Server 12 STIG Benchmark - Ver 2, Rel 1
Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Server 12 STIG - Ver 2, Rel 1
NIST National Checklist for Red Hat Virtualization Host 4.x (content v0.1.48) Red Hat Virtualization Host 4.3
Red Hat
10/26/2020 SCAP 1.3 Content - NIST National Checklist for Red Hat Virtualization Host 4.x
Ansible Playbook - [DRAFT] DISA STIG for Red Hat Virtualization Host (RHVH)
Ansible Playbook - VPP - Protection Profile for Virtualization v. 1.0 for Red Hat Virtualization Hypervisor (RHVH)
Machine-Readable Format - OpenControl-formatted NIST 800-53 responses for Red Hat Virtualization Host 4.x
NIST National Checklist for Red Hat Enterprise Linux 8.x (content v0.1.50) Red Hat Enterprise Linux 8.0
Red Hat Enterprise Linux 8.1
Red Hat Enterprise Linux 8.2
Red Hat
10/26/2020 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 8.x
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for RHEL 8.x
Ansible Playbook - PCI-DSS
OpenShift 3.x on Azure for Government (FedRAMP Moderate) (v1) Red Hat OpenShift Container Platform 3.10
Red Hat OpenShift Container Platform 3.11
Red Hat OpenShift Container Platform 3.5
Red Hat OpenShift Container Platform 3.6
Red Hat OpenShift Container Platform 3.7
Red Hat OpenShift Container Platform 3.8
Red Hat OpenShift Container Platform 3.9
Red Hat
10/26/2020 Security Template - OpenShift Container Platform 3.x on Azure for Government, FedRAMP Moderate SSP Template
Security Template - Ansible Playbooks supporting the creation of either a multi-node full HA production cluster or a single node designed for exploration of OpenShift on Azure.
Prose - Deploying Red Hat OpenShift Container Platform 3 on Microsoft Azure
NIST National Checklist for Red Hat Enterprise Linux 7.x (content v0.1.50) Red Hat Enterprise Linux 7.0
Red Hat Enterprise Linux 7.1
Red Hat Enterprise Linux 7.2
Red Hat Enterprise Linux 7.3
Red Hat Enterprise Linux 7.4
Red Hat Enterprise Linux 7.5
Red Hat Enterprise Linux 7.6
Red Hat Enterprise Linux 7.7
Red Hat
10/26/2020 SCAP 1.3 Content - NIST National Checklist for Red Hat Enterprise Linux 7.x, SCAP 1.3
Ansible Playbook - CIA Commercial Cloud Services (CIA C2S)
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST National Checklist for Red Hat Enterprise Linux 7.x
Ansible Playbook - PCI-DSS
Ansible Playbook - DoD STIG
NIST National Checklist for Red Hat OpenShift Container Platform 3.x (content v0.1.48) Red Hat OpenShift Container Platform 3.10
Red Hat OpenShift Container Platform 3.11
Red Hat OpenShift Container Platform 3.5
Red Hat OpenShift Container Platform 3.6
Red Hat OpenShift Container Platform 3.7
Red Hat OpenShift Container Platform 3.8
Red Hat OpenShift Container Platform 3.9
Red Hat
10/26/2020 SCAP 1.3 Content - NIST National Checklist for Red Hat OpenShift Container Platform 3.x
Machine-Readable Format - OpenControl-formatted NIST 800-53/FISMA Applicability Guide for OpenShift 3.x
Blackberry UEM STIG (Ver 1, Rel 1) BlackBerry UEM 12.11
Defense Information Systems Agency
09/28/2020 Standalone XCCDF 1.1.4 - Blackberry UEM STIG - Ver 1, Rel 1
Apple OS X 10.15 STIG (Ver 1, Rel 2) Apple OS X 10.15
Defense Information Systems Agency
09/28/2020 Standalone XCCDF 1.1.4 - Apple OS X 10.15 STIG - Ver 1, Rel 2
CIS Oracle Cloud Infrastructure Foundations Benchmark (1.0.0) Oracle Cloud Infrastructure
Center for Internet Security (CIS)
09/11/2020 Prose - CIS Oracle Cloud Infrastructure Foundations Benchmark version 1.0.0
Microsoft Excel 2016 STIG (Version 1, Release 3) Microsoft Excel 2016
Defense Information Systems Agency
09/04/2020 Standalone XCCDF 1.1.4 - Microsoft Excel 2016 STIG - Ver 1, Rel 2
CIS Oracle Database 18c Benchmark (1.0.0) Oracle Database 18c
Center for Internet Security (CIS)
08/20/2020 Prose - CIS Oracle Database Server 18c Benchmark v1.0.0
CIS Amazon Web Services Foundations Benchmark (v1.3.0) Amazon Web Services
Center for Internet Security (CIS)
08/11/2020 Prose - CIS Amazon Web Services Foundations Benchmark version 1.3.0
BlackBerry UEM 12.10 STIG (Ver 1, Rel 1) BlackBerry UEM 12.10
Defense Information Systems Agency
08/10/2020 Standalone XCCDF 1.1.4 - Sunset - BlackBerry UEM 12.10 STIG - Ver 1, Rel 1
* This checklist is still undergoing review for inclusion into the NCP.