National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

National Checklist Program Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 514 matching records. Displaying matches 1 through 20.


Name (Version) Target Authority Last Modified Resources
NIST National Checklist for Red Hat Virtualization Host 4.x (content v0.1.44) Red Hat Virtualization Host 4.3 Red Hat 06/14/2019 SCAP 1.3 Content - NIST National Checklist Collection for Red Hat Products with SCAP 1.3
SCAP 1.2 Content - NIST National Checklist Collection for Red Hat Products with SCAP 1.2
Ansible Playbook - VPP - Protection Profile for Virtualization v. 1.0 for Red Hat Virtualization Hypervisor (RHVH)
Ansible Playbook - [DRAFT] DISA STIG for Red Hat Virtualization Host (RHVH)
NIST National Checklist for Red Hat Enterprise Linux 7.x (content v0.1.44) Red Hat Enterprise Linux 7.0
Red Hat Enterprise Linux 7.1
Red Hat Enterprise Linux 7.2
Red Hat Enterprise Linux 7.3
Red Hat Enterprise Linux 7.4
Red Hat Enterprise Linux 7.5
Red Hat Enterprise Linux 7.6
Red Hat 06/14/2019 SCAP 1.3 Content - NIST National Checklist Collection for Red Hat Products with SCAP 1.3
SCAP 1.2 Content - NIST National Checklist Collection for Red Hat Products with SCAP 1.2
Ansible Playbook - CIA Commercial Cloud Services (CIA C2S)
Ansible Playbook - DoD STIG
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - NIST National Checklist for Red Hat Enterprise Linux 7.x
Ansible Playbook - PCI-DSS
NIST National Checklist for Red Hat Enterprise Linux 8.x (content v0.1.44) Red Hat Enterprise Linux 8.0 Red Hat 07/11/2019 SCAP 1.3 Content - NIST National Checklist Collection for Red Hat Products with SCAP 1.3
SCAP 1.2 Content - NIST National Checklist Collection for Red Hat Products with SCAP 1.2
Ansible Playbook - FBI Criminal Justice Information Services (FBI CJIS)
Ansible Playbook - Health Insurance Portability and Accountability Act (HIPAA)
Ansible Playbook - NIST 800-171 (Controlled Unclassified Information)
Ansible Playbook - NIST National Checklist for RHEL 8.x
Ansible Playbook - PCI-DSS
NIST National Checklist for Red Hat OpenShift Container Platform 3.x (content v0.1.44) Red Hat OpenShift Container Platform 3.5
Red Hat OpenShift Container Platform 3.6
Red Hat OpenShift Container Platform 3.7
Red Hat OpenShift Container Platform 3.8
Red Hat OpenShift Container Platform 3.9
Red Hat OpenShift Container Platform 3.10
Red Hat OpenShift Container Platform 3.11
Red Hat 06/14/2019 SCAP 1.3 Content - NIST National Checklist Collection for Red Hat Products with SCAP 1.3
SCAP 1.2 Content - NIST National Checklist Collection for Red Hat Products with SCAP 1.2
Machine-Readable Format - OpenControl-formatted NIST 800-53/FISMA Applicability Guide for OpenShift 3.x
Security Template - NIST 800-53/FISMA Applicability Guide for OpenShift 3.x
Prose - OpenShift Security Configuration Guide (HTML)
Adobe Acrobat Reader DC Classic Track (Version 1, Release 6) Adobe Acrobat Reader Defense Information Systems Agency 08/09/2019 SCAP 1.2 Content - Adobe Acrobat Reader DC Classic Track STIG Benchmark - Ver 1, Rel 6
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Classic Track STIG - Ver 1, Rel 5
Adobe Acrobat Reader DC Continuous Track STIG (Ver 1, Rel 6) Adobe Acrobat Reader Defense Information Systems Agency 08/09/2019 SCAP 1.2 Content - Adobe Acrobat Reader DC Continuous Track STIG Benchmark - Ver 1, Rel 5
Standalone XCCDF 1.1.4 - Adobe Acrobat Reader DC Continuous Track STIG - Ver 1, Rel 6
APT-Suspicious file names and file locations (v0.4) Microsoft Windows XP
Microsoft Windows 7
CyberESI 05/06/2017 SCAP 1.2 Content - APT - Suspicious file names and file locations
Google Chrome Browser STIG for Windows (Version 1, Release 16) Google Chrome 33 Defense Information Systems Agency 08/09/2019 SCAP 1.2 Content - Google Chrome for Windows STIG Benchmark - Ver 1, Rel 12
GPOs - Group Policy objects (GPOs) - July 2019
Standalone XCCDF 1.1.4 - Google Chrome Browser STIG - Ver 1, Rel 16
Windows 8/8.1 STIG (Version 1, Release 21) Microsoft Windows 8 x86 (32-bit)
Microsoft Windows 8 x64 (64-bit)
Microsoft Windows 8.1 (x64)
Microsoft Windows 8.1 (x86)
Defense Information Systems Agency 09/11/2019 SCAP 1.2 Content - Sunset - Microsoft Windows 8/8.1 STIG Benchmark - Ver 1, Rel 22
GPOs - Group Policy Objects (GPOs) - April 2019
Standalone XCCDF 1.1.4 - Sunset - Microsoft Windows 8/8.1 STIG - Ver 1, Rel 21
Microsoft Windows 7 (Version 1, Release 30) Microsoft Windows 7 Defense Information Systems Agency 09/11/2019 SCAP 1.2 Content - Sunset - Microsoft Windows 7 STIG Benchmark - Ver 1, Rel 36
GPOs - Group Policy Objects (GPOs) - April 2019
Machine-Readable Format - Sunset - Microsoft Windows 7 Audit Benchmark
Standalone XCCDF 1.1.4 - Sunset - Microsoft Windows 7 STIG - Ver 1, Rel 30
Windows Firewall STIG and Advanced Security STIG (version 1, release 7) windows firewall Defense Information Systems Agency 06/12/2019 SCAP 1.2 Content - Microsoft Windows Firewall STIG Benchmark - Ver 1, Rel 7
GPOs - Group Policy Objects (GPOs) - April 2019
Standalone XCCDF 1.1.4 - Microsoft Windows Firewall STIG and Advanced Security STIG - Ver 1, Rel 7
Microsoft Windows Defender Antivirus STIG (Ver 1, Rel 6) Microsoft Windows Defender Defense Information Systems Agency 08/12/2019 SCAP 1.2 Content - Microsoft Windows Defender Antivirus STIG Benchmark - Ver 1, Rel 3
GPOs - Group Policy Objects (GPOs) - April 2019
Standalone XCCDF 1.1.4 - Microsoft Windows Defender Antivirus STIG - Ver 1, Rel 6
Microsoft Windows Server 2016 STIG (Version 1, Release 10) Microsoft Windows Server 2016 Defense Information Systems Agency 08/12/2019 SCAP 1.2 Content - Microsoft Windows Server 2016 STIG Benchmark - Ver 1, Rel 10
GPOs - Group Policy objects (GPOs) - July 2019
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2016 STIG - Ver 1, Rel 9
Windows 10 STIG (Version 1, Release 18) Microsoft Windows 10 Defense Information Systems Agency 08/12/2019 SCAP 1.2 Content - Microsoft Windows 10 STIG Benchmark - Ver 1, Rel 15
GPOs - Group Policy objects (GPOs) - July 2019
Standalone XCCDF 1.1.4 - Microsoft Windows 10 STIG - Ver 1, Rel 18
Microsoft Windows 2008 R2 STIG (Version 1, Release 33) Microsoft Windows Server 2008 R2
Microsoft Windows Server 2008 r2 Itanium
Microsoft Windows Server 2008 r2 x64
Microsoft Windows Server 2008 R2 Service Pack 1
Microsoft Windows Server 2008 r2 Service Pack 1 Itanium
Microsoft Windows Server 2008 r2 x64 Service Pack 1
Defense Information Systems Agency 09/20/2019 SCAP 1.2 Content - Microsoft Windows 2008 R2 DC STIG Benchmark - Ver 1, Rel 32
SCAP 1.2 Content - Microsoft Windows 2008 R2 MS STIG Benchmark - Ver 1, Rel 33
GPOs - Group Policy objects (GPOs) - July 2019
Standalone XCCDF 1.1.4 - Microsoft Windows 2008 R2 DC STIG - Ver 1, Rel 31
Standalone XCCDF 1.1.4 - Microsoft Windows 2008 R2 MS STIG - Ver 1, Rel 30
Internet Explorer 11 STIG (Version 1, Release 17) Microsoft Internet Explorer 11 Defense Information Systems Agency 08/14/2019 SCAP 1.2 Content - Microsoft Internet Explorer 11 STIG Benchmark - Ver1, Rel 13
GPOs - Group Policy objects (GPOs) - July 2019
Standalone XCCDF 1.1.4 - Microsoft Internet Explorer 11 STIG - Ver 1, Rel 17
Windows Server 2012 / 2012 R2 STIG (Version 2, Release 17) Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012
Defense Information Systems Agency 08/12/2019 SCAP 1.2 Content - Microsoft Windows 2012 and 2012 R2 DC STIG Benchmark - Ver 2 Rel 17
SCAP 1.2 Content - Microsoft Windows 2012 and 2012 R2 MS STIG Benchmark - Ver 2, Rel 16
GPOs - Group Policy objects (GPOs) - July 2019
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2012 and 2012 R2 DC STIG - Ver 2, Rel 17
Standalone XCCDF 1.1.4 - Microsoft Windows Server 2012 and 2012 R2 MS STIG - Ver 2, Rel 16
McAfee Antivirus 8.8 STIG (Version 5, Release 16) Mcafee Virusscan Enterprise 8.8.0 Defense Information Systems Agency 06/25/2019 SCAP 1.2 Content - McAfee VirusScan 8.8 Local Client STIG Benchmark - Ver 1, Rel 1
SCAP 1.2 Content - McAfee VirusScan 8.8 Managed Client STIG Benchmark - Ver 1, Rel 2
Standalone XCCDF 1.1.4 - McAfee Virus Scan 8.8 Local Client STIG - Ver 5, Rel 16
Standalone XCCDF 1.1.4 - McAfee VirusScan 8.8 Managed Client STIG - Ver 5, Rel 20
Microsoft .NET Framework 4 (Version 1, Release 8) Microsoft .NET Framework 4.0 Defense Information Systems Agency 08/15/2019 SCAP 1.2 Content - MS DotNet Framework 4 STIG Benchmark - Ver 1, Rel 6
Standalone XCCDF 1.1.4 - Microsoft DotNet Framework 4.0 STIG - Ver 1, Rel 8
Microsoft Office 2013 STIG (Version 1 Release 3) Microsoft Office 2013 Defense Information Systems Agency 06/08/2019 SCAP 1.2 Content - Microsoft Office System 2013 STIG Benchmark - Ver 1, Rel 5 (SCC tool use only)
Standalone XCCDF 1.1.4 - Microsoft Office 2013 STIG - Version 1 Release 3
Prose - Microsoft Office 2013 Overview - Ver 1, Rel 5
* This checklist is still undergoing review for inclusion into the NCP.