| 1.1.3.17.2 Set 'User Account Control: Detect application installations and prompt for elevation' to 'Enabled' | CIS Windows 8 L1 v1.0.0 | Windows | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 1.205 SOL-11.1-090130 | CIS Solaris 11 X86 STIG v1.0.0 CAT II | Unix | CONFIGURATION MANAGEMENT |
| 2.1.1 Ensure 'extproc' Is Not Enabled | CIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS Windows | Windows | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.1 Ensure 'extproc' Is Not Enabled | CIS Oracle Database 19c v2.0.0 L1 RDBMS On Host OS Unix | Unix | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.22 Ensure that 'Inline Cloud Analysis' on Vulnerability Protection profiles are enabled if 'Advanced Threat Prevention' is available | CIS Palo Alto Firewall 11 v1.2.0 L1 | Palo_Alto | RISK ASSESSMENT |
| 8.1.3.4 Ensure that 'Agentless scanning for machines' Component Status is Set to 'On' | CIS Microsoft Azure Foundations v6.0.0 L2 | microsoft_azure | RISK ASSESSMENT |
| 8.1.7.4 Ensure That Microsoft Defender for SQL Servers on Machines Is Set To 'On' | CIS Microsoft Azure Foundations v6.0.0 L2 | microsoft_azure | RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION |
| All network interfaces are operating in full-duplex mode | TNS Citrix Hypervisor | Unix | CONFIGURATION MANAGEMENT |
| CIS_AlmaLinux_OS_10_v1.0.0_L1_Workstation.audit from CIS AlmaLinux OS 10 v1.0.0 | CIS AlmaLinux OS 10 v1.0.0 L1 Workstation | Unix | |
| CIS_Amazon_Linux_2023_v1.0.0_L1_Server.audit from CIS Amazon Linux 2023 v1.0.0 | CIS Amazon Linux 2023 v1.0.0 L1 Server | Unix | |
| CIS_Debian_Linux_13_v1.0.0_L1_Workstation.audit from CIS Debian Linux 13 v1.0.0 | CIS Debian Linux 13 v1.0.0 L1 Workstation | Unix | |
| CIS_Debian_Linux_13_v1.0.0_L2_Server.audit from CIS Debian Linux 13 v1.0.0 | CIS Debian Linux 13 v1.0.0 L2 Server | Unix | |
| CIS_Debian_Linux_13_v1.0.0_L2_Workstation.audit from CIS Debian Linux 13 v1.0.0 | CIS Debian Linux 13 v1.0.0 L2 Workstation | Unix | |
| CIS_Kubernetes_v1.24_v1.0.0_Level_1_Master.audit from CIS Kubernetes v1.24 Benchmark v1.0.0 | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Master | Unix | CONFIGURATION MANAGEMENT |
| CIS_Kubernetes_v1.24_v1.0.0_Level_1_Worker.audit from CIS Kubernetes v1.24 Benchmark v1.0.0 | CIS Kubernetes v1.24 Benchmark v1.0.0 L1 Worker | Unix | CONFIGURATION MANAGEMENT |
| CIS_Kubernetes_v1.24_v1.0.0_Level_2_Master.audit from CIS Kubernetes v1.24 Benchmark v1.0.0 | CIS Kubernetes v1.24 Benchmark v1.0.0 L2 Master | Unix | CONFIGURATION MANAGEMENT |
| CIS_MariaDB_10.11_v1.0.0_L1_MariaDB_RDBMS_on_Linux_Unix.audit from CIS MariaDB 10.11 v1.0.0 | CIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS on Linux Unix | Unix | |
| CIS_MariaDB_10.11_v1.0.0_L1_MariaDB_RDBMS_Unix.audit from CIS MariaDB 10.11 v1.0.0 | CIS MariaDB 10.11 v1.0.0 L1 MariaDB RDBMS Unix | Unix | |
| CIS_MariaDB_10.11_v1.0.0_L2_MariaDB_RDBMS_on_Linux_Unix.audit from CIS MariaDB 10.11 v1.0.0 | CIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS on Linux Unix | Unix | |
| CIS_MariaDB_10.11_v1.0.0_L2_MariaDB_RDBMS_Unix.audit from CIS MariaDB 10.11 v1.0.0 | CIS MariaDB 10.11 v1.0.0 L2 MariaDB RDBMS Unix | Unix | |
| CIS_MongoDB_4_v1.0.0_L2_Unix.audit from CIS MongoDB 4 v1.0.0 | CIS MongoDB 4 v1.0.0 L2 Unix | Unix | |
| CIS_MongoDB_4_v1.0.0_L2_Windows.audit from CIS MongoDB 4 v1.0.0 | CIS MongoDB 4 v1.0.0 L2 Windows | Windows | |
| CIS_MongoDB_Benchmark_Level_1_OS_Unix_v1.0.0.audit from CIS MongoDB Benchmark v1.0.0 | CIS MongoDB L1 Unix Audit v1.0.0 | Unix | |
| CIS_Oracle_Linux_8_STIG_v1.0.0_CAT_III.audit from CIS Oracle Linux 8 STIG v1.0.0 | CIS Oracle Linux 8 STIG v1.0.0 CAT III | Unix | |
| CIS_Oracle_Linux_9_STIG_v1.0.0_CAT_II.audit from CIS Oracle Linux 9 STIG v1.0.0 | CIS Oracle Linux 9 STIG v1.0.0 CAT II | Unix | |
| CIS_Oracle_Linux_10_v1.0.0_L1_Server.audit from CIS Oracle Linux 10 v1.0.0 | CIS Oracle Linux 10 v1.0.0 L1 Server | Unix | |
| CIS_Oracle_Linux_10_v1.0.0_L1_Workstation.audit from CIS Oracle Linux 10 v1.0.0 | CIS Oracle Linux 10 v1.0.0 L1 Workstation | Unix | |
| CIS_PostgreSQL_18_v1.0.0_L1_Database_PostgreSQLDB.audit from CIS PostgreSQL 18 v1.0.0 | CIS PostgreSQL 18 v1.0.0 L1 Database PostgreSQLDB | PostgreSQLDB | |
| CIS_PostgreSQL_18_v1.0.0_L1_Database_Unix.audit from CIS PostgreSQL 18 v1.0.0 | CIS PostgreSQL 18 v1.0.0 L1 Database Unix | Unix | |
| CIS_PostgreSQL_18_v1.0.0_L1_OS_Linux_PostgreSQLDB.audit from CIS PostgreSQL 18 v1.0.0 | CIS PostgreSQL 18 v1.0.0 L1 OS Linux PostgreSQLDB | PostgreSQLDB | |
| CIS_Rocky_Linux_10_v1.0.0_L2_Server.audit from CIS Rocky Linux 10 v1.0.0 | CIS Rocky Linux 10 v1.0.0 L2 Server | Unix | |
| CIS_Rocky_Linux_10_v1.0.0_L2_Workstation.audit from CIS Rocky Linux 10 v1.0.0 | CIS Rocky Linux 10 v1.0.0 L2 Workstation | Unix | |
| CIS_Solaris_11_SPARC_STIG_v1.0.0_CAT_II.audit from CIS Solaris 11 SPARC STIG v1.0.0 | CIS Solaris 11 SPARC STIG v1.0.0 CAT II | Unix | |
| CIS_SUSE_Linux_Enterprise_16_v1.0.0_L2_Server.audit from CIS SUSE Linux Enterprise 16 v1.0.0 | CIS SUSE Linux Enterprise 16 v1.0.0 L2 Server | Unix | |
| DTAM154 - McAfee VirusScan On-Demand scan must be configured to scan memory for rootkits. | DISA McAfee VirusScan 8.8 Local Client STIG v6r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTAM154 - McAfee VirusScan On-Demand scan must be configured to scan memory for rootkits. | DISA McAfee VirusScan 8.8 Managed Client STIG v6r1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| Enable only necessary and secure services, protocols, daemons - 'lwsmd' | TNS Citrix Hypervisor | Unix | CONFIGURATION MANAGEMENT |
| F5BI-AP-300065 - The F5 BIG-IP appliance providing content filtering must automatically update malicious code protection mechanisms. | DISA F5 BIG-IP TMOS ALG STIG v1r3 | F5 | SYSTEM AND INFORMATION INTEGRITY |
| F5BI-AS-000119 - The BIG-IP ASM module must be configured to automatically update malicious code protection mechanisms when providing content filtering to virtual servers. | DISA F5 BIG-IP Application Security Manager STIG v2r2 | F5 | SYSTEM AND INFORMATION INTEGRITY |
| Host is enabled | TNS Citrix Hypervisor | Unix | CONFIGURATION MANAGEMENT |
| JUSX-IP-000023 - The IDPS must send an alert to, at a minimum, the ISSO and ISSM when intrusion detection events are detected that indicate a compromise or potential for compromise. | DISA Juniper SRX Services Gateway IDPS v2r1 | Juniper | SYSTEM AND INFORMATION INTEGRITY |
| MS.EXO.11.3v1 - The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence. | CISA SCuBA Microsoft 365 Exchange Online v1.5.0 | microsoft_azure | ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| PANW-IP-000051 - The Palo Alto Networks security platform must send an alert to, at a minimum, the ISSO and ISSM when intrusion detection events are detected which indicate a compromise or potential for compromise. | DISA Palo Alto Networks IDPS STIG v3r2 | Palo_Alto | SYSTEM AND INFORMATION INTEGRITY |
| Snapshots are not present | TNS Citrix Hypervisor | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| SonicWALL - Flood Protection - Layer 2 - Threshold | TNS SonicWALL v5.9 | SonicWALL | SYSTEM AND COMMUNICATIONS PROTECTION |
| SonicWALL - Flood Protection - TCP - Handshake enforcement | TNS SonicWALL v5.9 | SonicWALL | |
| SonicWALL - SSL Control - Detect MD5 Digest | TNS SonicWALL v5.9 | SonicWALL | SYSTEM AND INFORMATION INTEGRITY |
| XenServer - Install a trusted CA certificate on the pool | TNS Citrix XenServer | Unix | |
| XenServer - Passwords stored in 'secrets' are not visible | TNS Citrix XenServer | Unix | |
| XenServer - Restrict allowed IPv6 addresses used by each VM guest | TNS Citrix XenServer | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |